Authorization
Authorization decides whether the actor may perform this operation.
What it is
Authorization decides whether the actor may perform this operation.
When to use it
Check every protected resource action, including read endpoints.
Syntax
Gate::authorize("update", $order);Example
use Illuminate\Support\Facades\Gate;
public function update(UpdateOrderRequest $request, Order $order)
{
Gate::authorize("update", $order);
$order->update($request->validated());
return response()->json(["id" => $order->id]);
}Common mistakes
Hiding a button is not authorization; guessed IDs must not bypass ownership.