NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #224 most downloaded on Packagist
Permission handling for Laravel 12 and up
Last release 3 months ago
03 Jul 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
224 releases · first in 2015
Fix duplicate permissions being created through artisan command
Remove use of array_wrap helper function due to future deprecation
Change cache config time to DateInterval instead of integer
One column per quarter.
This is in preparation for compatibility with Laravel 5.8's cache TTL change to seconds instead of minutes.
NOTE: If you leave your existing config/permission.php file alone, then with Laravel 5.8 the 60 * 24 will change from being treated as 24 hours to just 24 minutes. Depending on your app, this may or may not make a significant difference. Updating your config file to a specific DateInterval will add specificity and insulate you from the TTL change in Laravel 5.8.
Refs:
https://laravel-news.com/cache-ttl-change-coming-to-laravel-5-8 https://github.com/laravel/framework/commit/fd6eb89b62ec09df1ffbee164831a827e83fa61d
Fix bound saved event from firing on all subsequent models when calling assignRole or givePermissionTo on unsaved models. However, it is preferable to
saved event from firing on all subsequent models when calling assignRole or givePermissionTo on unsaved models. However, it is preferable to save the model first, and then add roles/permissions after saving. See #971.Use config settings for cache reset in migration stub
Remove use of Cache facade, for Lumen compatibility
Add ability to specify a cache driver for roles/permissions caching
Added the ability to reset the permissions cache via an Artisan command:
php artisan permission:cache-resetminor update to de-duplicate code overhead
Substantial speed increase by caching the associations between models and permissions
The following changes are not "breaking", but worth making the updates to your app for consistency.
config/permission.php file changed to move cache-related settings into a sub-array. You should review the changes and merge the updates into your own config file. Specifically the expiration_time value has moved into a sub-array entry, and the old top-level entry is no longer used.app or tests are clearing the cache by specifying the cache key, it is better to use the built-in forgetCachedPermissions() method so that it properly handles tagged cache entries. Here is the recommended change:- app()['cache']->forget('spatie.permission.cache');
+ $this->app->make(\Spatie\Permission\PermissionRegistrar::class)->forgetCachedPermissions();
A model's roles and permissions relations (respectively) are now automatically reloaded after an Assign/Remove role or Grant/Revoke of permissions. Th
roles and permissions relations (respectively) are now automatically reloaded after an Assign/Remove role or Grant/Revoke of permissions. This means there's no longer a need to call ->fresh() on the model if the only reason is to reload the role/permission relations. (That said, you may want to call it for other reasons.)Fix operator used on RoleOrPermissionMiddleware, and avoid throwing PermissionDoesNotExist if invalid permission passed
Avoid unnecessary queries of user roles when fetching all permissions
Fix Lumen issue with Route helper added in 2.22.0
Added Route::role() and Route::permission() middleware helper functions
Route::role() and Route::permission() middleware helper functionsrole_or_permission middleware to allow specifying "or" combinationsRevert changes from 2.17.1 in order to support Lumen 5.7
It will sync roles/permissions to models that are not persisted, by registering a saved callback.
saved callback.```php @role('roleA') // user hasRole 'roleA' @elserole('roleB') // user hasRole 'roleB' but not 'roleA' @endrole
@elserole directive:@role('roleA')
// user hasRole 'roleA'
@elserole('roleB')
// user hasRole 'roleB' but not 'roleA'
@endrole
Spark-related fix to accommodate missing guard[providers] config
Add ability to pass in IDs or mixed values to role scope
role scope@unlessrole/@endunlessrole Blade directivesExpanded CLI permission:create-role command to create optionally create-and-link permissions in one command. Also now no longer throws an error if the
permission:create-role command to create optionally create-and-link permissions in one command. Also now no longer throws an error if the role already exists.Require laravel/framework instead of illuminate/* starting from ~5.4.0
- Laravel 5.7 compatibility
Replace static Permission::class and Role::class with dynamic value (allows custom models more easily)
Make assigning the same role or permission twice not throw an exception
Allow using another key name than model_id by defining new columns array with model_morph_key key in config file. This improves UUID compatibility as
model_id by defining new columns array with model_morph_key key in config file. This improves UUID compatibility as discussed in #777.Fix issue with null values passed to syncPermissions & syncRoles
- added hasAllPermissions method
Reverted 2.12.0. REVERTS: "Add ability to pass guard name to gate methods like can()". Requires reworking of guard handling if we're going to add this
Add ability to pass guard name to gate methods like can()
Improve speed of permission lookups with findByName, findById, findOrCreate
changes the type-hinted Authenticatable to Authorizable in the PermissionRegistrar.
Now findOrCreate() exists for both Roles and Permissions
Permissions now support passing integer id for sync, find, hasPermissionTo and hasDirectPermissionTo
add compatibility with Laravel 5.6
Allow a collection containing a model to be passed to role/permission scopes
Fix compatibility with Spark v2.0 to v5.0
Support getting guard_name from extended model when using static methods
Changes related to throwing UnauthorizedException:
Changes related to throwing UnauthorizedException:
NOTE: This Dynamic field naming was a breaking change, so we've removed it for now.
BEST NOT TO USE v2.7.7 if you've changed tablenames in the config file.
updated HasPermissions::getStoredPermission to allow a collection to be returned, and to fix query when passing multiple permissions
HasPermissions::getStoredPermission to allow a collection to be returned, and to fix query when passing multiple permissionsupdated HasRole::assignRole and HasRole::syncRoles to accept role id's in addition to role names as arguments
HasRole::assignRole and HasRole::syncRoles to accept role id's in addition to role names as argumentsfixed Gate::before for custom gate callbacks
Gate::before for custom gate callbacksadded cache clearing command in up migration for permission tables
up migration for permission tablesrefactor middleware to throw custom UnauthorizedException (which raises an HttpException with 403 response)
UnauthorizedException (which raises an HttpException with 403 response)refactor PermissionRegistrar to use $gate->before()
PermissionRegistrar to use $gate->before()log_registration_exception as it is no longer relevantfixed a bug where Roles and Permissions got detached when soft deleting a model
Roles and Permissions got detached when soft deleting a model- add support for L5.3
- add permission scope
register the blade directives in the register method of the service provider
register the blade directives in the boot method of the service provider
- let middleware use caching
add getRoleNames() method to return a collection of assigned roles
add compatibility with Laravel 5.5
automatically detach roles and permissions when a user gets deleted
fix processing of pipe symbols in @hasanyrole and @hasallroles Blade directives
@hasanyrole and @hasallroles Blade directivesadd PermissionMiddleware and RoleMiddleware
PermissionMiddleware and RoleMiddlewareallow hasAnyPermission to take an array of permissions
hasAnyPermission to take an array of permissionsfix commands not using custom models
add create-permission and create-role commands
create-permission and create-role commandsYour coding agent can read these notes before it upgrades. Set up the MCP server →