Global and Group Middleware

Global Middleware and Middleware Groups

The global stack is not written anywhere in your application; the builder supplies it. Ask the HTTP kernel for the live list (php artisan route:list -v shows each route's groups and route middleware):

Listing the global middleware stackShell
php artisan tinker --execute='echo implode(PHP_EOL,
  app(Illuminate\Contracts\Http\Kernel::class)->getGlobalMiddleware());'
Output
Illuminate\Http\Middleware\ValidatePathEncoding
Illuminate\Foundation\Http\Middleware\InvokeDeferredCallbacks
Illuminate\Http\Middleware\TrustProxies
Illuminate\Http\Middleware\HandleCors
Illuminate\Foundation\Http\Middleware\PreventRequestsDuringMaintenance
Illuminate\Http\Middleware\ValidatePostSize
Illuminate\Foundation\Http\Middleware\TrimStrings
Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull
App\Http\Middleware\AddServerTiming

The defaults reject a path that is not valid UTF-8, run defer() callbacks after the response, honor X-Forwarded-* from trusted proxies (ProxyPass), answer CORS from config/cors.php, return 503 during php artisan down, refuse bodies over post_max_size with 413, and trim strings and null empty ones. The online documentation's copy of the list omits ValidatePathEncoding: trust the kernel.

A group is a named list. web holds EncryptCookies, AddQueuedCookiesToResponse, StartSession, ShareErrorsFromSession, PreventRequestForgery and SubstituteBindings; api holds only SubstituteBindings, since a token API needs no session (throttleApi() and statefulApi() add more, Sanctum for SPAs). The bookshop's catalog group, applied with Route::middleware('catalog'), bundles the key check and the locale switch. ->withoutMiddleware([...]) exempts one route from route and group middleware, never from global ones.