Answer a successful POST with a redirect (Post/Redirect/Get), so a refresh repeats a harmless GET. After validating (Validating Inside a Controller) and creating the product, the web store action returns redirect()->route('products.show', $product)->with('status', "Added {$product->name}."), which flashes the message into the session for exactly one request:
$ curl -si -c jar -u admin@example.com:secret123 -H 'Sec-Fetch-Site: same-origin' \
-d 'name=Refactoring&sku=BK-1005&price=47.5&category_id=1' $B/products | grep ^Location
Location: http://127.0.0.1:8305/products/5
$ curl -s -b jar -c jar $B/products/5 | grep -A1 '<body>' # first visit
<body>
<p class="flash">Added Refactoring.</p>
$ curl -s -b jar -c jar $B/products/5 | grep -A1 '<body>' # refresh
<body>
<h1>Refactoring</h1>The view printed session('status') once (Flash Data and Old Input). Other targets: to_route('name', $model), redirect()->action([...]), back() and redirect()->away($url). withInput() flashes fields for old(); a failed validate() does so and redirects back(), here to /products/create from the Referer. Check user-supplied targets such as ?next=, or you build an open redirect.