Skip to main content
Create your own
Lesson illustration

Breeze-Powered Session Authentication

Hello! Welcome to the first lesson in our module on Authentication and Authorization.

In the previous module, we focused on securing the "perimeter" of our application. We learned how to control which external domains can access our API (CORS) and how often they can make requests (Rate Limiting). Now, we'll shift our focus inward to manage who can use our application and what they are allowed to do.

This lesson kicks off that journey by tackling a fundamental requirement for most web applications: user authentication. We'll implement a complete, session-based authentication system—including registration, login, and password reset—not by building it from scratch, but by using a powerful Laravel starter kit called Breeze. Your goal is to learn how to install Breeze, understand the code it generates, and see how its different authentication features work together.

1. What are Starter Kits? Meet Laravel Breeze

Before we start coding, it's important to understand what a "starter kit" is and why it's useful. Building authentication is a repetitive and critical task. A mistake can have serious security implications. Laravel provides starter kits to give you a well-tested, pre-built foundation for your application's authentication system.

Starter Kits - Laravel 10.x

Let's start with the official Laravel documentation to get a high-level overview of starter kits and Laravel Breeze.

Read the 'Introduction' and 'Laravel Breeze' sections. Pay attention to the list of features Breeze provides out-of-the-box (login, registration, password reset, etc.) and its technology stack (Blade templates and Tailwind CSS).

As you read, Breeze is described as a "minimal, simple implementation" of Laravel's authentication features. It scaffolds all the necessary routes, controllers, and views, allowing you to have a full authentication system up and running in minutes. This is what it will look like once installed:

Laravel Breeze Login and Registration Forms
These are the default login and registration pages generated by Laravel Breeze. They are fully functional and styled with Tailwind CSS.

2. Installation and Scaffolding

Now for the hands-on part. We are going to install and configure Breeze in a fresh Laravel project. The following video provides an excellent, detailed walkthrough of the entire process. We will follow its steps to get our authentication system running.

Laravel Breeze Tutorial | Learn how Laravel Breeze Works | Enable Verification with Laravel Breeze

This video from Code With Dary will guide us through the installation. We'll start with the initial Composer and Artisan commands.

Watch from 00:21 to 03:13. Follow the steps to install Breeze. I'll summarize the commands below.

Here are the steps to follow in your project's terminal:

  1. Require the Package: First, we'll pull in the Breeze package using Composer.

    composer require laravel/breeze --dev
    
  2. Install the Scaffolding: Next, run the breeze:install Artisan command. This is where Breeze will publish its controllers, views, and routes into your application.

    php artisan breeze:install
    

    You will be prompted to choose a frontend stack. For this lesson, select Blade with Alpine. You can also choose your preferred testing framework (e.g., Pest).

  3. Configure Your Database: Before migrating, make sure your .env file is configured to connect to your MSSQL database. Your settings should look something like this:

    DB_CONNECTION=sqlsrv
    DB_HOST=your_mssql_server_ip
    DB_PORT=1433
    DB_DATABASE=your_database_name
    DB_USERNAME=your_username
    DB_PASSWORD=your_password
    
  4. Run Migrations: Now, run the database migrations. This will create the users table and other tables that Breeze needs.

    php artisan migrate
    
  5. Compile Frontend Assets: Finally, install the frontend dependencies and compile the CSS and JavaScript.

    npm install
    npm run dev
    

Once these steps are complete, run php artisan serve and navigate to /login or /register in your browser. You should see the working forms!

3. A Tour of the Breeze Architecture

Breeze isn't a "black box." It publishes all its code directly into your application, giving you full control to inspect and customize it. Let's explore the key files that were just created.

Laravel Breeze Tutorial | Learn how Laravel Breeze Works | Enable Verification with Laravel Breeze

The same video provides an excellent tour of the files generated by Breeze. This will help you understand how the different pieces connect.

Watch from 03:13 to 08:38. This segment covers: Routes: The new routes/auth.php file and how it's included in web.php. Controllers: The new app/Http/Controllers/Auth directory and its contents. Database & Model: The default users table migration and a review of the User model's properties (fillable, hidden, casts).

