Development › Authorization

Authorization

Authorization answers whether an authenticated principal may perform an action on a resource.

#Layers

LayerTool
Route / middlewarecan, custom middleware, Sanctum abilities
Policiesapp/Security/Policies and/or module policies
ApplicationExplicit checks / domain rules inside Actions when needed
DomainInvariants that are business rules (not HTTP-centric)
  1. Authenticate first (auth:sanctum).
  2. Authorize with Policies for resource actions (view, update, delete).
  3. Keep complex multi-entity rules in Domain/Application, throwing a dedicated authorization/domain exception.
  4. Map failures to 403 JSON for api/* routes.

Example controller shape:

class="tk-v">$this->authorize(class="tk-s">'update', class="tk-v">$order);

class="tk-v">$order = class="tk-v">$this->updateOrder->execute(class="tk-v">$data);

#Module ownership

#Rate limiting

Abuse protection lives under app/Security/RateLimiting and Laravel’s RateLimiter. Prefer Redis-backed limiters in production (see redis.md).

Edit this page on GitHub