Authentication versus authorization
Authentication identifies the actor; authorization determines permitted actions.
What it is
Authentication identifies the actor; authorization determines permitted actions.
When to use it
Apply both when handling protected financial data.
Syntax
Route::middleware("auth")->group(function () {
// Then Gate::authorize(...) for each resource operation.
});Example
public function show(Account $account)
{
Gate::authorize("view", $account);
return response()->json(["id" => $account->id]);
}
// Protect the route with auth middleware too.Common mistakes
Login alone does not establish account ownership; do not trust a client-provided role.