Build1 publisherNot yet confirmed elsewhere2 min readPublished
Laravel 13.35 lets search routes take their filters in an HTTP QUERY body
Laravel 13.35, released October 7, adds Route::query() so search requests can carry complex filters in an HTTP QUERY body. Routes in the web middleware group still go through CSRF checks, so browser clients may need a token, according to a dev.to walkthrough.
The Engineer · Build desk

What happened
- According to the dev.to walkthrough, Laravel's routing documentation now lists query() alongside the standard HTTP route methods.
- Eloquent models can opt into a new HasDefaultAttributes trait and define a defaults() method that calculates default attributes.
- Queue, bus, event and notification fake assertions now accept property arrays for checking specific properties on dispatched objects.
- The release also brings percentage-based queue memory limits and scheduler improvements for multi-server deployments.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Teams moving a browser search to QUERY have two options: send a CSRF token from the client, or design the route's protection outside the web group's defaults on purpose.
- cost Runtime defaults cost one trait per model, so a codebase full of static $attributes arrays can move over one class at a time.
- constraint Operators who size worker memory caps by hand need Laravel's own queue documentation before trading a fixed cap for a percentage.
Registering a QUERY route takes one call: Route::query('/products/search', SearchProductsController::class) [1]. The walkthrough's case for it is an advanced product search sent as a JSON body [3]. That body holds two categories, two brands, a price range of 500 to 2000 and a list of required features such as 16GB RAM and Wi-Fi 6 [3].
The GET version of the same search spreads it across six query-string parameters, with brands and features packed into comma-separated values [4][15]. The post's own example gives up at the sixth parameter and ends in an ellipsis [4]. The post says GET "works perfectly for simple searches" [5]. QUERY covers the rest, carrying query data in the body while the request stays safe and idempotent [7].
QUERY is a safe method by definition [7], yet a QUERY route inside Laravel's web middleware group still goes through CSRF protection [8]. I think CSRF by default is the right call for a method the framework has only just started routing. Lifting the check should be a decision someone makes on purpose and can defend at review. The walkthrough's author wrote: "So don't treat QUERY as a shortcut for bypassing Laravel's security mechanisms." [13]
Before moving an existing search off GET, I would also confirm that the load balancer and any cache in front of the application pass an unfamiliar method through intact. A route that registers cleanly in the framework still depends on every hop before it.
Static Eloquent defaults have lived in the $attributes array as fixed values, such as 'trial_days' => 14 [12]. Under the new defaults() method, the post's example returns 30 trial days when Feature::active('extended-trials') is on and 14 when it is off [10]. The same method can pull a country from config('app.default_country') or set trial_ends_at to now()->addDays(14) [14]. Those values are computed at runtime [9].
The queue memory change is the thinnest part of the record. The post's summary lists percentage-based limits without saying what the percentage is measured against [16]. Whether a percentage is safer than a fixed cap for a given worker pool turns on that base.
What to watch
- Laravel's queue documentation for 13.35 stating what the percentage memory limit is calculated against.
- Any later Laravel release that exempts QUERY routes from CSRF checks in the web middleware group.
- Whether the proxies and HTTP clients in front of Laravel apps accept QUERY requests without modification.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Laravel 13.35 adds a Route::query() method that registers a route for the HTTP QUERY method, for example Route::query('/products/search', SearchProductsController::class).
ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source - [2]
Laravel's current routing documentation now lists query() alongside the standard HTTP route methods.
ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source - [3]
The post's example advanced product search is a JSON body with categories laptops and monitors, brands Dell and Lenovo, a price range of min 500 and max 2000, and features 16GB RAM, SSD and Wi-Fi 6.
ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source - [4]
The post's GET alternative is /products? with category=laptops, brand=dell,lenovo, price_min=500, price_max=2000, features=16gb,ssd,wifi6 and availability=... ending in an ellipsis.
ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source - [5]
A traditional GET search endpoint such as GET /products?category=laptops&brand=dell&ram=16gb "works perfectly for simple searches."
ReportedSupportedSource: dev.to walkthrough2 sources— create a free account to open themView cited source - [6]
Laravel 13.35 was released on October 7, 2026.
- [7]
The HTTP QUERY method is designed for requests that need to send query information in a request body while remaining safe and idempotent.
- [8]
When a QUERY route is placed in Laravel's web middleware group, it remains subject to CSRF protection, so a browser-based QUERY request may require a CSRF token like other state-sensitive requests handled by the web middleware stack.
- [9]
Laravel 13.35 introduces an opt-in HasDefaultAttributes trait that lets Eloquent models define a defaults() method so default attributes can be determined at runtime.
- [10]
In the post's example, defaults() sets 'trial_days' to 30 when Feature::active('extended-trials') is true and 14 otherwise, with 'cancelled' defaulting to false.
- [11]
Property arrays can now be used with queue, bus, event, and notification fake assertions, for checking specific properties on dispatched objects.
- [12]
Previously, developers defined static default attributes using the $attributes property, for example 'cancelled' => false and 'trial_days' => 14.
- [13]
"So don't treat QUERY as a shortcut for bypassing Laravel's security mechanisms."
- [14]
A second defaults() example returns 'status' => 'active', 'country' => config('app.default_country') and 'trial_ends_at' => now()->addDays(14).
- [15]
The post's GET example uses six query-string parameters.
- [16]
The release includes percentage-based queue memory limits and scheduler improvements for multi-server deployments; the post's summary lists them without describing how the percentage is calculated.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toLaravel 13.35: New QUERY Routes, Smarter Model Defaults & Queue Improvements
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.