|
|
hai 2 semanas | |
|---|---|---|
| .. | ||
| resources | hai 2 semanas | |
| src | hai 2 semanas | |
| README.md | hai 2 semanas | |
| README.zh-CN.md | hai 2 semanas | |
| composer.json | hai 2 semanas | |
| phpunit.xml | hai 2 semanas | |
English | 中文
Webman's validation component, based on illuminate/validation, provides manual validation, annotation-based validation, parameter-level validation, and reusable rule sets.
composer require webman/validation
rules, messages, attributes, and scenes by extending support\validation\Validator, which can be reused in manual and annotation validation.#[Validate] to bind validation to controller methods.#[Param] to bind validation to controller method parameters.support\validation\ValidationException on validation failure; the exception class is configurable via config.composer require webman/database.use support\validation\Validator;
$data = ['email' => 'user@example.com'];
Validator::make($data, [
'email' => 'required|email',
])->validate();
Note
validate()will throwsupport\validation\ValidationExceptionif validation fails. If you prefer not to throw exceptions, usefails()as shown below.
use support\validation\Validator;
$data = ['contact' => 'user@example.com'];
Validator::make(
$data,
['contact' => 'required|email'],
['contact.email' => 'Invalid email format'],
['contact' => 'Email']
)->validate();
If you don't want exceptions, use fails() and read errors from the MessageBag:
use support\validation\Validator;
$data = ['email' => 'bad-email'];
$validator = Validator::make($data, [
'email' => 'required|email',
]);
if ($validator->fails()) {
$firstError = $validator->errors()->first(); // string
$allErrors = $validator->errors()->all(); // array
$errorsByField = $validator->errors()->toArray(); // array
// handle errors...
}
namespace app\validation;
use support\validation\Validator;
class UserValidator extends Validator
{
protected array $rules = [
'id' => 'required|integer|min:1',
'name' => 'required|string|min:2|max:20',
'email' => 'required|email',
];
protected array $messages = [
'name.required' => 'Name is required',
'email.required' => 'Email is required',
'email.email' => 'Invalid email format',
];
protected array $attributes = [
'name' => 'Name',
'email' => 'Email',
];
}
use app\validation\UserValidator;
UserValidator::make($data)->validate();
Scenes are optional. They are only used when you call withScene(...) to validate a subset of fields.
namespace app\validation;
use support\validation\Validator;
class UserValidator extends Validator
{
protected array $rules = [
'id' => 'required|integer|min:1',
'name' => 'required|string|min:2|max:20',
'email' => 'required|email',
];
protected array $scenes = [
'create' => ['name', 'email'],
'update' => ['id', 'name', 'email'],
];
}
use app\validation\UserValidator;
// No scene specified -> validate all rules
UserValidator::make($data)->validate();
// Specify scene -> validate only fields in that scene
UserValidator::make($data)->withScene('create')->validate();
use support\Request;
use support\validation\annotation\Validate;
class AuthController
{
#[Validate(
rules: [
'email' => 'required|email',
'password' => 'required|string|min:6',
],
messages: [
'email.required' => 'Email is required',
'password.required' => 'Password is required',
],
attributes: [
'email' => 'Email',
'password' => 'Password',
]
)]
public function login(Request $request)
{
return json(['code' => 0, 'msg' => 'ok']);
}
}
use app\validation\UserValidator;
use support\Request;
use support\validation\annotation\Validate;
class UserController
{
#[Validate(validator: UserValidator::class, scene: 'create')]
public function create(Request $request)
{
return json(['code' => 0, 'msg' => 'ok']);
}
}
use support\validation\annotation\Validate;
class UserController
{
#[Validate(rules: ['email' => 'required|email'])]
#[Validate(rules: ['token' => 'required|string'])]
public function send()
{
return json(['code' => 0, 'msg' => 'ok']);
}
}
use support\validation\annotation\Validate;
class UserController
{
#[Validate(
rules: ['email' => 'required|email'],
in: ['query', 'body', 'path']
)]
public function send()
{
return json(['code' => 0, 'msg' => 'ok']);
}
}
Use in to specify where validation data comes from:
$request->get()$request->post()$request->route->param()in can be a string or array; when it's an array, values are merged in order and later sources override earlier ones. When in is omitted, it defaults to the equivalent of ['query', 'body', 'path'].
