An Introduction to Laravel Policy
An Introduction to Laravel Policy
30 Dec 2018 . Laravel. 7.6K views
If you heard about Laravel Policy and still not yet use that, this introduction to Laravel Policy post is for you then. In this tutorial, I will write a real-life tutorial that, how to use Laravel Policy for the beginner.
What is Laravel Policy
Laravel policy is a part of Authorization of Laravel that help you to protect content or resources from unauthorized access.
Just imagine a simple concept that you have a blog that contains users and posts. Normally the post can be visible to every visitor, however, to edit a post, you need to be the owner of the post. In this tutorial, I will show you how to show the edit post option to the post owner only.
The basic concept of this apps is-
- A user can create a post
- A post can be viewed by visitor / user
- The post creator only can edit the post
- The post creator only can able to delete
Basic Configuration
First, let's connect with Database. In your .env file, update like follow. My database name is laravel-policy
Next, need to create the migration, model and controller for posts and users table.
php artisan make:model User -m -c
php artisan make:model Post -m -c
Let's define migration now.
Schema::create('users', function (Blueprint $table) {
Schema::create('posts', function (Blueprint $table) {
Once, you have done this part, now run the migration.
php artisan migrate
If everything goes smoothly, you will see two tables in your database called users and posts. Now you may record data in your tables. You may go for seeding data or add manually. To keep this tutorial show, I just skip this step.
Create Policy
The ideal way to define a policy is to follow the model name. In our case, our model name is Post, so that our policy name should be PostPolicy to the authorized user to edit or delete. The artisan command to do that is-
php artisan make:policy PostPolicy
This command make:policy
will generate an empty policy class in the App\Policies folder. In addition, you can suffix --model=Post
to create CRUD.
Writing Policy
Now, let write the policy for the post where the post id is 1 that belongs to a user who's id is 1. So, the post is available to view from any user or visitor, however, in order to update or delete, you need to be a user who's id is 1.
Now, defining the update method to restrict the update option from mass people.
namespace App\Policies;
use App\User;
use App\Post;
use Illuminate\Auth\Access\HandlesAuthorization;
class PostPolicy
use HandlesAuthorization;
* Determine if the given post can be updated by the user.
* @param \App\User $user
* @param \App\Post $post
* @return bool
public function update(User $user, Post $post)
return $user->id === $post->user_id;
This update method will check whether the post creator is this user or not. It will return true once it matches otherwise, returns false.
Registering a Policy.
Once you have defined policy, you need to register the policy in the app/Providers/AuthServiceProvider.
namespace App\Providers;
use App\Post;
use App\Policies\PostPolicy;
use Illuminate\Support\Facades\Gate;
use Illuminate\Foundation\Support\Providers\AuthServiceProvider as ServiceProvider;
class AuthServiceProvider extends ServiceProvider
* The policy mappings for the application.
* @var array
protected $policies = [
'App\Model' => 'App\Policies\ModelPolicy',
Post::class => PostPolicy::class
How to use
Once you are in this stage that means, you have done everything successfully. Now, you need to use that.
Via View
In the view, you can use @can and @cannot directive.
@can('update', $post)
<!-- The Current User Can Update The Post -->
@cannot('update', $post)
<!-- The Current User Can't Update The Post -->
Via Model
In the model, you can use in the following way-
if ($user->can('update', $post)) {
Via Controller
Even you can use via controller also. Cool, right?
public function update(Request $request, Post $post)
$this->authorize('update', $post);
// The current user can update the blog post...
Sweet. Hope, you will like this. If you love this, feel free to share.
You can get this code in the following repository.
Thank you.
An Introduction to Laravel Policy的更多相关文章
- A Quick Introduction to Linux Policy Routing
A Quick Introduction to Linux Policy Routing 29 May 2013 In this post, I’m going to introduce you to ...
- Laravel policy 的应用
Laravel 提供更简单的方式来处理用户授权动作.类似用户认证,有 2 种主要方式来实现用户授权:gates 和策略,我这里主要讲解下策略的使用. 文档 上面有详细的说明,我这里只根据自己使用过程做 ...
- 使用 Laravel 实现微型博客系统
参考链接:An Introduction to Laravel Authorization Gates 这个微型博客系统包含两个用户角色(作者 和 编辑),它们的权限如下: 作者能创建博客 作者能更新 ...
- PHP and laravel知识点小小积累
function () use ($x, &$y){} 自从PHP5.3开始有了closure/匿名函数的概念,在这里的use关键词的作用是允许匿名函数capture到父函数scope 内存在 ...
- Laravel Gate 授权方式的使用指南
参考链接:An Introduction to Laravel Authorization Gates 本文使用 Laravel 的 Gate 授权方式 实现一个基于用户角色的博客发布系统. 在系统包 ...
- Laravel 5.8: Automatic Policy Resolution
Laravel 5.8: Automatic Policy Resolution March 26, 2019 One of the new features in Laravel 5.8 allow ...
- Laravel策略(Policy)示例
场景:当前用户创建的订单,只能当前用户自己看,可以通过授权策略类(Policy)来实现 1.php artisan make:policy OrderPolicy 成功后,默认只有一个构造方法.因为涉 ...
- laravel/lumen 单元测试
Testing Introduction Application Testing Interacting With Your Application Testing JSON APIs Session ...
- Machine Learning Algorithms Study Notes(1)--Introduction
Machine Learning Algorithms Study Notes 高雪松 @雪松Cedro Microsoft MVP 目 录 1 Introduction 1 1.1 ...
- 某 游戏公司 php 面试题
1.实现未知宽高元素的水平垂直居中,至少两种方法. <div, class="father"> <div class="son">< ...
- StarUML3.1.0版(2019.3.6)生成Java代码
下载官网 StarUML3.1.0(2019.3.6) 步骤 打开StarUML: 点击菜单栏的Tools: 列表中如果有Java,说明已经有这个生成Java代码的扩展了: 列表里如果没有Java: ...
- 解决 windows oracle ORA-01113和ORA-01110错误
windows2008上的数据库版本为11.,数据库打开为mount状态.报错如下: SQL> startup ORACLE instance started. Total Sys ...
- 理解 is_callable
官方解释: (PHP 4 >= 4.0.6, PHP 5, PHP 7) is_callable — 检测参数是否为合法的可调用结构. 说明 is_callable ( callable $na ...
- PHP trait介绍
Trait 自 PHP 5.4.0 起,PHP 实现了一种代码复用的方法,称为 trait. Trait 是为类似 PHP 的单继承语言而准备的一种代码复用机制.Trait 为了减少单继承语言的限制, ...
- awesome-javascript
一系列令人敬畏的浏览器端JavaScript库,资源和闪亮的东西. 令人敬畏的JavaScript 包管理员 装载机 捆扎机 测试框架 QA工具 MVC框架和库 基于节点的CMS框架 模板引擎 文章/ ...
- Linux中 ls -l 命令显示结果中的每一列的含义
图片转载自: 简单解释下: 1.第一列颜色框:文件类型列,这里简单描述几种常见类型,d表示目 ...
- 存储过程、插入数据后直接过去主键id
DECLARE @sql nvarchar() DECLARE @cou int SET @sql='INSERT INTO people values('''+'xiaohong'+''');sel ...
- dll安装到GAC以及引用的方法【转】
一 首先 程序集(dll) 安装到 GAC 中的方法 所谓的GAC,就是全局程序集缓存(Global Assembly Cache). 针对一些类库项目或用户控件项目在程序开发完成后,有时需要将 ...
- elementUI动态数据表格(带分页)
index.vue <template> <div> <el-table ref="multipleTable" :data="tableD ...