Middleware Aliases and Sorting

An alias is a short name for a class. Laravel 2,157 predefines auth, auth.basic, auth.session, cache.headers, can, guest, password.confirm, precognitive, signed, throttle and verified (plus subscribed when Spark is installed), and alias([...]) adds your own: here api.key for RequireApiKey, whose handle compares the X-Api-Key header with config('services.catalog.key') through hash_equals (Hashing and HMAC) and returns a 401 JSON response on a mismatch.

Route middleware runs in assignment order, group first. On api/products/{product} the api group's SubstituteBindings therefore loads the Product before api.key runs, so an anonymous caller can probe which IDs exist, at a query per guess: without a priority entry, both requests below returned

  1. The kernel's priority list is a reference order; middleware from it that meet on one route are

re-sorted to match. The prependToPriorityList call in Registering Middleware puts RequireApiKey just before SubstituteBindings:

The key check now runs before route model bindingPHP
K='X-Api-Key: s3cret-catalog-key'; B=http://127.0.0.1:8304/api
curl -s -o /dev/null -w '%{http_code}\n' $B/products/999
curl -s -o /dev/null -w '%{http_code}\n' -H "$K" $B/products/999
curl -s -H "$K" $B/products/1; echo
Output
401
404
{"id":1,"isbn":"978-0-13-468599-1","title":"The Pragmatic Programmer","price":49.99}

The default list puts sessions and authentication before ThrottleRequests, then SubstituteBindings, and Authorize last, so can:update,product always sees a loaded model. priority([...]) replaces the list and appendToPriorityList inserts after an anchor. Priority only reorders route middleware already present; it never adds any.