Skip to content

Build1 publisherNot yet confirmed elsewhere2 min readPublished

Laravel 13.35 lets search routes take their filters in an HTTP QUERY body

Laravel 13.35, released October 7, adds Route::query() so search requests can carry complex filters in an HTTP QUERY body. Routes in the web middleware group still go through CSRF checks, so browser clients may need a token, according to a dev.to walkthrough.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Laravel 13.35 lets search routes take their filters in an HTTP QUERY body
Generated illustration

What happened

  • According to the dev.to walkthrough, Laravel's routing documentation now lists query() alongside the standard HTTP route methods.
  • Eloquent models can opt into a new HasDefaultAttributes trait and define a defaults() method that calculates default attributes.
  • Queue, bus, event and notification fake assertions now accept property arrays for checking specific properties on dispatched objects.
  • The release also brings percentage-based queue memory limits and scheduler improvements for multi-server deployments.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Teams moving a browser search to QUERY have two options: send a CSRF token from the client, or design the route's protection outside the web group's defaults on purpose.
  • cost Runtime defaults cost one trait per model, so a codebase full of static $attributes arrays can move over one class at a time.
  • constraint Operators who size worker memory caps by hand need Laravel's own queue documentation before trading a fixed cap for a percentage.

Registering a QUERY route takes one call: Route::query('/products/search', SearchProductsController::class) [1]. The walkthrough's case for it is an advanced product search sent as a JSON body [3]. That body holds two categories, two brands, a price range of 500 to 2000 and a list of required features such as 16GB RAM and Wi-Fi 6 [3].

The GET version of the same search spreads it across six query-string parameters, with brands and features packed into comma-separated values [4][15]. The post's own example gives up at the sixth parameter and ends in an ellipsis [4]. The post says GET "works perfectly for simple searches" [5]. QUERY covers the rest, carrying query data in the body while the request stays safe and idempotent [7].

QUERY is a safe method by definition [7], yet a QUERY route inside Laravel's web middleware group still goes through CSRF protection [8]. I think CSRF by default is the right call for a method the framework has only just started routing. Lifting the check should be a decision someone makes on purpose and can defend at review. The walkthrough's author wrote: "So don't treat QUERY as a shortcut for bypassing Laravel's security mechanisms." [13]

Before moving an existing search off GET, I would also confirm that the load balancer and any cache in front of the application pass an unfamiliar method through intact. A route that registers cleanly in the framework still depends on every hop before it.

Static Eloquent defaults have lived in the $attributes array as fixed values, such as 'trial_days' => 14 [12]. Under the new defaults() method, the post's example returns 30 trial days when Feature::active('extended-trials') is on and 14 when it is off [10]. The same method can pull a country from config('app.default_country') or set trial_ends_at to now()->addDays(14) [14]. Those values are computed at runtime [9].

The queue memory change is the thinnest part of the record. The post's summary lists percentage-based limits without saying what the percentage is measured against [16]. Whether a percentage is safer than a fixed cap for a given worker pool turns on that base.

What to watch

  • Laravel's queue documentation for 13.35 stating what the percentage memory limit is calculated against.
  • Any later Laravel release that exempts QUERY routes from CSRF checks in the web middleware group.
  • Whether the proxies and HTTP clients in front of Laravel apps accept QUERY requests without modification.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence40
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence45
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Laravel 13.35 adds a Route::query() method that registers a route for the HTTP QUERY method, for example Route::query('/products/search', SearchProductsController::class).

    ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source
  2. [2]

    Laravel's current routing documentation now lists query() alongside the standard HTTP route methods.

    ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source
  3. [3]

    The post's example advanced product search is a JSON body with categories laptops and monitors, brands Dell and Lenovo, a price range of min 500 and max 2000, and features 16GB RAM, SSD and Wi-Fi 6.

    ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 8, 2026

    Laravel 13.35: New QUERY Routes, Smarter Model Defaults & Queue Improvements

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories