The inputs a business handler was given — a tiny surface, three kinds of input: identity, payload, dimensions.
parameter()/parameters() expose the #[Parameter] route map (the
resolver's name => value pairs — an id or a bound model); validated() is
the FormRequest's guaranteed body; slot()/slots() are the resolved ambient
dimensions (sales_org, currency, period, …) a handler opts into by
implements SlottableInterface. The FormRequest object itself stays at the
HTTP boundary; only its validated array crosses into the domain. Identity is
NOT here — the handler reads actor/org off the SdkContext sibling, so there
is no dual-source drift.
Slot values are untrusted for authorization. A slot may be client-supplied
(the Request source is first in the resolution chain), exactly like
validated() body data. The framework guarantees the value, never the
right to act at it: authorizing a mutation against the slots it consumes is
the handler's own responsibility (Enterprise API notes §3.1 / §4).
| Methods | ||
|---|---|---|
public
|
parameter(string $name): mixed
|
# |
public
|
parameters(): array<string, mixed>
|
# |
public
|
validated(): array<string, mixed>
|
# |
public
|
slot(string $name): mixed
|
# |
public
|
slots(): array<string, mixed>
|
# |