PHP code example of expertapps / laravel-abac

1. Go to this page and download the library: Download expertapps/laravel-abac library. Choose the download type require.

2. Extract the ZIP file and open the index.php.

3. Add this code to the index.php.
    
        
<?php
require_once('vendor/autoload.php');

/* Start to develop here. Best regards https://php-download.com/ */

    

expertapps / laravel-abac example snippets


return [
    /*
    |--------------------------------------------------------------------------
    | Registered Policy Groups
    |--------------------------------------------------------------------------
    | List of Policy Groups auto-registered into the AbacRuleRegistry
    | upon application bootstrap.
    */
    'policy_groups' => [
        App\Abac\Policies\PatientRecordPolicyGroup::class,
    ],

    /*
    |--------------------------------------------------------------------------
    | Strict Fail-Closed Policy
    |--------------------------------------------------------------------------
    | When true, any unmapped resource or action evaluates strictly to false.
    */
    'fail_closed' => true,
];

namespace App\Abac\Rules;

use ExpertApps\LaravelAbac\Contracts\AbacRuleInterface;
use ExpertApps\LaravelAbac\Domain\AttributeContext;
use App\Models\User;
use App\Models\PatientRecord;

final readonly class DepartmentMatchRule implements AbacRuleInterface
{
    public function supports(AttributeContext $context): bool
    {
        return $context->subject instanceof User
            && $context->resource instanceof PatientRecord;
    }

    public function evaluate(AttributeContext $context): bool
    {
        /** @var User $user */
        $user = $context->subject;
        /** @var PatientRecord $record */
        $record = $context->resource;

        return $user->department === $record->department;
    }
}

namespace App\Abac\Rules;

use ExpertApps\LaravelAbac\Contracts\AbacRuleInterface;
use ExpertApps\LaravelAbac\Domain\AttributeContext;

final readonly class WorkingHoursRule implements AbacRuleInterface
{
    public function supports(AttributeContext $context): bool
    {
        return true;
    }

    public function evaluate(AttributeContext $context): bool
    {
        $currentHour = (int) date('H');

        // Allow access only between 08:00 AM and 06:00 PM
        return $currentHour >= 8 && $currentHour < 18;
    }
}

namespace App\Abac\Rules;

use ExpertApps\LaravelAbac\Contracts\AbacRuleInterface;
use ExpertApps\LaravelAbac\Domain\AttributeContext;

final readonly class ExportFeeLimitRule implements AbacRuleInterface
{
    public function supports(AttributeContext $context): bool
    {
        return $context->hasAttribute('requested_export_limit');
    }

    public function evaluate(AttributeContext $context): bool
    {
        $requestedLimit = $context->getAttribute('requested_export_limit');

        // Maximum allowed export threshold is 5000
        return $requestedLimit <= 5000;
    }
}

namespace App\Abac\Policies;

use ExpertApps\LaravelAbac\Domain\AbstractPolicyGroup;
use ExpertApps\LaravelAbac\Domain\AttributeContext;
use App\Models\PatientRecord;
use App\Models\User;
use App\Abac\Rules\DepartmentMatchRule;
use App\Abac\Rules\WorkingHoursRule;
use App\Abac\Rules\ExportFeeLimitRule;

final class PatientRecordPolicyGroup extends AbstractPolicyGroup
{
    public function targetResource(): string
    {
        return PatientRecord::class;
    }

    /**
     * Fast-Pass Hook: Super Admins bypass granular rules immediately.
     */
    public function before(AttributeContext $context): ?bool
    {
        if ($context->subject instanceof User && $context->subject->is_super_admin) {
            return true;
        }

        return null; // Continue standard rule evaluation
    }

    /**
     * Action Matrix: Mapping Actions to Required Rules.
     * All listed rules under an action MUST evaluate to true.
     */
    public function actionRules(): array
    {
        return [
            'view' => [
                DepartmentMatchRule::class,
                WorkingHoursRule::class,
            ],
            'export' => [
                DepartmentMatchRule::class,
                WorkingHoursRule::class,
                ExportFeeLimitRule::class,
            ],
        ];
    }
}

return [
    'policy_groups' => [
        App\Abac\Policies\PatientRecordPolicyGroup::class,
    ],

    'fail_closed' => true,
];

use ExpertApps\LaravelAbac\Facades\Abac;
use ExpertApps\LaravelAbac\Domain\AttributeContext;

$context = AttributeContext::make(
    subject: auth()->user(),
    resource: $patientRecord,
    action: 'export',
    attributes: [
        'requested_export_limit' => 2500, // Dynamic runtime parameters
    ]
);

if (Abac::isAllowed($context)) {
    // Perform export action
}

namespace App\Http\Controllers;

use App\Models\PatientRecord;
use Illuminate\Http\Request;

class PatientRecordController extends Controller
{
    public function export(Request $request, PatientRecord $record)
    {
        // Pass dynamic attributes via standard authorize method
        $this->authorize('export', [$record,
            ['requested_export_limit' => $request->input('limit', 1000)]
        ]);

        return response()->json(['message' => 'Export successful']);
    }
}

use Illuminate\Support\Facades\Gate;

if (Gate::allows('view', [$patientRecord])) {
    // User is authorized to view
}
bash
php artisan vendor:publish --tag="abac-config"
bash
php artisan make:abac-rule DepartmentMatchRule
php artisan make:abac-rule WorkingHoursRule
php artisan make:abac-rule ExportFeeLimitRule