codecorner / laravel-setup-wizard
Browser setup wizard that starts automatically on `php artisan serve` for a fresh Laravel project.
Package info
github.com/yashgupta-dev/laravel-setup-wizard
pkg:composer/codecorner/laravel-setup-wizard
Requires
- php: ^8.1
- illuminate/support: ^10.0|^11.0|^12.0
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-01 12:40:41 UTC
README
Install it, run php artisan serve, open the URL: a fresh project walks you through
requirements, app settings, database, migrations and seeders, and the first admin account.
Install
composer require codecorner/laravel-setup-wizard --dev php artisan vendor:publish --tag=setup-wizard-config php artisan serve
Before the project is set up, artisan serve prints a reminder and every web request
redirects to /setup. Once the last step finishes, a lock file is written to
storage/app/setup-wizard.lock and the wizard's routes are no longer loaded.
Configure (config/setup-wizard.php)
user.model: your user model (App\Models\Admin, etc.).user.fields: form fields and validation rules for the first admin.user.attributes: forced values, e.g.['is_admin' => true]or['role' => 'admin'].user.creator: your own class implementingContracts\AdminCreator(assign roles, send mail, ...).seeders: seeder classes the user can tick on the migration step.migrate.fresh/migrate.paths:migrate:freshor extra migration paths.steps: add, remove, or reorder steps. Custom steps extendSteps\Step.environments: defaults to['local']. The wizard never runs elsewhere.
Notes
- Settings are held in
storage/app/setup-wizard.staged.jsonand written to.envonce, after the last step, soartisan serverestarts only at the very end. - The database must exist already (SQLite files are created for you).
- Run
php artisan setup:resetto remove the lock and run the wizard again. - If the user table already has rows, the project counts as set up (
detect_existing).
Security
- Local only: runs when
APP_ENVis inenvironments(defaultlocal), and only for clients inallowed_ipswith a Host header matchingallowed_hosts. Don't add0.0.0.0or*. Never runartisan serve --host=0.0.0.0on an unconfigured project. - An existing user is never overwritten unless
user.update_existingistrue. - Secrets sit in
storage/app/setup-wizard.staged.json(mode 0600) until the last step, then move to.env. - SQLite paths are limited to
.sqlite/.dbfiles inside the project; values with line breaks are rejected.