Field Manual PHP / Laravel reference
← Laravel

Authorization

Authorization decides whether the actor may perform this operation.

What it is

Authorization decides whether the actor may perform this operation.

When to use it

Check every protected resource action, including read endpoints.

Syntax

Gate::authorize("update", $order);

Example

use Illuminate\Support\Facades\Gate;
public function update(UpdateOrderRequest $request, Order $order)
{
    Gate::authorize("update", $order);
    $order->update($request->validated());
    return response()->json(["id" => $order->id]);
}

Common mistakes

Hiding a button is not authorization; guessed IDs must not bypass ownership.

Related topics

AuthorizationAuthentication versus authorizationAuthorization and RBAC