roundly-consulting / permissions-for-laravel
Native roles & permissions for Laravel — single-guard, cache-backed, additive-grant registry with Gate integration and zero third-party runtime deps.
Package info
github.com/roundly-consulting/permissions-for-laravel
pkg:composer/roundly-consulting/permissions-for-laravel
Fund package maintenance!
Requires
- php: ^8.4
- illuminate/auth: ^12.0|^13.0
- illuminate/console: ^12.0|^13.0
- illuminate/contracts: ^12.0|^13.0
- illuminate/database: ^12.0|^13.0
- illuminate/support: ^12.0|^13.0
- roundly-consulting/enums-for-laravel: ^1.0
- roundly-consulting/package-toolkit-for-laravel: ^1.0
- roundly-consulting/translatable-for-laravel: ^1.0
Requires (Dev)
- larastan/larastan: ^3.0
- laravel/pint: ^1.0
- nunomaduro/collision: ^8.0
- orchestra/testbench: ^10.0|^11.0
- pestphp/pest: ^4.0
- pestphp/pest-plugin-arch: ^4.0
- phpstan/extension-installer: ^1.4
- roundly-consulting/testing-for-laravel: ^1.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
Permissions for Laravel
Roles and permissions for any authenticatable Laravel model — native, single-guard and
cache-backed. Grant roles and direct permissions, resolve the effective set (direct and via
roles), and let Laravel's Gate and can: middleware authorize against them.
Installation
Requires PHP 8.4 and Laravel 12 or 13.
composer require roundly-consulting/permissions-for-laravel
php artisan vendor:publish --tag="permissions-migrations"
php artisan migrate
If your users have UUID/ULID keys, set PERMISSIONS_KEY_TYPE (uuid or ulid) before
migrating.
Usage
Add HasRoles to your user model:
use Illuminate\Foundation\Auth\User as Authenticatable; use RoundlyConsulting\Permissions\Concerns\HasRoles; class User extends Authenticatable { use HasRoles; }
Register permissions, bundle them into a role and assign it:
use RoundlyConsulting\Permissions\Facades\Permissions; Permissions::permission('posts.view'); // find or create Permissions::permission('posts.edit'); Permissions::role('editor')->givePermissionTo('posts.view', 'posts.edit'); Permissions::for($user)->assignRole('editor');
Then check them — Laravel's Gate answers for every registered permission:
$user->hasRole('editor'); // true $user->getAllPermissions()->pluck('name'); // direct + via roles: posts.view, posts.edit $user->can('posts.edit'); // true Route::get('/posts', PostsController::class)->middleware('can:posts.view');
Documentation
The full documentation — configuration, every feature and its API, and testing — lives on our website: roundly-consulting.com/open-source/docs/permissions-for-laravel
Release notes are in CHANGELOG.md. To contribute, see the contributing guide.
Support our work
This package is free and open source, built and maintained by Roundly Consulting. If it saves you time, please consider supporting our open-source work — a one-time donation, a monthly pledge on Patreon or a crypto donation helps fund maintenance, new features and new packages.
License
The MIT License (MIT). Copyright (c) Roundly Consulting. See LICENSE.md.