use support\validation\annotation\Param;
class MailController
{
public function send(
#[Param(rules: 'required|email')] string $from,
#[Param(rules: 'required|email')] string $to,
#[Param(rules: 'required|string|min:1|max:500')] string $content
) {
return json(['code' => 0, 'msg' => 'ok']);
}
}
Parameter-level validation also supports the in parameter to specify data source:
use support\validation\annotation\Param;
class MailController
{
public function send(
#[Param(rules: 'required|email', in: ['body'])] string $from
) {
return json(['code' => 0, 'msg' => 'ok']);
}
}
use support\validation\annotation\Param;
class MailController
{
public function send(
#[Param(rules: ['required', 'email'])] string $from
) {
return json(['code' => 0, 'msg' => 'ok']);
}
}
use support\validation\annotation\Param;
class UserController
{
public function updateEmail(
#[Param(
rules: 'required|email',
messages: ['email.email' => 'Invalid email format'],
attribute: 'Email'
)]
string $email
) {
return json(['code' => 0, 'msg' => 'ok']);
}
}
final class ParamRules
{
public const EMAIL = ['required', 'email'];
}
class UserController
{
public function send(
#[Param(rules: ParamRules::EMAIL)] string $email
) {
return json(['code' => 0, 'msg' => 'ok']);
}
}
use support\Request;
use support\validation\annotation\Param;
use support\validation\annotation\Validate;
class UserController
{
#[Validate(rules: ['token' => 'required|string'])]
public function send(
Request $request,
#[Param(rules: 'required|email')] string $from,
#[Param(rules: 'required|integer')] int $id
) {
return json(['code' => 0, 'msg' => 'ok']);
}
}
When a method uses #[Validate], or any parameter on that method uses #[Param], this package will infer and auto-complete basic validation rules from the PHP method signature, then merge them with your existing rules and run validation.
#[Validate] Equivalent Expansion1) Enable #[Validate] without writing rules:
use support\validation\annotation\Validate;
class DemoController
{
#[Validate]
public function create(string $content, int $uid)
{
}
}
Equivalent to:
use support\validation\annotation\Validate;
class DemoController
{
#[Validate(rules: [
'content' => 'required|string',
'uid' => 'required|integer',
])]
public function create(string $content, int $uid)
{
}
}
2) Only partial rules provided, the rest is inferred:
use support\validation\annotation\Validate;
class DemoController
{
#[Validate(rules: [
'content' => 'min:2',
])]
public function create(string $content, int $uid)
{
}
}
Equivalent to:
use support\validation\annotation\Validate;
class DemoController
{
#[Validate(rules: [
'content' => 'required|string|min:2',
'uid' => 'required|integer',
])]
public function create(string $content, int $uid)
{
}
}
3) Default values / nullable types:
use support\validation\annotation\Validate;
class DemoController
{
#[Validate]
public function create(string $content = 'default', ?int $uid = null)
{
}
}
Equivalent to:
use support\validation\annotation\Validate;
class DemoController
{
#[Validate(rules: [
'content' => 'string',
'uid' => 'integer|nullable',
])]
public function create(string $content = 'default', ?int $uid = null)
{
}
}
Validation failure throws support\validation\ValidationException, which inherits from Webman\Exception\BusinessException and does not log errors.
Default response behavior is handled by BusinessException::render():
token is required.{"code": 422, "msg": "token is required.", "data":....}exception in config/plugin/webman/validation/app.phpThe component includes built-in Chinese and English language packs and supports project overrides. Loading order:
resource/translations/{locale}/validation.phpvendor/webman/validation/resources/lang/{locale}/validation.phpNote
The default language of webman is configured inconfig/translation.php, and it can also be changed using the functionlocale('en');.
resource/translations/en/validation.php
return [
'email' => 'The :attribute is not a valid email format.',
];
After installation, the component automatically loads the validation middleware via config/plugin/webman/validation/middleware.php, no manual registration required.
Use make:validator to generate a validator class (generated under app/validation by default).
Tip
You need to installcomposer require webman/console
Generate an empty template
php webman make:validator UserValidator
Overwrite if the file already exists
php webman make:validator UserValidator --force
php webman make:validator UserValidator -f
Generate rules from a table schema (infers $rules from column type/nullability/length; default excluded columns depend on ORM: laravel uses created_at/updated_at/deleted_at, thinkorm uses create_time/update_time/delete_time)
php webman make:validator UserValidator --table=wa_users
php webman make:validator UserValidator -t wa_users
Select a database connection (multi-connection)
php webman make:validator UserValidator --table=wa_users --database=mysql
php webman make:validator UserValidator -t wa_users -d mysql
Generate CRUD scenes: create/update/delete/detail
php webman make:validator UserValidator --table=wa_users --scenes=crud
php webman make:validator UserValidator -t wa_users -s crud
The
updatescene includes the primary key (to locate the record) plus the other fields;delete/detailinclude only primary key fields by default.
Force
php webman make:validator UserValidator --table=wa_users --orm=laravel
php webman make:validator UserValidator --table=wa_users --orm=thinkorm
php webman make:validator UserValidator -t wa_users -o thinkorm
php webman make:validator UserValidator -t wa_users -d mysql -s crud -o laravel -f
Enter the webman/validation root directory and execute:
composer install
vendor\bin\phpunit -c phpunit.xml
[!IMPORTANT]
- Webman Validation is based on
illuminate/validation, with rule names consistent with Laravel, and the rules themselves have no Webman-specific modifications.- The middleware validates data from
$request->all()(GET+POST) by default and merges route parameters, excluding uploaded files; for file-related rules, manually merge$request->file()into the data or callValidator::makemanually.current_passworddepends on authentication guards,exists/uniquedepend on database connections and query builders, and these rules are unavailable without integrating the corresponding components.
The following lists all available validation rules and their functions:
The field under validation must be "yes", "on", 1, "1", true, or "true". This is commonly used for scenarios like confirming agreement to terms of service.
The field under validation must be "yes", "on", 1, "1", true, or "true" when another field equals the specified value. This is useful for conditional agreement scenarios.
The field under validation must have a valid A or AAAA record. The rule first extracts the hostname using parse_url and then validates it with dns_get_record.
The field under validation must be a value after the given date. The date is converted to a valid DateTime using strtotime:
use support\validation\Validator;
Validator::make($data, [
'start_date' => 'required|date|after:tomorrow',
])->validate();
You can also pass another field name for comparison:
Validator::make($data, [
'finish_date' => 'required|date|after:start_date',
])->validate();
You can use the fluent date rule builder:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'start_date' => [
'required',
Rule::date()->after(\Carbon\Carbon::today()->addDays(7)),
],
])->validate();
afterToday and todayOrAfter can conveniently express "must be after today" or "must be today or later":
Validator::make($data, [
'start_date' => [
'required',
Rule::date()->afterToday(),
],
])->validate();
The field under validation must be after or equal to the given date. For more details, see the after rule.
You can use the fluent date rule builder:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'start_date' => [
'required',
Rule::date()->afterOrEqual(\Carbon\Carbon::today()->addDays(7)),
],
])->validate();
Rule::anyOf allows specifying "pass if any one of the rule sets is satisfied". For example, the following rule means username is either an email address or an alphanumeric string with underscores/dashes of at least 6 characters:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'username' => [
'required',
Rule::anyOf([
['string', 'email'],
['string', 'alpha_dash', 'min:6'],
]),
],
])->validate();
The field under validation must consist of Unicode letters (\p{L} and \p{M}).
