tooinfinity / infinity-starter-kit
Infinity Starter Kit (Laravel + Inertia + React) a full-featured, modular Laravel starter kit powered by Laravel Chisel and Laravel Fortify.
Package info
github.com/tooinfinity/infinity-starter-kit
Language:TypeScript
Type:project
pkg:composer/tooinfinity/infinity-starter-kit
Requires
- php: ^8.5.0
- inertiajs/inertia-laravel: v3.0.6
- laravel/chisel: ^0.1.1
- laravel/fortify: ^1.37.2
- laravel/framework: ^13.18.0
- laravel/wayfinder: ^0.1.20
- nunomaduro/essentials: ^1.2.0
- spatie/laravel-data: ^4.23
- spatie/laravel-permission: ^8.3
Requires (Dev)
- driftingly/rector-laravel: ^2.5.0
- fakerphp/faker: ^1.24.1
- larastan/larastan: ^3.10.0
- laravel/boost: ^2.4.11
- laravel/pail: ^1.2.7
- laravel/pao: ^1.1.2
- laravel/pint: ^1.29.3
- laravel/tinker: ^3.0.2
- mockery/mockery: ^1.6.12
- nunomaduro/collision: ^8.9.4
- pestphp/pest: ^5.0
- pestphp/pest-plugin-browser: ^5.0
- pestphp/pest-plugin-laravel: ^5.0
- pestphp/pest-plugin-type-coverage: ^5.0
- rector/rector: ^2.5.2
- roave/security-advisories: dev-latest
This package is auto-updated.
Last update: 2026-08-31 22:25:56 UTC
README
A full-featured, modular Laravel starter kit powered by Laravel Chisel, Laravel Fortify, and Spatie Laravel Permission.
Designed for speed and cleanliness: choose your features during composer create-project, and Chisel automatically prunes unused backend routes, controllers, actions, Inertia pages, traits, model interfaces, and Pest tests.
β‘ Tech Stack
- Framework: Laravel 13 (PHP 8.5+)
- Frontend SPA: Inertia.js v3 + React 19
- TypeScript & Routing: Laravel Wayfinder (
@/actions,@/routes) - Styling: Tailwind CSS v4 + Radix UI primitives + Lucide Icons
- Bundler: Vite-Plus / Bun
- Authentication: Laravel Fortify
- Authorization / RBAC: Spatie Laravel Permission
- Feature Pruning: Laravel Chisel
- Testing: Pest 5
π Quick Start
1. Create a New Project
composer create-project tooinfinity/infinity-starter-kit my-app
During setup, the post-create-project-cmd hook will automatically:
- Generate your application encryption key.
- Initialize your local database (
database/database.sqlite). - Run database migrations.
- Trigger the interactive
php artisan install:featurescommand powered by Chisel.
2. Select Your Features
When prompted:
Which authentication features would you like to enable?
[x] Registration
[x] Email verification
[x] Two-factor authentication
Which authorization features would you like to enable?
[x] Spatie Roles & Permissions (spatie/laravel-permission)
Select the features you want using Space, then press Enter.
3. Set Up Authorization (if enabled)
php artisan authorization:setup # Creates permissions + Super Admin role php artisan admin:setup # Creates admin user interactively
4. Start Development
cd my-app
composer run dev
π οΈ Implemented Modules
π Authentication Module
| Feature | Description | Chisel Pruning |
|---|---|---|
| Registration | User registration form, routes, and user creation action. | Removes /register route, registration page, and login page register links. |
| Email Verification | Native Fortify verification flow (MustVerifyEmail), verification notice page, resend notifications. |
Strips MustVerifyEmail interface, removes verification controllers, views, and tests. |
| Two-Factor Authentication | TOTP / QR codes, recovery codes, security settings page, and 2FA challenge flow. | Strips TwoFactorAuthenticatable trait, removes 2FA routes, settings UI, controllers, and tests. |
| Account & Security | Login/logout, password reset, profile updates, password change, appearance settings. | Core β always retained. |
π‘οΈ Authorization & RBAC Module
A Policy-Free role-based access control system powered by spatie/laravel-permission, PHP string-backed enums, and Laravel Gates.
Architecture
Permission enum (source of truth)
β
βΌ
Spatie Permission models
β
Gate::before() ββ Super Admin bypass
β
Form Request authorize() ββ Per-endpoint access control
β
Inertia shared props ββ Frontend authorization data
β
useAuthorization() hook / <Can> component ββ UI helpers
Key Design Decisions
- No Policies β All authorization uses
Gate::before()for super-admin bypass, Spatie permission checks, and Form Requestauthorize()methods. - PHP Enums β
App\Enums\PermissionandApp\Enums\Roleare the single source of truth for permission/role identifiers. No magic strings. - Two Setup Commands β Separation of concerns:
authorization:setupmanages permissions/roles,admin:setupmanages users. - Frontend UI Helpers β
useAuthorization()hook and<Can>component read shared Inertia props. These are UI helpers only; server-side authorization is the actual security boundary.
