finds.dev← search

// the find

jeremykenedy/laravel-roles

★ 1,050 · Blade · MIT · updated Sep 2026

Role-Based Access Control (RBAC) for Laravel. Roles, permissions and role levels. Supports Laravel 5.3 through 13.

An RBAC package for Laravel that adds roles, permissions, and numeric role levels with inheritance, plus an optional CRUD GUI and JSON API for managing them. It's aimed at teams that want a self-contained, database-backed permission system with an admin interface, not just code-level Gate checks, and it explicitly supports a long tail of Laravel versions (5.3 through 13).

Entity checks let a user act on a model they own without needing an explicit permission grant, which avoids having to mint an 'edit-own-post' style permission for every ownable model. Every table name, model class, and behavior (inheritance, GUI framework, API toggle) is driven by an environment variable, so it doesn't force its own naming conventions onto an existing schema. The CI matrix actually tests PHP 8.2-8.4 against Laravel 12/13, and there's a dedicated NPlusOneQueriesTest, which matters for a package that's going to touch the users table on every permission check. `roles:switch` and `roles:update --css=` let you swap the shipped GUI theme (Bootstrap 4/5, Tailwind) without hand-editing config, and the `--force`/flag-based options make install scriptable in a deploy pipeline.

This is a parallel authorization system that doesn't touch Laravel's own Gate/Policy layer - nothing here maps to Gate::define or a Policy class, so adopting it means either running two separate permission systems side by side or tearing one out. The optional GUI ships three full, near-duplicate view trees (bootstrap4/bootstrap5/tailwind) and expects your app's layout to already yield specific named sections like inline_template_linked_css and inline_footer_scripts - real coupling if your layout doesn't have those slots. Role 'levels' bolt a second axis (a numeric hierarchy) onto named roles and permissions with inheritance you can turn off, which is flexible but is one more mental model to hold when debugging why a given user has a given permission. Both the JSON API and the GUI are gated by a single `role:admin` config value - get that wrong, or hit it before the admin role exists on a fresh install, and you've got an open CRUD surface for roles and permissions.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →