Add $request->session()->regenerate();
in your login() method after Auth::login($user, true);
to regenerate the session ID.
Auth::login($user, true);
$request->session()->regenerate();
$request->session()->regenerateToken();
Log::info('User logged in:', ['user' => $user]);