That redirect flashed the messages and the input (minus password, password_confirmation and current_password) for one request. The web group's ShareErrorsFromSession middleware gives every view an $errors bag, and old('field') reads the input back. The review form wraps a summary in @if ($errors->any()) and writes each field like <textarea name="body" @error('body') aria-invalid="true" @enderror>{{ old('body') }}</textarea> plus @error('body') <small>{{ $message }}</small> @enderror, $message being the first error. After posting author=Bob&rating=&body=Great!! with a cookie jar, the redirected GET returned:
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@picocss/pico@2/css/pico.min.css">
<main class="container">
<h2>Review The Pragmatic Programmer</h2>
<p role="alert"><mark>Please correct 2 fields.</mark></p>
<form method="POST" action="http://127.0.0.1:8308/products/1/reviews">
<input type="hidden" name="_token" value="Wg6n0XhVapKM4iXa6CJ9DizgI69BV4iKrBeGbjQX" autocomplete="off">
<label>Your name
<input name="author" value="Bob"
>
</label>
<label>Rating (1-5)
<input name="rating" type="number" value=""
aria-invalid="true" >
<small>The rating field is required.</small> </label>
<label>Review
<textarea name="body" rows="2"
aria-invalid="true" >Great!!</textarea>
<small>The body field must be at least 20 characters.</small> </label>
<button>Submit review</button>
</form>
</main>
Pico CSS paints aria-invalid fields red. A second GET showed neither errors nor "Bob". Edit forms pass a fallback, old('name', $product->name). For two forms on a page, validateWithBag('review', [...]) stores the messages as $errors->review, read by @error('body', 'review').