Fortify

Fortify and the Routes It Registers

Fortify 1,761 is authentication without a user interface. The kit hands it screens in FortifyServiceProvider (Fortify::loginView(...) and six more) and enables features in config/fortify.php: registration, password resets, email verification, two-factor authentication and passkeys. Each feature adds routes, from login, logout and register to reset-password/{token}, email/verify/{id}/{hash} and two-factor-challenge. In a plain skeleton, composer require laravel/fortify and php artisan fortify:install publish the config, provider, five actions and two migrations and register 33 routes. To replay a browser with curl 3,008 , keep cookies in a jar and pull the CSRF token from the hidden _token input in the login page:

A Fortify login with a cookie jar, then six bad passwords in a rowPHP
B=http://127.0.0.1:8314; J='-b jar -c jar'; W='%{http_code} %{redirect_url}\n'
tok() { curl -s $J "$B$1" | grep -o 'name="_token" value="[^"]*' | cut -d'"' -f4; }
T=$(tok /login); echo "$T"; P='email=ada@example.com&password'
curl -s $J -o /dev/null -w "$W" -d "$P=correct-horse-9" $B/login
curl -s $J -o /dev/null -w "$W" -d "_token=$T&$P=wrong" $B/login
curl -s $J -o /dev/null -w "$W" -d "_token=$T&$P=correct-horse-9" $B/login
curl -s $J -o /dev/null -w "$W" $B/dashboard
rm jar; T=$(tok /login); F="_token=$T&email=bob@example.com&password=x"
for i in 1 2 3 4 5 6; do curl -s $J -o /dev/null -w '%{http_code} ' -d "$F" $B/login; done; echo
Output
AVNfjDmcEDTyWUGYOaByRb1WXTfRCNgwMgT33s45
419
302 http://127.0.0.1:8314/login
302 http://127.0.0.1:8314/dashboard
200
302 302 302 302 302 429

Without the token, the request died with 419 before Fortify saw it. The wrong password went back to /login with "These credentials do not match our records."; the right one went to the home path in config/fortify.php. The kit's login limiter allows five attempts a minute per email and IP, so the sixth got 429 (JSON clients also see Retry-After). Since each email gets its own budget, add a per-IP Limit as well against password spraying.