Download the PHP package expertapps/laravel-abac without Composer

On this page you can find all versions of the php package expertapps/laravel-abac. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package laravel-abac

Laravel ABAC (Attribute-Based Access Control)

Latest Version on Packagist Downloads PHP Laravel

An enterprise-grade, ultra-fast Attribute-Based Access Control (ABAC) authorization engine for Laravel applications built by ExpertApps.

Unlike traditional Role-Based Access Control (RBAC) packages that rely on static database queries, laravel-abac evaluates authorization dynamically using runtime attributes across Subject, Resource, Action, and Environment parameters—executed via an in-memory $O(1)$ Policy Group & Action Matrix Strategy.


🎯 The Problem We Solve

In real-world enterprise applications, traditional RBAC (Role-Based Access Control) breaks down as authorization requirements become contextual and dynamic:

1. The "Role Explosion" Problem

In traditional RBAC, when access depends on conditions (e.g., "Medical Record Viewer in Cardiology during working hours"), developers are forced to invent endless artificial roles like Cardiology_Doctor_WorkingHours_ExportAllowed. This clutters database tables and makes role maintenance unsustainable.

2. Context Blindness

Standard Laravel Policies or RBAC packages evaluate permissions using static database records (User -> Roles -> Permissions). They struggle when permissions depend on real-time runtime parameters, such as:

3. Database Bottlenecks

Standard database-backed permission systems execute N+1 database queries during complex request life cycles just to check permissions across nested models and UI elements.


⚡ How laravel-abac Solves It

laravel-abac shifts authorization from static database lookups to in-memory dynamic evaluation:


⚡ Key Architectural Features


📋 Requirements

Requirement Supported Version
PHP ^8.3
Laravel Framework ^10.0 | ^11.0 | ^12.0 | ^13.0

🚀 Installation

Install the package via Composer:

Publish the package configuration:


⚙️ Configuration

The published config/abac.php file defines your policy group registry and fallback security behavior:


🏁 Get Started Guide

Follow this step-by-step example to build your first ABAC authorization pipeline for a medical PatientRecord resource.

Step 1: Create Granular Rules

Granular rules implement single-responsibility access logic.

Generate rules using Artisan:

Rule 1: Check Department Alignment

Rule 2: Evaluate Environmental Parameters (Working Hours)

Rule 3: Evaluate Dynamic Runtime Attributes

Step 2: Create a Policy Group (Action Matrix)

Create a Policy Group to bundle target resources and map actions to rules:

Implement your action matrix:

Step 3: Register Policy Group in Configuration

Add your Policy Group class to config/abac.php:


💻 Authorization Usage Methods

1. Programmatic Authorization via Facade

2. Native Laravel Controllers ($this->authorize)

laravel-abac integrates seamlessly with standard Laravel authorization methods. You can pass dynamic runtime attributes as an array parameter:

3. Native Gate Facade (Gate::allows)

4. Blade Directives


🏛️ Architecture Flow


🔒 Security Model


🧪 Testing

Run test suites using PHPUnit or Pest:


🛡️ Security & Vulnerabilities

If you discover any security vulnerabilities within laravel-abac, please email [email protected].


📜 License

The MIT License (MIT). Please see LICENSE for more information. Developed with ❤️ by ExpertApps.


All versions of laravel-abac with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package expertapps/laravel-abac contains the following files

Loading the files please wait ...