To allow only ASCII (a-z, A-Z), add the ascii option:
Validator::make($data, [
'username' => 'alpha:ascii',
])->validate();
The field under validation can only contain Unicode alphanumeric characters (\p{L}, \p{M}, \p{N}), as well as ASCII dashes (-) and underscores (_).
To allow only ASCII (a-z, A-Z, 0-9), add the ascii option:
Validator::make($data, [
'username' => 'alpha_dash:ascii',
])->validate();
The field under validation can only contain Unicode alphanumeric characters (\p{L}, \p{M}, \p{N}).
To allow only ASCII (a-z, A-Z, 0-9), add the ascii option:
Validator::make($data, [
'username' => 'alpha_num:ascii',
])->validate();
The field under validation must be a PHP array.
When the array rule includes additional parameters, the keys in the input array must be in the parameter list. In the example, the admin key is not in the allowed list, so it is invalid:
use support\validation\Validator;
$input = [
'user' => [
'name' => 'Taylor Otwell',
'username' => 'taylorotwell',
'admin' => true,
],
];
Validator::make($input, [
'user' => 'array:name,username',
])->validate();
It is recommended to explicitly specify the allowed keys for arrays in actual projects.
The field under validation can only contain 7-bit ASCII characters.
When the first validation rule for a field fails, stop validating the other rules for that field.
This rule only affects the current field. For "stop on first failure globally", use Illuminate's validator directly and call stopOnFirstFailure().
The field under validation must be before the given date. The date is converted to a valid DateTime using strtotime. Similar to the after rule, you can pass another field name for comparison.
You can use the fluent date rule builder:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'start_date' => [
'required',
Rule::date()->before(\Carbon\Carbon::today()->subDays(7)),
],
])->validate();
beforeToday and todayOrBefore can conveniently express "must be before today" or "must be today or earlier":
Validator::make($data, [
'start_date' => [
'required',
Rule::date()->beforeToday(),
],
])->validate();
The field under validation must be before or equal to the given date. The date is converted to a valid DateTime using strtotime. Similar to the after rule, you can pass another field name for comparison.
You can use the fluent date rule builder:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'start_date' => [
'required',
Rule::date()->beforeOrEqual(\Carbon\Carbon::today()->subDays(7)),
],
])->validate();
The field under validation must have a size between the given min and max (inclusive). Strings, numbers, arrays, and files are evaluated using the same rules as size.
The field under validation must be convertible to a boolean value. Acceptable inputs include true, false, 1, 0, "1", "0".
You can use the strict parameter to allow only true or false:
Validator::make($data, [
'foo' => 'boolean:strict',
])->validate();
The field under validation must have a matching field {field}_confirmation. For example, if the field is password, password_confirmation is required.
You can also specify a custom confirmation field name, such as confirmed:repeat_username, which requires repeat_username to match the current field.
The field under validation must be an array and must contain all the given parameter values. This rule is often used for array validation and can be constructed using Rule::contains:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'roles' => [
'required',
'array',
Rule::contains(['admin', 'editor']),
],
])->validate();
The field under validation must be an array and must not contain any of the given parameter values. You can use Rule::doesntContain to construct:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'roles' => [
'required',
'array',
Rule::doesntContain(['admin', 'editor']),
],
])->validate();
The field under validation must match the current authenticated user's password. You can specify the authentication guard via the first parameter:
Validator::make($data, [
'password' => 'current_password:api',
])->validate();
[!WARNING] This rule depends on the authentication component and guard configuration; do not use it without integrating authentication.
The field under validation must be a valid (non-relative) date recognized by strtotime.
The field under validation must equal the given date. The date is converted to a valid DateTime using strtotime.
The field under validation must match one of the given formats. Use either date or date_format. This rule supports all formats of PHP DateTime.
