<?php

namespace App\Http\Middleware;

use Illuminate\Foundation\Http\Middleware\VerifyCsrfToken as Middleware;

class VerifyCsrfToken extends Middleware
{
    /**
     * URIs that are excluded from CSRF verification.
     * Login is NOT excluded — browsers must send a valid CSRF token with session cookies.
     */
    protected $except = [
        // Razorpay / device webhooks that authenticate via signature or Basic auth live under /api
        // and are not on the web middleware stack.
    ];
}
