{
 "id": "web-laravel-node",
 "kind": "skill",
 "name": "Web: Laravel and Node.js",
 "description": "Web development: Laravel (PHP), Node.js/TypeScript backends, and HTML/CSS/JavaScript frontends, including web-app and API security basics. Use for web app code.",
 "version": "1.0.0",
 "author": "Hexa Hub",
 "files": {
  "SKILL.md": "---\nname: web-laravel-node\ndescription: Web development: Laravel (PHP), Node.js/TypeScript backends, and HTML/CSS/JavaScript frontends, including web-app and API security basics. Use for web app code.\ntitle: Web: Laravel and Node.js\nicon: tabler:brand-nodejs\ncategory: Development\n---\n\n# Web development\n\nCheck the project's versions first (`composer.json`, `package.json`, lockfiles) and follow the existing structure.\nVerify APIs in the docs (`devtools__web_search` topic `laravel`, `nodejs`, `typescript`, `web`) instead of guessing.\n\n## Laravel\n- Use artisan generators (`make:model -mfc`, `make:request`, `make:policy`). Migrations for every schema change.\n- Validation in Form Requests; authorization via policies/gates; mass assignment guarded with `$fillable`.\n- Avoid N+1 queries: eager load with `with()`; use `chunk`/`cursor` for big sets; add indexes for lookups.\n- Config via `.env` + `config()` (never `env()` outside config files); `php artisan config:cache` in production.\n- Queues for slow work; scheduled tasks via `schedule:run`. Tests with Pest/PHPUnit: feature tests hit routes, use factories.\n- Blade escapes by default (`{{ }}`); only use `{!! !!}` for trusted HTML.\n\n## Node.js / TypeScript\n- Use current LTS. Decide ESM vs CJS and stay consistent. `strict` mode in `tsconfig.json`; avoid `any`.\n- `async/await` with try/catch at boundaries; never leave promises unhandled; set timeouts on outbound calls.\n- Validate all input (zod or similar). Use environment variables for config; commit the lockfile; `npm ci` in CI.\n- Test pure logic with `devtools__run_code` (node) where possible; real projects use vitest/jest.\n\n## Frontend\n- Semantic HTML, labels on inputs, keyboard focus, sufficient contrast. CSS: flexbox/grid, `rem`, custom properties,\n  mobile-first media queries. JS: `const`/`let`, no globals, `fetch` with error handling, avoid `innerHTML` with user data.\n\n## Security checklist (always)\nParameterized queries, escape output, CSRF protection on state-changing forms, strict CORS, rate limit auth routes,\nhash passwords (bcrypt/argon2), don't log secrets, HTTPS only, set security headers, validate file uploads.\n"
 }
}