You can use the fluent date rule builder:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'start_date' => [
'required',
Rule::date()->format('Y-m-d'),
],
])->validate();
The field under validation must be a number with the specified number of decimal places:
Validator::make($data, [
'price' => 'decimal:2',
])->validate();
Validator::make($data, [
'price' => 'decimal:2,4',
])->validate();
The field under validation must be "no", "off", 0, "0", false, or "false".
The field under validation must be "no", "off", 0, "0", false, or "false" when another field equals the specified value.
The field under validation must be different from field.
The field under validation must be an integer with a length of value.
The field under validation must be an integer with a length between min and max.
The field under validation must be an image and satisfy the dimension constraints:
Validator::make($data, [
'avatar' => 'dimensions:min_width=100,min_height=200',
])->validate();
Available constraints: _minwidth, _maxwidth, _minheight, _maxheight, width, height, ratio.
ratio is the aspect ratio, which can be expressed as a fraction or float:
Validator::make($data, [
'avatar' => 'dimensions:ratio=3/2',
])->validate();
Due to the many parameters in this rule, it is recommended to use Rule::dimensions to construct:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'avatar' => [
'required',
Rule::dimensions()
->maxWidth(1000)
->maxHeight(500)
->ratio(3 / 2),
],
])->validate();
When validating an array, the field values must not be duplicated:
Validator::make($data, [
'foo.*.id' => 'distinct',
])->validate();
By default, loose comparison is used. For strict comparison, add strict:
Validator::make($data, [
'foo.*.id' => 'distinct:strict',
])->validate();
You can add ignore_case to ignore case differences:
Validator::make($data, [
'foo.*.id' => 'distinct:ignore_case',
])->validate();
The field under validation must not start with the specified values.
The field under validation must not end with the specified values.
The field under validation must be a valid email address. This rule relies on egulias/email-validator, defaulting to RFCValidation, but other validation methods can be specified:
Validator::make($data, [
'email' => 'email:rfc,dns',
])->validate();
Available validation methods:
You can use the fluent rule builder:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [
'required',
Rule::email()
->rfcCompliant(strict: false)
->validateMxRecord()
->preventSpoofing(),
],
])->validate();
[!WARNING]
dnsandspoofrequire the PHPintlextension.
The field under validation must match the specified character encoding. This rule uses mb_check_encoding to detect the encoding of files or strings. It can be used with the file rule builder:
use Illuminate\Validation\Rules\File;
use support\validation\Validator;
Validator::make($data, [
'attachment' => [
'required',
File::types(['csv'])->encoding('utf-8'),
],
])->validate();
The field under validation must end with one of the specified values.
Enum is a class-based rule used to validate if the field value is a valid enum value. Pass the enum class name during construction. For validating basic type values, use Backed Enum:
use app\enums\ServerStatus;
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'status' => [Rule::enum(ServerStatus::class)],
])->validate();
You can use only/except to restrict enum values:
use app\enums\ServerStatus;
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'status' => [
Rule::enum(ServerStatus::class)
->only([ServerStatus::Pending, ServerStatus::Active]),
],
])->validate();
Validator::make($data, [
'status' => [
Rule::enum(ServerStatus::class)
->except([ServerStatus::Pending, ServerStatus::Active]),
],
])->validate();
You can use when for conditional restrictions:
use app\Enums\ServerStatus;
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'status' => [
Rule::enum(ServerStatus::class)->when(
$isAdmin,
fn ($rule) => $rule->only(ServerStatus::Active),
fn ($rule) => $rule->only(ServerStatus::Pending),
),
],
])->validate();
The field under validation will be excluded from the data returned by validate/validated.
The field under validation will be excluded from the data returned by validate/validated when anotherfield equals value.
