Download the PHP package teksite/authorize without Composer
On this page you can find all versions of the php package teksite/authorize. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download teksite/authorize
More information about teksite/authorize
Files in teksite/authorize
Package authorize
Short Description Authorization package for managing roles and permissions in Laravel applications
License MIT
Informations about the package authorize
Teksite Authorize
A flexible and model-independent authorization package for Laravel.
Teksite Authorize provides a simple way to manage:
- Permissions
- Roles
- Role hierarchy
- Direct model permissions
- Model roles
- Role-based permissions
- Laravel Gates
- Authorization caching
- Super administrator access
- Polymorphic authorization relationships
The package is designed to work with any Eloquent model, not only User.
Features
- Model-independent authorization
- Polymorphic roles
- Polymorphic permissions
- Direct permissions for any Eloquent model
- Role-based permissions
- Multiple roles per model
- Multiple permissions per model
- Permission and role lookup by ID or title
- Laravel Gate integration
- Super administrator support
- Role hierarchy
- Authorization cache
- Cache invalidation helpers
- Artisan installation command
- Factory support
- Validation rule helpers
Requirements
This package requires a Laravel application using Eloquent ORM.
The package uses modern Laravel features such as PHP attributes, so make sure your Laravel and PHP versions support the features used by your installed package version.
Installation
Install the package through Composer:
Then run the installation command:
This command creates the required authorization migrations inside:
After that, run:
Configuration
The package configuration is available at:
Example:
Configuration options
boot_gates
Determines whether permissions should be registered as Laravel Gates.
Set to false if you do not want the package to register Gates automatically.
boot_gates_in_console
Determines whether authorization Gates should be booted while Laravel is running in console mode.
Default:
This is useful for avoiding unnecessary database access when running Artisan commands.
cache_enabled
Enables or disables authorization caching.
When disabled, authorization data is loaded directly from the database.
cache_ttl
Defines the authorization cache lifetime in seconds.
The default value is 24 hours.
super_admin_role
Defines the role that should bypass permission checks.
If the authenticated or authorized model has this role, permission checks return true.
Set it to null if you do not want to use a super administrator role.
Database Structure
The package creates five tables.
auth_permissions
Stores permissions.
| Column | Description |
|---|---|
id |
Permission ID |
title |
Unique permission name |
description |
Optional description |
created_at |
Creation timestamp |
updated_at |
Update timestamp |
Example:
auth_roles
Stores roles.
| Column | Description |
|---|---|
id |
Role ID |
title |
Unique role name |
description |
Optional description |
hierarchy |
Role hierarchy level |
created_at |
Creation timestamp |
updated_at |
Update timestamp |
Example roles:
auth_permission_role
Connects permissions to roles.
A role can have many permissions, and a permission can belong to many roles.
auth_permission_models
Connects permissions directly to any Eloquent model using a polymorphic relationship.
auth_role_models
Connects roles to any Eloquent model using a polymorphic relationship.
Basic Usage
Add HasAuthorization to a Model
Any Eloquent model can use the authorization system.
For example:
The package is not limited to User.
For example:
Or:
Or:
As long as the model is an Eloquent model, it can use the Trait.
Permissions
Creating a Permission
Finding a Permission
By ID:
By title:
Roles
Creating a Role
Assigning Permissions to a Role
Multiple permissions can be assigned:
Assigning Roles to a Model
The role can also be specified by ID:
Or by Role model:
Multiple roles:
By default, assignRole() replaces the existing roles.
To keep existing roles:
Assigning Direct Permissions
Permissions can be assigned directly to a model without using a role.
By ID:
Using a Permission model:
Multiple permissions:
By default, existing direct permissions are replaced.
To keep existing permissions:
Checking Roles
Check whether a model has a role:
By ID:
Using a Role model:
Multiple roles:
By default, hasRole() checks whether any requested role exists.
To require all roles:
Checking Permissions
Check a permission:
By ID:
Using a Permission model:
Multiple permissions:
By default, hasPermission() checks whether any requested permission exists.
To require all permissions:
Permission Sources
A model can receive permissions from two sources:
- Direct permissions
- Permissions inherited from roles
For example:
hasPermission() considers both sources.
Getting Permissions
Get All Permissions
By default, only permission IDs are returned:
Example:
To get permission titles:
Example:
Get Direct Permissions
This only returns permissions directly assigned to the model.
