Laravel

Authorization

In addition to providing built-in authentication services, Laravel also provides a simple way to authorize user actions against a given resource. For example, even though a user is authenticated, they may not be authorized to update or delete certain Eloquent models or database records managed by your application. Laravel
  • Policies MUST use dot notation. Example: @can('post.edit', $post)
  • Try to name abilities using the default CRUD words. One exception: replace show with view — a server shows a resource, a user views it.

Read More:

Copyright © 2026