Download the PHP package expertapps/laravel-abac without Composer
On this page you can find all versions of the php package expertapps/laravel-abac. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download expertapps/laravel-abac
More information about expertapps/laravel-abac
Files in expertapps/laravel-abac
Package laravel-abac
Short Description Enterprise-grade Attribute-Based Access Control (ABAC) using Policy Group and Action Matrix Strategy for Laravel.
License MIT
Informations about the package laravel-abac
Laravel ABAC (Attribute-Based Access Control)
An enterprise-grade, ultra-fast Attribute-Based Access Control (ABAC) authorization engine for Laravel applications built by ExpertApps.
Unlike traditional Role-Based Access Control (RBAC) packages that rely on static database queries, laravel-abac evaluates authorization dynamically using runtime attributes across Subject, Resource, Action, and Environment parameters—executed via an in-memory $O(1)$ Policy Group & Action Matrix Strategy.
🎯 The Problem We Solve
In real-world enterprise applications, traditional RBAC (Role-Based Access Control) breaks down as authorization requirements become contextual and dynamic:
1. The "Role Explosion" Problem
In traditional RBAC, when access depends on conditions (e.g., "Medical Record Viewer in Cardiology during working hours"), developers are forced to invent endless artificial roles like Cardiology_Doctor_WorkingHours_ExportAllowed. This clutters database tables and makes role maintenance unsustainable.
2. Context Blindness
Standard Laravel Policies or RBAC packages evaluate permissions using static database records (User -> Roles -> Permissions). They struggle when permissions depend on real-time runtime parameters, such as:
- Environment: Can this user view the resource from an external IP address at 11:00 PM?
- Dynamic Limits: Can a user approve a refund up to $5,000, but require extra approval above $5,000?
- Resource Context: Can a doctor view a patient record only if they belong to the same medical department?
3. Database Bottlenecks
Standard database-backed permission systems execute N+1 database queries during complex request life cycles just to check permissions across nested models and UI elements.
⚡ How laravel-abac Solves It
laravel-abac shifts authorization from static database lookups to in-memory dynamic evaluation:
- Zero Database Queries: Authorization matrices are pre-registered upon application boot. Evaluation happens entirely in memory.
- $O(1)$ Action Lookups: Exact array-map indexing routes
[ResourceClass][Action]directly to its target rule chain in constant time. - Dynamic Context Bag: Pass real-time environmental variables (IPs, monetary limits, request signatures) directly into evaluation context.
- Fail-Closed Zero-Trust Model: Unmapped actions or unregistered resources automatically evaluate to
false(access denied), eliminating accidental security loopholes.
⚡ Key Architectural Features
- Zero Database Overhead: Pure in-memory Clean Architecture execution.
- $O(1)$ Action Matrix Indexing: Instant route matching based on target resources and actions.
- Fail-Closed Strategy: Denies access by default unless an explicit rule passes.
- Fast-Pass Hook (
before): Provides global short-circuit logic (e.g., Super-Admin overrides). - Native Laravel Ecosystem: Direct support for
Gate::allows(),$this->authorize(), Blade directives, and Artisan generators.
📋 Requirements
| Requirement | Supported Version |
|---|---|
| PHP | ^8.3 |
| Laravel Framework | ^10.0 | ^11.0 | ^12.0 | ^13.0 |
🚀 Installation
Install the package via Composer:
Publish the package configuration:
⚙️ Configuration
The published config/abac.php file defines your policy group registry and fallback security behavior:
🏁 Get Started Guide
Follow this step-by-step example to build your first ABAC authorization pipeline for a medical PatientRecord resource.
Step 1: Create Granular Rules
Granular rules implement single-responsibility access logic.
Generate rules using Artisan:
Rule 1: Check Department Alignment
Rule 2: Evaluate Environmental Parameters (Working Hours)
Rule 3: Evaluate Dynamic Runtime Attributes
Step 2: Create a Policy Group (Action Matrix)
Create a Policy Group to bundle target resources and map actions to rules:
Implement your action matrix:
Step 3: Register Policy Group in Configuration
Add your Policy Group class to config/abac.php:
💻 Authorization Usage Methods
1. Programmatic Authorization via Facade
2. Native Laravel Controllers ($this->authorize)
laravel-abac integrates seamlessly with standard Laravel authorization methods. You can pass dynamic runtime attributes as an array parameter:
3. Native Gate Facade (Gate::allows)
4. Blade Directives
🏛️ Architecture Flow
🔒 Security Model
- Zero-Trust / Fail-Closed Default: If a resource or action is unmapped, access is denied (
false). - Short-Circuit Exemption: Trusted entities (e.g., Super-Admins) can bypass granular checks safely via
before(). - Dynamic Context Validation: Real-time variables (IP addresses, monetary values, time slots) are validated instantly in memory per request.
🧪 Testing
Run test suites using PHPUnit or Pest:
🛡️ Security & Vulnerabilities
If you discover any security vulnerabilities within laravel-abac, please email [email protected].
📜 License
The MIT License (MIT). Please see LICENSE for more information. Developed with ❤️ by ExpertApps.
All versions of laravel-abac with dependencies
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0