Hard20 minLaravel Fundamentals
UpdatedAug 5, 2026
Edit

Laravel Authentication and Authorization

Question Variations

  • "What is the difference between a guard and a policy?"
  • "Where should resource ownership be checked?"
  • "Why is a role check alone often insufficient?"

Why This Is Asked

This tests the distinction between identifying a user and enforcing permissions on a resource.

Key Concepts

  • Guards authenticate requests using a configured mechanism.
  • Policies and gates express authorization decisions.
  • Authorization must consider object ownership and tenant boundaries.
  • Authentication middleware should fail closed for protected routes.

Question Variations

  • “What is the difference between a guard and a policy?”
  • “Where should resource ownership be checked?”
  • “Why is a role check alone often insufficient?”

Answers by Technology

+ Add Variant
LaravelImprove this answer ✏️

Expected Answer (Laravel 13 / PHP 8.3+)

Guards establish the authenticated user for a request; policies and gates decide whether that user may act on a particular resource. Put object-level rules in policies so ownership and tenant constraints remain consistent across controllers, jobs, and other entry points. Authentication alone never proves a user may modify every resource.

Why It Matters

Policies prevent broken access control that simple role checks often miss.

Code Example

final class OrderPolicy
{
    public function update(User $user, Order $order): bool
    {
        return $order->customer_id === $user->id;
    }
}

Common Mistakes

  • Checking only a broad role: A role may not grant ownership of every object.
  • Trusting a user ID from the request body: Identity must come from authentication.

Follow-up Questions

  • What is a guard? (Answer: An authentication mechanism.)
  • What is a policy? (Answer: A model or resource authorization rule.)