What's New in Laravel 13.27: Key Features | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com/public) - [Home](https://www.msaied.com/public)
- [Projects](https://www.msaied.com/public/projects)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [About](https://www.msaied.com/public#about)

           [  Contact](https://www.msaied.com/public#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com/public)
- [ProjectsCase studies](https://www.msaied.com/public/projects)
- [ArticlesEngineering notes](https://www.msaied.com/public/articles)
- [CertificatesCredentials](https://www.msaied.com/public/certificates)
- [AboutHow I work](https://www.msaied.com/public#about)
- [ContactGet in touch](https://www.msaied.com/public#contact)

  [Start a conversation](https://www.msaied.com/public#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com/public)
2. /
3. [Articles](https://www.msaied.com/public/articles)
4. /
5. [Laravel](https://www.msaied.com/public/articles?category=laravel)
6. /
7. Query Binding Masking and whereBinary() in Laravel 13.27

   [Laravel](https://www.msaied.com/public/articles?category=laravel) 

 Query Binding Masking and whereBinary() in Laravel 13.27
=========================================================

 Laravel 13.27 ships query binding masking for safer exception messages, a whereBinary() family for byte-exact MySQL comparisons, refreshForUpdate() for pessimistic locking, a Cloud facade, and queue size totals.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com/public#person) Published 26 Aug 2026 · Updated 26 Aug 2026 · 4 min read

ShareCopy linkCopied

 ![Query Binding Masking and whereBinary() in Laravel 13.27](https://cdn.msaied.com/597/bd82bbbaee7d7826a7a3a2f4e8b77330.png) 

  On this page +1. [What's New in Laravel 13.27](#whats-new-in-laravel-1327)
2. [Masking Query Bindings in Exception Messages](#masking-query-bindings-in-exception-messages)
3. [whereBinary() for Case-Sensitive Comparisons](#codewherebinarycode-for-case-sensitive-comparisons)
4. [refreshForUpdate() for Pessimistic Locking](#coderefreshforupdatecode-for-pessimistic-locking)
5. [Cloud Facade](#codecloudcode-facade)
6. [Queue Size Totals](#queue-size-totals)
7. [Other Notable Changes](#other-notable-changes)
8. [Key Takeaways](#key-takeaways)

 What's New in Laravel 13.27
---------------------------

Laravel 13.27 was released on August 26, 2026, bringing several developer-quality-of-life improvements alongside meaningful security and correctness fixes. Here is a breakdown of the most important changes.

---

### Masking Query Bindings in Exception Messages

By default, `QueryException` interpolates bound values directly into its message. That means a failed `INSERT` can expose email addresses, names, or other sensitive data in log files, APM spans, and the `failed_jobs` table.

A new per-connection config key stops the interpolation:

```php
'mysql' => [
    'driver' => 'mysql',
    // ...
    'mask_bindings_in_exception_messages' => env('DB_MASK_BINDINGS', false),
],

```

With masking enabled, the exception message retains `?` placeholders instead of real values. `getBindings()` is unaffected, so debugging tooling that reads bindings directly still works. Applications that never published `config/database.php` can enable the feature with a single environment variable: `DB_MASK_BINDINGS=true`.

---

### `whereBinary()` for Case-Sensitive Comparisons

MySQL's default collations are case-insensitive, so `where('name', 'John')` also matches `john` and `JOHN`. Previously, a byte-exact comparison required raw SQL:

```php
DB::table('queues')->whereRaw('name = BINARY ?', [$queueName])->first();

```

Laravel 13.27 adds a full family of query builder methods:

```php
DB::table('queues')->whereBinary('name', $queueName)->first();
// select * from `queues` where `name` = binary ?

DB::table('queues')->whereNotBinary('name', $queueName)->get();
// select * from `queues` where `name` != binary ?

```

The family includes `orWhereBinary()` and `orWhereNotBinary()`. MariaDB inherits the MySQL grammar and works automatically. Postgres, SQLite, and SQL Server throw a `RuntimeException`, consistent with how `whereLike()` handles engines that are already case-sensitive.

---

### `refreshForUpdate()` for Pessimistic Locking

Models resolved before a transaction starts — through route model binding or a job payload — need to be re-queried under a lock before writing. The old pattern discarded the existing instance:

```php
DB::transaction(function () use ($product) {
    $product = Product::query()->lockForUpdate()->findOrFail($product->getKey());
    $product->decrement('stock');
});

```

The new `refreshForUpdate()` method refreshes the instance in place:

```php
DB::transaction(function () use ($product) {
    $product->refreshForUpdate();

    if ($product->stock === 0) {
        throw new RuntimeException('The product is out of stock.');
    }

    $product->decrement('stock');
});

```

The lock only holds for the life of the transaction, so the call must be made inside one.

---

### `Cloud` Facade

A new `Cloud` facade consolidates Laravel Cloud environment checks into three methods:

```php
use Illuminate\Support\Facades\Cloud;

Cloud::hosted();            // running on Laravel Cloud?
Cloud::usesManagedQueues(); // is the cloud queue connection configured?
Cloud::queue();             // the managed queue connection itself

```

`Cloud::queue()` throws a `RuntimeException` when managed queues are not configured, so pair it with `usesManagedQueues()`. The facade is not registered in the default aliases to avoid collisions with existing application classes.

