Authorization
API authorization restricts records and operations for the actor.
What it is
API authorization restricts records and operations for the actor.
When to use it
Check every request and tenant boundary.
Syntax
Gate::authorize("view", $account);Example
Route::get("/accounts/{account}", function (Account $account) {
Gate::authorize("view", $account);
return response()->json(["id" => $account->id, "currency" => $account->currency]);
})->middleware("auth");Common mistakes
A valid token does not grant access to every account; object IDs are not secrets.