To summarize the key locations you should explore in your code editor:

  • routes/auth.php: Contains all authentication-related routes (login, logout, registration, password reset, etc.). Notice they are all grouped under the guest middleware, except for the logout route.
  • app/Http/Controllers/Auth/: This new directory holds all the logic. For example:
    • RegisteredUserController.php: Handles new user registration.
    • AuthenticatedSessionController.php: Manages login and logout.
    • PasswordResetLinkController.php: Sends password reset links.
    • NewPasswordController.php: Handles the actual password reset.
  • app/Http/Requests/Auth/LoginRequest.php: A dedicated Form Request class that handles validation for the login form.
  • resources/views/:
    • auth/: Contains all the primary Blade views for authentication forms.
    • layouts/: Includes guest.blade.php (for pages like login/register) and app.blade.php (for authenticated users).
    • components/: Reusable Blade components like input.blade.php, label.blade.php, etc., are stored here.

4. Deep Dive: Key Authentication Flows

With the scaffolding in place and an understanding of the file structure, let's see these features in action.

Registration and Email Verification

The registration flow is more than just creating a user. Breeze also includes the logic for email verification, though it's not enabled by default.

Laravel Breeze Tutorial | Learn how Laravel Breeze Works | Enable Verification with Laravel Breeze

Let's walk through the registration process and then enable the crucial email verification feature.

Watch from 08:38 to 19:49. This is a detailed section. Focus on: The Registration Flow: How the RegisteredUserController's store method validates input, creates a user, logs them in, and redirects. Enabling Email Verification: This is a key practical step. Pay close attention to the two changes required: Implementing the MustVerifyEmail interface in the User model. Adding the verified middleware to the dashboard route in routes/web.php.

By enabling email verification, you protect your dashboard route. Unverified users will be automatically redirected to an email verification prompt, preventing them from accessing authenticated areas until they've confirmed their email address.

Login, Logout, and Rate Limiting

The login flow is handled by the AuthenticatedSessionController. A particularly interesting part of this controller is its connection to the topic of our last lesson: rate limiting.

Laravel Breeze Tutorial | Learn how Laravel Breeze Works | Enable Verification with Laravel Breeze

Now, let's examine the login and logout functionality. Pay special attention to how Breeze protects your login form from brute-force attacks.

Watch from 19:49 to 26:59. Note the following: The LoginRequest class and its authenticate method. The use of ensureIsNotRateLimited to throttle login attempts. This is a real-world application of the RateLimiter we discussed in the last lesson! The destroy method, which handles user logout by invalidating the session.

The built-in login throttling is a perfect example of Laravel's integrated nature. The security features we learn about are not just theoretical; they are baked into core functionalities like authentication.

5. Customizing Breeze: A Practical Example

A starter kit is just that—a start. Your application will almost certainly have unique requirements. The real power of Breeze is that all its code is in your project, ready to be modified.

Let's walk through a common customization: allowing users to log in with a username instead of an email address.

Laravel Breeze Tutorial | Learn how Laravel Breeze Works | Enable Verification with Laravel Breeze

To solidify your understanding, let's extend Breeze's default functionality. This final video segment demonstrates how to add a username field and use it for login.

Watch from 30:35 to 40:20. This is a very practical walkthrough of the entire customization process. Follow the steps: Create a new migration to add a username column to the users table. Update the User model's $fillable array. Modify the registration controller (RegisteredUserController) to validate and save the new username field. Update the registration view (register.blade.php) to include the username input field. Change the login view (login.blade.php) to ask for a username instead of an email. Modify the LoginRequest to validate a username and attempt authentication using it.

This exercise demonstrates the complete lifecycle of a feature change within the Breeze scaffolding: from the database schema up to the frontend views and backend logic. Being able to perform these kinds of customizations is key to mastering Laravel.

Conclusion

In this lesson, you've successfully implemented a complete, secure, and session-based authentication system for a web application using Laravel Breeze. You didn't just run a command; you explored the generated architecture, understood the flow of data and logic, enabled a key security feature (email verification), and even customized the default behavior.

Key Takeaways:

  • Laravel Breeze is a starter kit that scaffolds a minimal but complete authentication system, including routes, controllers, and views.
  • It is not a black box; it publishes all its code into your application, giving you full control to customize it.
  • The authentication logic is neatly organized into controllers within the app/Http/Controllers/Auth directory.
  • Features like email verification can be easily enabled by implementing the MustVerifyEmail interface and adding the verified middleware.
  • Breeze integrates other Laravel features like the Rate Limiter to provide out-of-the-box security against brute-force attacks.

Up Next:

Session-based authentication is perfect for traditional, stateful web applications where the server and browser maintain a consistent session. But what about modern JavaScript frontends or mobile apps that communicate with a backend via an API? These are typically "stateless."

In the next lesson, we will tackle this challenge by implementing token-based authentication for stateless APIs using Laravel Sanctum.

Can't find a good explanation? Sign up and we'll make it for you

Sign up