Laravel 5.6中如何为apiResource路由配置Policies中间件?
Hey there! Let's tackle your Laravel 5.6 API permission questions one by one:
apiResource Routes Since apiResource maps to standard CRUD endpoints (index, show, store, update, destroy), you have a couple of clean ways to attach the can middleware (which leverages your Policies) to each specific route action:
Option 1: Attach Middleware Directly to the apiResource Definition
You can specify middleware per route action when defining the apiResource:
Route::apiResource('me', 'UserController') ->middleware([ 'index' => 'can:viewAny,App\User', 'show' => 'can:view,App\User', 'store' => 'can:create,App\User', 'update' => 'can:update,App\User', 'destroy' => 'can:delete,App\User', ]);
Just make sure the policy actions (viewAny, view, etc.) match the methods defined in your UserPolicy class.
Option 2: Set Middleware in the Controller Constructor
Many developers prefer this approach for better organization, as it keeps route definitions clean:
class UserController extends Controller { public function __construct() { // Apply middleware only to specific controller methods $this->middleware('can:viewAny,App\User')->only('index'); $this->middleware('can:view,App\User')->only('show'); $this->middleware('can:create,App\User')->only('store'); $this->middleware('can:update,App\User')->only('update'); $this->middleware('can:delete,App\User')->only('destroy'); } // Your controller methods here... }
For your me endpoint, remember to adjust your Policy logic to handle the current user's own resource (e.g., in the update method, check if the authenticated user's ID matches the target user's ID, or allow admins to modify any user).
Important Pre-Requisite
Don't forget to register your Policy in AuthServiceProvider.php so Laravel knows to use it:
protected $policies = [ App\User::class => App\Policies\UserPolicy::class, ];
Absolutely! If you're now handling all permission checks via the Policy middleware (before the request reaches the controller/FormRequest), you can safely return true in your FormRequest's authorize method.
This works because the middleware already blocks unauthorized requests with a 403 response before they ever hit the FormRequest validation or authorization logic. Just make sure you've covered all necessary permission scenarios in your Policies—no gaps left that the FormRequest was previously handling.
For example:
class UpdateUserRequest extends FormRequest { public function authorize() { // All permission checks are handled by the Policy middleware return true; } // Your validation rules here... }
内容的提问来源于stack exchange,提问作者Cilenco