Permission Enum
enum Permission: string { case UsersView = 'users.view'; case UsersCreate = 'users.create'; case UsersUpdate = 'users.update'; case UsersDelete = 'users.delete'; }
Add your own permissions by extending the enum. Run php artisan authorization:setup to synchronize.
Role Enum
enum Role: string { case SuperAdmin = 'super-admin'; }
Only super-admin is included in the starter kit. Add application-specific roles as needed.
Super Admin Bypass
Configured in AppServiceProvider via Gate::before():
Gate::before(function (User $user, string $ability): ?true { if ($user->hasRole(Role::SuperAdmin->value)) { return true; } return null; });
Form Request Authorization
Use the Permission enum in Form Request authorize() methods:
public function authorize(): bool { return $this->user()?->can(Permission::UsersCreate->value) ?? false; }
Frontend Authorization
useAuthorization hook:
const { can, canAny, canAll, hasRole } = useAuthorization(); if (can('users.create')) { /* ... */ } if (canAny(['users.update', 'users.delete'])) { /* ... */ } if (hasRole('super-admin')) { /* ... */ }
Can component:
<Can permission="users.create"> <Button>Create User</Button> </Can> <Can permissions={['users.update', 'users.delete']} mode="any"> <Button>Manage Users</Button> </Can>
Chisel Pruning
When authorization is disabled, Chisel removes:
HasRolestrait fromUsermodelGate::before()fromAppServiceProvider- Authorization shared props from
HandleInertiaRequests config/permission.phpand Spatie migrationsapp/Enums/Permission.phpandapp/Enums/Role.php- Both setup commands
- Frontend hook,
<Can>component, and authorization types - All authorization tests
π§Ή Interactive Feature Pruning (chisel.php)
How Feature Pruning Works
For every unselected feature:
- Config β Disables feature flags or deletes configuration files.
- Routes β Removes route definitions from
routes/web.php. - Models β Strips unused traits and interfaces from
app/Models/User.php. - Controllers & Actions β Deletes unnecessary controllers and actions.
- Frontend Pages β Deletes unused Inertia React pages and navigation tabs.
- Tests β Deletes matching Pest test files.
Non-Interactive Installation
php artisan install:features --answers='{"auth_features":["registration","two-factor-authentication"],"authorization_features":["roles-permissions"]}'
πΊοΈ Module Roadmap
- Authentication β Registration, Email Verification, 2FA, Profile, Password, Session management.
- Authorization & RBAC β Spatie Roles & Permissions, PHP enums, Gate bypass, Form Request authorization, frontend hooks.
- User Management β Admin user directory, creation/edit modals, role assignment, user deactivation.
- Settings β Expanded user profile, security controls, and application configuration.
- Notifications β Database & mail notification center, user preference toggles.
- Audit Trails β Searchable activity log tracking changes, IP addresses, user agents, and timestamps.
- Reporting & Analytics β Dashboard metrics, date filtering, CSV exports, queued export jobs.
- Localization β Supported locales, locale switcher component, translated UI messages.
π§ͺ Testing & Quality Control
# Run all tests composer test # Run feature tests vendor/bin/pest tests/Feature # Run authorization tests vendor/bin/pest tests/Feature/Authorization tests/Unit/Enums # Code formatters and linters composer run lint # Type check (PHPStan & TypeScript) composer test:types
π Key Directory Structure
βββ app/
β βββ Actions/ # Reusable business logic actions
β βββ Console/Commands/ # Artisan commands
β β βββ InstallFeaturesCommand.php
β β βββ SetupAuthorizationCommand.php
β β βββ SetupAdminUserCommand.php
β βββ Enums/ # PHP string-backed enums
β β βββ Permission.php
β β βββ Role.php
β βββ Http/
β β βββ Controllers/ # Inertia HTTP controllers
β β βββ Middleware/ # HandleInertiaRequests (shares auth data)
β β βββ Requests/ # Form Requests with authorize()
β βββ Models/ # Eloquent models (User with HasRoles)
β βββ Providers/ # AppServiceProvider (Gate::before)
βββ chisel.php # Feature pruning configuration
βββ config/
β βββ fortify.php
β βββ permission.php # Spatie Permission config
βββ database/migrations/ # Users + Spatie Permission tables
βββ resources/js/
β βββ components/
β β βββ can.tsx # <Can> authorization component
β βββ hooks/
β β βββ use-authorization.ts # useAuthorization() hook
β βββ types/
β βββ auth.ts # Auth type with permissions/roles
βββ tests/
βββ Feature/Authorization/ # RBAC + command tests
βββ Unit/Enums/ # Enum tests
π License
This starter kit is open-sourced software licensed under the MIT license.