Example:
Role permissions are not included.
Get Permissions Through Roles
Example:
Getting Roles
Get role IDs:
Example:
Get roles with their titles:
Example:
Super Administrator
The package supports a configurable super administrator role.
Configuration:
If a model has this role:
then:
will return:
You can also check it directly:
Laravel Gates
The package automatically registers every permission as a Laravel Gate.
For example, if the database contains:
you can use:
Or:
In Blade:
The Gate internally uses the model's:
method.
Route Authorization
Because permissions are registered as Laravel Gates, Laravel's normal authorization features can be used.
Example:
Role Hierarchy
Roles have a hierarchy value.
For example:
A lower hierarchy value can access a higher hierarchy value according to the package's hierarchy comparison logic.
The model's minimum hierarchy can be retrieved with:
The maximum hierarchy:
Both values:
or:
returns:
Comparing Model Hierarchy
A model can be compared against another authorization model:
Possible results:
or:
null means the target model does not have a hierarchy value.
The target model must use:
Comparing Against a Role
A model can also be compared against a Role:
By ID:
Using a Role model:
Authorization Cache
Authorization data is cached by default.
The package caches:
- Model permissions
- Model roles
- Model hierarchy
- Permission Gate list
Cache can be configured using:
Clearing Authorization Cache
Clear all authorization caches for a model:
Warming Authorization Cache
You can pre-load authorization information:
This loads:
- Permissions
- Roles
- Hierarchy
into the authorization cache.
Cache Architecture
The package creates model-specific cache keys using the model's morph class and primary key.
Example:
This prevents collisions between different model types that have the same primary key.
For example:
will have different authorization cache keys.
Polymorphic Authorization
One of the main features of the package is that authorization is not tied to a specific model.
For example:
All of these models can use the same authorization system.
This is achieved through Laravel polymorphic relationships.
Model Relationships
Models using HasAuthorization receive:
and:
Both relationships are polymorphic.
Role Relationships
A Role has many permissions:
A Role can be assigned to many models through the polymorphic relation.
Permission Relationships
A Permission belongs to many roles:
A Permission can also be directly assigned to many models.
Validation Rules
Both Permission and Role provide suggested validation rules.
Permission
Create:
Update:
Role
Create:
Update:
The Role rules include validation for permissions and hierarchy.
Factories
The package provides factories for Permission and Role.
Permission factory:
Multiple permissions:
Role factory:
Multiple roles:
Example
A complete example:
Direct Permission Example
Roles are not mandatory.
A model can receive permissions directly:
Then:
returns:
Authorization Flow
The authorization flow can be summarized as:
When checking:
the package checks:
Cache Invalidation
The package automatically clears relevant model caches when authorization-related models are changed.
Examples include:
- Permission created
- Permission updated
- Permission deleted
- Role saved
- Role deleted
- Authorization model saved
The package also provides cache helper methods for relationship/pivot changes.
For custom direct manipulation of authorization pivot relationships, make sure the relevant authorization cache is invalidated.
For example, when changing role permissions directly:
you should ensure affected authorization model caches are cleared appropriately.
For package-level integrations, the methods available in AuthorizationCache can be used for this purpose.
Artisan Command
Install authorization migrations:
The command creates:
inside:
Existing migration files are not overwritten.
Disabling Gate Booting
If you do not want automatic Laravel Gate registration:
The model authorization methods such as:
remain available.
Disabling Cache
To disable authorization caching:
Authorization data will then be resolved directly without using the package cache.
Recommended Permission Naming
It is recommended to use a consistent permission naming convention.
For example:
This makes permissions easier to organize and use with Laravel Gates.
Recommended Role Structure
A typical application could use:
with hierarchy values such as:
The exact hierarchy values are application-dependent.
Summary
Model Methods
Model Relationships
Permission Methods
Role Methods
License
This package is open-source software.
Add your project's license information here.
Contributing
Contributions, bug reports, feature requests, and pull requests are welcome.
Before submitting a pull request, make sure that:
- The code follows Laravel conventions.
- Existing functionality is not broken.
- New functionality is covered by tests where appropriate.
- Authorization cache behavior is considered for authorization-related changes.
Security
If you discover a security vulnerability, please report it privately to the package maintainer instead of opening a public issue.
Credits
Developed by Teksite.
Package:
A model-independent authorization system for Laravel.