Field Manual PHP / Laravel reference
← Security

Least privilege

Least privilege grants only the access necessary for a task.

What it is

Least privilege grants only the access necessary for a task.

When to use it

Limit user roles, database credentials, file access, and operational accounts.

Syntax

// Application DB account: required DML only
// Migration account: separate schema permissions
// Auditor: read audit records, no transaction mutation

Example

// Tenant boundary in every relevant query:
$accounts = Account::where("tenant_id", $user->tenant_id)->get();
// Then authorize the requested action through a policy.

Common mistakes

A local SQLite file has filesystem permissions rather than database users; protect backups as well.

Related topics

Browse Security