Medium15 minLaravel Fundamentals
UpdatedAug 5, 2026
Edit

Laravel Form Requests

Question Variations

  • "Why use a FormRequest instead of inline validation?"
  • "Where should request authorization live?"
  • "What status code does Laravel return for JSON validation errors?"

Why This Is Asked

Form requests test API boundary design and whether validation and authorization stay out of controllers.

Key Concepts

  • Form requests encapsulate validation and authorization for an endpoint.
  • Controllers consume validated data rather than the entire input.
  • Validation failures return structured client errors for JSON requests.
  • Domain rules remain separate from basic request shape validation.

Question Variations

  • “Why use a FormRequest instead of inline validation?”
  • “Where should request authorization live?”
  • “What status code does Laravel return for JSON validation errors?”

Answers by Technology

+ Add Variant
LaravelImprove this answer ✏️

Expected Answer (Laravel 13 / PHP 8.3+)

A Form Request encapsulates input authorization and validation for one endpoint. Type-hint it in a controller, then use validated() to pass only approved fields onward. This keeps controllers thin, makes rules reusable and testable, and gives JSON clients Laravel’s structured validation response. Keep business conflicts, such as a duplicate domain rule, in the application layer rather than pretending they are field-shape validation.

Why It Matters

Boundary validation prevents untrusted fields reaching persistence and gives clients predictable errors.

Code Example

final class StoreUserRequest extends FormRequest
{
    public function authorize(): bool { return true; }
    public function rules(): array { return ['email' => ['required', 'email']]; }
}

Common Mistakes

  • Using $request->all() for writes: Unexpected fields can be mass-assigned.
  • Putting authorization checks only in controllers: Other entry points can bypass them.

Follow-up Questions

  • What does validated() return? (Answer: Only the data that passed the request rules.)
  • What status is used for JSON validation errors? (Answer: 422.)