API & Architecture

Authorization & Policies in Modern Laravel

The Code Hub Admin
Sep 22, 2026
6 min read

Implement fine-grained resource authorization using Laravel Policies, Gate definitions, and Inertia authorization props.

Policies: Granular Model Security

A Policy is a dedicated class that organizes authorization logic around a specific Eloquent model.

PHP
namespace App\Policies;

use App\Models\Project;
use App\Models\User;

class ProjectPolicy
{
    public function view(User $user, Project $project): bool
    {
        return $user->id === $project->user_id;
    }

    public function update(User $user, Project $project): bool
    {
        return $user->id === $project->user_id;
    }

    public function delete(User $user, Project $project): bool
    {
        return $user->id === $project->user_id;
    }
}

Controller Enforcement

Enforce policies in controllers using $this->authorize() or Gate::authorize():

PHP
public function edit(Project $project)
{
    Gate::authorize('update', $project);

    return Inertia::render('projects/edit', ['project' => $project]);
}

Sharing Permissions with Inertia

Do not force the frontend to guess whether an edit button should appear. Pass evaluated policy gates directly in Inertia props:

PHP
'can' => [
    'update' => $user->can('update', $project),
    'delete' => $user->can('delete', $project),
]
Topics in this article

Related Knowledge Articles

Keep controllers pristine by moving complex input validation, authorization rules, and sanitized data casting into dedicated Form Request classes.
Transform bloated controllers and fragmented services into single-responsibility Action classes that are clean, testable, and reusable.
Prevent path traversal, MIME spoofing, and unauthorized download exposure when serving learning resources.