Download the PHP package codesuab/laravel-permission without Composer
On this page you can find all versions of the php package codesuab/laravel-permission. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download codesuab/laravel-permission
More information about codesuab/laravel-permission
Files in codesuab/laravel-permission
Package laravel-permission
Short Description Simple, secure and framework-native roles and permissions for Laravel, Blade and Inertia.
License MIT
Informations about the package laravel-permission
Laravel Permission
Secure, framework-native RBAC + ACL for Laravel 11/12/13 with Blade, Gate/Policy integration, Inertia React, teams/tenancy, wildcard permissions, route/resource protection and an ACL matrix API.
Install
Add traits to your User model:
Permissions
Permission::ensure() intentionally replaces Permission::create() so Eloquent's native Model::create() is never overridden.
Routes
Resource mapping:
index/show=view, create/store=create, edit/update=update, destroy=delete.
Team-scoped routes:
Or:
Policy / Gate integration
The package registers a Gate::before integration. Explicit permission abilities work automatically:
Standard Laravel Policy abilities are translated to CRUD permissions. For a User model:
The resource name is inferred from $model->getTable(). Override it in config/permission.php:
Then update Invoice checks billing.invoices.update.
Normal Laravel Policy logic remains available: if the package does not grant the ability, Gate continues to the registered policy.
Teams / Multi-tenancy
A permission can be global or team-scoped. User-role and direct-user-permission assignments contain team_id.
Team middleware reads {team} from the route, verifies membership when enabled, sets the request team context, and clears it after the request.
Global grants remain available inside a team. Team grants are isolated by team_id.
ACL Matrix
The result contains:
- roles
- permissions grouped by permission group
matrix[role_slug] => permission_slugs[]
Update a role:
React includes an optional matrix component:
Blade
Inertia React
The backend shares auth.permissions, auth.roles and auth.team automatically.
Client-side checks are UI helpers only. Authorization must always be enforced by Laravel middleware/Gate/Policy.
Wildcards
Super admin
The configured super-admin role bypasses permission checks. Configure it with:
Security model
- Server-side middleware and Gate/Policy are authoritative.
- Direct permissions are included in authorization and Inertia data.
- Team context is part of the permission cache key.
- Global permissions can be combined with tenant-scoped grants.
- No React/Blade check is treated as a security boundary.
License
MIT
All versions of laravel-permission with dependencies
illuminate/auth Version ^11.0|^12.0|^13.0
illuminate/cache Version ^11.0|^12.0|^13.0
illuminate/console Version ^11.0|^12.0|^13.0
illuminate/database Version ^11.0|^12.0|^13.0
illuminate/routing Version ^11.0|^12.0|^13.0
illuminate/support Version ^11.0|^12.0|^13.0
illuminate/view Version ^11.0|^12.0|^13.0