Policy gom logic phân quyền về một chỗ.
Tạo bằng php artisan make:policy PostPolicy --model=Post, rồi định nghĩa các method view(), create(), update(), delete():
php
public function update(User $user, Post $post) {
return $user->id === $post->user_id;
}Gọi từ controller bằng $this->authorize("update", $post);, hoặc kiểm tra inline if (auth()->user()->can("update", $post)).
Lợi ích: quy tắc auth tập trung, tái dùng qua nhiều controller, dễ test và dễ đọc.
Laravel 11+: AuthServiceProvider đã bị bỏ — đăng ký policy bằng Gate::policy() trong AppServiceProvider, hoặc để auto-discovery tự tìm.