$request->user()->orders->create($request->validated());
This looks so wrong from an architectural point of view! A request has a user (which in the context of HTTP should be more or less only an authenticated principal), which has orders, which are created from the same request, where the journey started. There is no separation of technical and business concerns.See: https://blog.cleancoder.com/uncle-bob/2012/08/13/the-clean-a...