---

### Queue Size Totals

Three new methods sum queue sizes across every queue a connection knows about, without decoding job payloads:

```php
Queue::totalPendingSize();
Queue::totalDelayedSize();
Queue::totalReservedSize();

```

Implemented for the Redis, database, failover, and fake drivers.

---

### Other Notable Changes

- **Vector distance queries** now work on MariaDB 11.7+ via `vec_distance_cosine()`.
- **Validation hardening**: `in_array` and `doesnt_contain` rules now use strict comparison, preventing scientific-notation string matches like `"1e0"` matching `"1"`.
- **`Request::merge(['*' => value])`** no longer wipes the entire input array; `*` is now stored literally.
- **`MaintenanceModeBypassCookie::isValid()`** now checks `is_string()` on the `mac` field, preventing a malformed cookie from causing a 500 error.
- **Postgres keepalive DSN options** prevent idle firewall timeouts from silently killing long-lived worker connections.
- **SQS credential caching** reduces AWS credential fetches to one per rotation instead of one per PHP-FPM worker.

---

### Key Takeaways

- Enable `DB_MASK_BINDINGS=true` to keep sensitive values out of exception messages and logs.
- Replace `whereRaw('name = BINARY ?', [...])` with `whereBinary('name', ...)` for cleaner, driver-aware code.
- Use `refreshForUpdate()` inside transactions to simplify pessimistic locking on already-resolved models.
- The `Cloud` facade provides a clean API for Laravel Cloud environment detection.
- Strict comparison fixes in validation rules close subtle type-juggling edge cases.

---

*Source: [Laravel News — Laravel 13.27.0](https://laravel-news.com/laravel-13-27-0)*

- [Laravel 13.27](https://www.msaied.com/public/articles?search=Laravel%2013.27)
- [Eloquent](https://www.msaied.com/public/articles?search=Eloquent)
- [Query Builder](https://www.msaied.com/public/articles?search=Query%20Builder)
- [Security](https://www.msaied.com/public/articles?search=Security)
- [Releases](https://www.msaied.com/public/articles?search=Releases)

 Frequently asked questions 
---------------------------

  Does enabling `mask\_bindings\_in\_exception\_messages` affect what `getBindings()` returns?No. Only the exception message changes — `?` placeholders replace the interpolated values. `getBindings()` still returns the actual bound values, so debugging tools that read bindings directly are unaffected.

   Which database drivers support the new `whereBinary()` methods?`whereBinary()` and its variants work on MySQL and MariaDB. Calling them on Postgres, SQLite, or SQL Server throws a `RuntimeException`, consistent with how `whereLike()` handles those engines.

   When should I use `refreshForUpdate()` instead of `refresh()`?Use `refreshForUpdate()` inside a database transaction when you need a pessimistic lock on a model that was resolved before the transaction started (e.g., via route model binding or a job payload). It reloads the model with `lockForUpdate()` applied, closing the data race between reading and writing.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com/public#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com/public#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articleLaravel Boost v2.6.0: Testing Best Practices Skill and Read-Only DB Transactions](https://www.msaied.com/public/articles/laravel-boost-v260-testing-best-practices-skill-and-read-only-db-transactions) [Next articleMulti-Tenant SaaS with Laravel: Isolating Tenant Data Using Row-Level Scoping](https://www.msaied.com/public/articles/multi-tenant-saas-with-laravel-isolating-tenant-data-using-row-level-scoping)  

   On this page
-------------

1. [What's New in Laravel 13.27](#whats-new-in-laravel-1327)
2. [Masking Query Bindings in Exception Messages](#masking-query-bindings-in-exception-messages)
3. [whereBinary() for Case-Sensitive Comparisons](#codewherebinarycode-for-case-sensitive-comparisons)
4. [refreshForUpdate() for Pessimistic Locking](#coderefreshforupdatecode-for-pessimistic-locking)
5. [Cloud Facade](#codecloudcode-facade)
6. [Queue Size Totals](#queue-size-totals)
7. [Other Notable Changes](#other-notable-changes)
8. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com/public#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/public/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) [ ![](https://cdn.msaied.com/739/2d6897fdcdcf090613f96f72a64b8a78.png)  · 4 min read### MySQL Full-Text Search in Laravel: Indexes, Relevance Scoring, and Boolean Mode

4 Oct 2026 ](https://www.msaied.com/public/articles/mysql-full-text-search-in-laravel-indexes-relevance-scoring-and-boolean-mode) [ ![](https://cdn.msaied.com/738/073696a3fefe18bec825beec5ac658f5.png)  · 4 min read### Laravel Queue Rate-Limited Middleware: Throttling Jobs Without Losing Work

4 Oct 2026 ](https://www.msaied.com/public/articles/laravel-queue-rate-limited-middleware-throttling-jobs-without-losing-work) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com/public#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com/public)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/public/sitemap.xml)