For complex conditions, use Rule::excludeIf:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'role_id' => Rule::excludeIf($isAdmin),
])->validate();
Validator::make($data, [
'role_id' => Rule::excludeIf(fn () => $isAdmin),
])->validate();
The field under validation will be excluded from the data returned by validate/validated unless anotherfield equals value. If value is null (e.g., exclude_unless:name,null), the field is retained only if the comparison field is null or does not exist.
The field under validation will be excluded from the data returned by validate/validated when anotherfield exists.
The field under validation will be excluded from the data returned by validate/validated when anotherfield does not exist.
The field under validation must exist in the specified database table.
Validator::make($data, [
'state' => 'exists:states',
])->validate();
If column is not specified, the field name is used by default. Thus, this example validates if the state column exists in the states table.
You can append the column name after the table name:
Validator::make($data, [
'state' => 'exists:states,abbreviation',
])->validate();
To specify a database connection, prepend the connection name to the table:
Validator::make($data, [
'email' => 'exists:connection.staff,email',
])->validate();
You can also pass a model class name, and the framework will resolve the table name:
Validator::make($data, [
'user_id' => 'exists:app\model\User,id',
])->validate();
To customize query conditions, use the Rule rule builder:
use Illuminate\Database\Query\Builder;
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [
'required',
Rule::exists('staff')->where(function (Builder $query) {
$query->where('account_id', 1);
}),
],
])->validate();
You can also specify the column name directly in Rule::exists:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'state' => [Rule::exists('states', 'abbreviation')],
])->validate();
When validating if a group of values exists, combine with the array rule:
Validator::make($data, [
'states' => ['array', Rule::exists('states', 'abbreviation')],
])->validate();
When array and exists coexist, a single query is generated to validate all values.
The uploaded file's extension must be in the allowed list:
Validator::make($data, [
'photo' => ['required', 'extensions:jpg,png'],
])->validate();
[!WARNING] Do not rely solely on extension validation for file types; it is recommended to use it with mimes or mimetypes.
The field under validation must be a successfully uploaded file.
When the field exists, its value must not be empty.
The field under validation must be greater than the given field or value. The two fields must be of the same type. Strings, numbers, arrays, and files are evaluated using the same rules as size.
The field under validation must be greater than or equal to the given field or value. The two fields must be of the same type. Strings, numbers, arrays, and files are evaluated using the same rules as size.
The field under validation must be a valid hexadecimal color value.
The field under validation must be an image (jpg, jpeg, png, bmp, gif, or webp).
[!WARNING] SVG is not allowed by default due to XSS risks. To allow it, add
allow_svg:image:allow_svg.
The field under validation must be in the given list of values. You can use Rule::in to construct:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'zones' => [
'required',
Rule::in(['first-zone', 'second-zone']),
],
])->validate();
When combined with the array rule, every value in the input array must be in the in list:
use support\validation\Rule;
use support\validation\Validator;
$input = [
'airports' => ['NYC', 'LAS'],
];
Validator::make($input, [
'airports' => [
'required',
'array',
],
'airports.*' => Rule::in(['NYC', 'LIT']),
])->validate();
The field under validation must exist in the value list of anotherfield.
The field under validation must be an array and must contain at least one of the given values as a key:
Validator::make($data, [
'config' => 'array|in_array_keys:timezone',
])->validate();
The field under validation must be an integer.
You can use the strict parameter to require the field type to be integer; string representations of integers will be considered invalid:
Validator::make($data, [
'age' => 'integer:strict',
])->validate();
[!WARNING] This rule only checks if it passes PHP's
FILTER_VALIDATE_INT; to enforce numeric types, use it with numeric.
The field under validation must be a valid IP address.
The field under validation must be a valid IPv4 address.
The field under validation must be a valid IPv6 address.
The field under validation must be a valid JSON string.
The field under validation must be less than the given field. The two fields must be of the same type. Strings, numbers, arrays, and files are evaluated using the same rules as size.
The field under validation must be less than or equal to the given field. The two fields must be of the same type. Strings, numbers, arrays, and files are evaluated using the same rules as size.
