lomkit/laravel-access-control

A package to help you manage your laravel application access rights.
17,256 5
Install
composer require lomkit/laravel-access-control
Latest Version:v0.5.0
PHP:^8.2
License:MIT
Last Updated:May 27, 2026
Links: GitHub  ·  Packagist
Maintainer: GautierDele

Laravel Access Control

Laravel Access Control allows you to fully secure your application in two key areas: Policies and Queries. Manage everything in one place!

Requirements

PHP 8.2+ and Laravel 11+

Documentation, Installation, and Usage Instructions

See the documentation for detailed installation and usage instructions.

What it does

You first need to define the perimeters concerned by your applications.

Create the model control:

class PostControl extends Control
{
    protected function perimeters(): array
    {
        return [
            GlobalPerimeter::new()
                ->allowed(function (Model $user, string $method) {
                    return $user->can(sprintf('%s global models', $method));
                })
                ->should(function (Model $user, Model $model) {
                    return true;
                })
                ->query(function (Builder $query, Model $user) {
                    return $query;
                }),
            ClientPerimeter::new()
                ->allowed(function (Model $user, string $method) {
                    return $user->can(sprintf('%s client models', $method));
                })
                ->should(function (Model $user, Model $model) {
                    return $model->client()->is($user->client);
                })
                ->query(function (Builder $query, Model $user) {
                    return $query->where('client_id', $user->client->getKey());
                }),
        // ...

Specify the control in your model:

class Post extends Model
{
    use HasControl;
}

Then set up your policy:

class PostPolicy extends ControlledPolicy
{
    protected string $model = Post::class;
}

and you are ready to go !

App\Models\Post::controlled()->get() // Apply the Control to the query

$user->can('view', App\Models\Post::first()) // Check if the user can view the post according to the policy

Related Packages

gguney/rbac

Role based access control for Laravel 5

144 0
gadixsystem/visitors

"Simple Laravel Middleware to log vistors and block users"

4,691 3
cellcast/vouch

An Authentication and Authorisation package for Laravel 4

13 2
michaeltintiuc/laravel-permy

Laravel user permissions (roles or groups) based on defined routes.

41 0
ajtarragona/acl

ACL Package for access control

1,757 0