Reading Input from the Request

Illuminate\Http\Request merges the query string, form fields and a JSON body into one input bag, whatever the verb. A diagnostic action returns one entry per accessor call for a POST that carries both a query string and a JSON body; each key names the call that produced it.

Output of 46
$ kv() { jq -r 'to_entries[] | "\(.key) = \(.value | tojson)"'; }    # one key per line
$ curl -s -X POST "$B/echo/input?x=from-query&qty=3" -H 'Sec-Fetch-Site: same-origin' \
    -H 'Content-Type: application/json' \
  -d '{"x":"from-body","author":{"name":"Ada"},"tags":["php","sql"],"gift":"on","note":"  "}' \
    | kv
input(x) = "from-body"
query(x) = "from-query"
author.name = "Ada"
tags.* = ["php","sql"]
integer(qty) = 3
boolean(gift) = true
has(note) = true
filled(note) = false
only = {"x":"from-body"}
keys(all) = ["x","author","tags","gift","note","qty"]

The body won the tie for x; query() still reached the query string. boolean() accepts 1, true, on and yes. note was present but not filled, because the global TrimStrings and ConvertEmptyStringsToNull middleware had turned " " into null. Other typed accessors are string(), float(), date(), array() and enum(): enum('sort', SortOrder::class, SortOrder::Name) falls back to the default for ?sort=bogus. They coerce but do not validate, so stored input goes through validate() or a form request (Form Request Classes), never all().