The field under validation must be lowercase.
The field under validation must be a list array. The keys in a list array must be consecutive numbers from 0 to count($array) - 1.
The field under validation must be a valid MAC address.
The field under validation must be less than or equal to value. Strings, numbers, arrays, and files are evaluated using the same rules as size.
The field under validation must be an integer with a length not exceeding value.
The file's MIME type must be in the list:
Validator::make($data, [
'video' => 'mimetypes:video/avi,video/mpeg,video/quicktime',
])->validate();
The MIME type is guessed by reading the file content, which may differ from the client-provided MIME.
The file's MIME type must correspond to the given extension:
Validator::make($data, [
'photo' => 'mimes:jpg,bmp,png',
])->validate();
Although the parameters are extensions, this rule reads the file content to determine the MIME. The extension-to-MIME mapping is from:
https://svn.apache.org/repos/asf/httpd/httpd/trunk/docs/conf/mime.types
This rule does not validate if the "filename extension" matches the "actual MIME". For example, mimes:png will consider photo.txt with PNG content as valid. To validate extensions, use extensions.
The field under validation must be greater than or equal to value. Strings, numbers, arrays, and files are evaluated using the same rules as size.
The field under validation must be an integer with a length of at least value.
The field under validation must be a multiple of value.
The field under validation must not exist in the input data.
The field under validation must not exist when anotherfield equals any value.
The field under validation must not exist unless anotherfield equals any value.
The field under validation must not exist when any of the specified fields exist.
The field under validation must not exist when all specified fields exist.
The field under validation must not be in the given list of values. You can use Rule::notIn to construct:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'toppings' => [
'required',
Rule::notIn(['sprinkles', 'cherries']),
],
])->validate();
The field under validation must not match the given regular expression.
This rule uses PHP preg_match. The regex must include delimiters, e.g., 'email' => 'not_regex:/^.+$/i'.
[!WARNING] When using
regex/not_regex, if the regex contains|, it is recommended to declare rules in array form to avoid conflicts with the|separator.
The field under validation may be null.
The field under validation must be numeric.
You can use the strict parameter to allow only integer or float types; numeric strings will be considered invalid:
Validator::make($data, [
'amount' => 'numeric:strict',
])->validate();
The field under validation must exist in the input data.
The field under validation must exist when anotherfield equals any value.
The field under validation must exist unless anotherfield equals any value.
The field under validation must exist when any of the specified fields exist.
The field under validation must exist when all specified fields exist.
The field under validation must be missing or empty. A field is "empty" if:
The field under validation must be missing or empty when anotherfield equals any value. A field is "empty" if:
For complex conditions, use Rule::prohibitedIf:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'role_id' => Rule::prohibitedIf($isAdmin),
])->validate();
Validator::make($data, [
'role_id' => Rule::prohibitedIf(fn () => $isAdmin),
])->validate();
The field under validation must be missing or empty when anotherfield is "yes", "on", 1, "1", true, or "true".
The field under validation must be missing or empty when anotherfield is "no", "off", 0, "0", false, or "false".
The field under validation must be missing or empty unless anotherfield equals any value. A field is "empty" if:
When the field under validation exists and is not empty, all fields in anotherfield must be missing or empty. A field is "empty" if:
The field under validation must match the given regular expression.
This rule uses PHP preg_match. The regex must include delimiters, e.g., 'email' => 'regex:/^.+@.+$/i'.
[!WARNING] When using
regex/not_regex, if the regex contains|, it is recommended to declare rules in array form to avoid conflicts with the|separator.
The field under validation must exist and not be empty. A field is "empty" if:
The field under validation must exist and not be empty when anotherfield equals any value.
For complex conditions, use Rule::requiredIf:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'role_id' => Rule::requiredIf($isAdmin),
])->validate();
Validator::make($data, [
'role_id' => Rule::requiredIf(fn () => $isAdmin),
])->validate();
The field under validation must exist and not be empty when anotherfield is "yes", "on", 1, "1", true, or "true".
