Review API.
Install the open-source review engine, connect a model, and build your own review experience.
← All Core topicsReview
Create a review safely
Use an authenticated endpoint and authorize the target before calling core. Core is a persistence API, not a replacement for your request validation or policies. For example, inside your application's controller action:
use Illuminate\Http\Request;
public function store(Request $request, Product $product)
{
$this->authorize('review', $product);
$validated = $request->validate([
'review' => ['required', 'string', 'min:10', 'max:5000'],
'recommend' => ['sometimes', 'boolean'],
'ratings' => ['required', 'array:overall,quality,price'],
'ratings.overall' => ['required', 'integer', 'between:1,5'],
'ratings.quality' => ['required', 'integer', 'between:1,5'],
'ratings.price' => ['required', 'integer', 'between:1,5'],
]);
$review = $product->addReview([
'review' => $validated['review'],
'recommend' => $request->boolean('recommend'),
'department' => 'default',
'ratings' => $validated['ratings'],
], $request->user()->getKey());
return response()->json(['review_id' => $review->id], 201);
}
Import your own Product class and define the review policy/Gate. If your base controller does not use Laravel's AuthorizesRequests trait, use Gate::authorize('review', $product) instead. Match the validation keys and boundaries to your configured department.
The author ID must come from the authenticated server context. Do not accept approved, author IDs, verification flags, or arbitrary departments from an untrusted payload. Trusted internal writers may explicitly pass approved to override core's default.
Core can also store a review without an author by passing null; Pro's customer submission and author-editing workflows require authentication.
Update, approve, and delete
Authorize each operation and ensure the review belongs to the intended target. These core methods are available on the reviewable model:
$product->updateReview($reviewId, [
'review' => 'My updated experience.',
'recommend' => true,
'ratings' => [
'overall' => 4,
'quality' => 4,
'price' => 5,
],
]);
$product->approveReview($reviewId);
$product->deleteReview($reviewId);
These methods do not apply Pro's author editing, duplicate-submission policy, verification, or content-filter workflows. Route author-facing Pro edits through ReviewEditingManager instead. Deletion is permanent; use approval controls to hide content you want to retain.
Use the service contract
The injectable service provides a decoupled alternative to the trait API. Set the saved target before using it:
use Codebyray\ReviewRateable\Contracts\ReviewRateableContract;
public function store(Product $product, ReviewRateableContract $reviews)
{
// Authorize and validate before this point.
$reviews->setModel($product);
return $reviews->addReview([
'review' => 'A thoughtful, validated review.',
'ratings' => ['overall' => 5],
], auth()->id());
}
Adapt the payload to your configured criteria. Do not reuse a service instance across targets without setting its model again.