The field under validation must exist and not be empty when anotherfield is "no", "off", 0, "0", false, or "false".
The field under validation must exist and not be empty unless anotherfield equals any value. If value is null (e.g., required_unless:name,null), the field is allowed to be empty only if the comparison field is null or does not exist.
The field under validation must exist and not be empty when any specified field exists and is not empty.
The field under validation must exist and not be empty when all specified fields exist and are not empty.
The field under validation must exist and not be empty when any specified field is empty or does not exist.
The field under validation must exist and not be empty when all specified fields are empty or do not exist.
The field under validation must be an array and must contain at least the specified keys.
Apply subsequent validation rules only when the field exists. Commonly used for fields that are "optional but must be valid if present":
Validator::make($data, [
'nickname' => 'sometimes|string|max:20',
])->validate();
The field under validation must be the same as field.
The field under validation must have a size equal to the given value. For strings, it is the character count; for numbers, it is the specified integer (use with numeric or integer); for arrays, it is the element count; for files, it is the size in KB. Example:
Validator::make($data, [
'title' => 'size:12',
'seats' => 'integer|size:10',
'tags' => 'array|size:5',
'image' => 'file|size:512',
])->validate();
The field under validation must start with one of the specified values.
The field under validation must be a string. To allow null, use with nullable.
The field under validation must be a valid timezone identifier (from DateTimeZone::listIdentifiers). Parameters supported by this method can be passed:
Validator::make($data, [
'timezone' => 'required|timezone:all',
])->validate();
Validator::make($data, [
'timezone' => 'required|timezone:Africa',
])->validate();
Validator::make($data, [
'timezone' => 'required|timezone:per_country,US',
])->validate();
The field under validation must be unique in the specified table.
Specifying Custom Table/Column Names:
You can directly specify the model class name:
Validator::make($data, [
'email' => 'unique:app\model\User,email_address',
])->validate();
You can specify the column name (defaults to the field name if not specified):
Validator::make($data, [
'email' => 'unique:users,email_address',
])->validate();
Specifying Database Connection:
Validator::make($data, [
'email' => 'unique:connection.users,email_address',
])->validate();
Ignoring a Specific ID:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [
'required',
Rule::unique('users')->ignore($user->id),
],
])->validate();
[!WARNING]
ignoreshould not receive user input; only use system-generated unique IDs (auto-increment IDs or model UUIDs), otherwise there may be SQL injection risks.
You can also pass a model instance:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [
Rule::unique('users')->ignore($user),
],
])->validate();
If the primary key is not id, specify the primary key name:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [
Rule::unique('users')->ignore($user->id, 'user_id'),
],
])->validate();
By default, the field name is used as the unique column, but you can specify the column name:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [
Rule::unique('users', 'email_address')->ignore($user->id),
],
])->validate();
Adding Extra Conditions:
use Illuminate\Database\Query\Builder;
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [
Rule::unique('users')->where(
fn (Builder $query) => $query->where('account_id', 1)
),
],
])->validate();
Ignoring Soft-Deleted Records:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [Rule::unique('users')->withoutTrashed()],
])->validate();
If the soft-delete column name is not deleted_at:
use support\validation\Rule;
use support\validation\Validator;
Validator::make($data, [
'email' => [Rule::unique('users')->withoutTrashed('was_deleted_at')],
])->validate();
The field under validation must be uppercase.
The field under validation must be a valid URL.
You can specify allowed protocols:
Validator::make($data, [
'url' => 'url:http,https',
'game' => 'url:minecraft,steam',
])->validate();
The field under validation must be a valid ULID.
The field under validation must be a valid RFC 9562 UUID (versions 1, 3, 4, 5, 6, 7, or 8).
You can specify the version:
Validator::make($data, [
'uuid' => 'uuid:4',
])->validate();