Repository navigation
Release v2.0.0 - #10
Merged
Merged
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
There was a problem hiding this comment.
Pull request overview
Release v2.0.0 of bbs-lab/nova-permission, adding granular (per-instance) permissions + an optional gate cache, tightening policy/contract typing, and substantially raising the project quality bar with full Pest coverage and CI automation.
Changes:
- Added instance-scoped (“authorizable”) permissions with an instance-override rule, plus query-level
scopeAuthorize()support. - Introduced an optional, config-driven permission/gate cache (
nova-permission.cache.*) with invalidation hooks. - Added comprehensive Pest test suite + CI workflows (tests matrix, Pint, PHPStan L8, mutation tests) and refreshed workbench/demo.
Reviewed changes
Copilot reviewed 87 out of 103 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
| workbench/routes/web.php | Redirect / to Nova for the workbench app. |
| workbench/database/seeders/DatabaseSeeder.php | Seed demo users/roles and add granular-permissions demo data. |
| workbench/database/migrations/2024_06_14_091717_create_services_table.php | Add services table for the demo resource. |
| workbench/database/factories/UserFactory.php | Add factory for seeded/test users. |
| workbench/database/factories/ServiceFactory.php | Add factory for Service demo model. |
| workbench/database/factories/PostFactory.php | Add factory for Post demo model. |
| workbench/config/view.php | Add strict_types. |
| workbench/config/session.php | Add strict_types. |
| workbench/config/services.php | Add strict_types. |
| workbench/config/queue.php | Add strict_types. |
| workbench/config/permission.php | Workbench Spatie config tweaks + imports cleanup. |
| workbench/config/nova.php | Adjust impersonation redirects to /nova. |
| workbench/config/nova-permission.php | Workbench config updated to new cache shape + imports. |
| workbench/config/mail.php | Add strict_types. |
| workbench/config/logging.php | Add strict_types. |
| workbench/config/hashing.php | Add strict_types. |
| workbench/config/filesystems.php | Add strict_types. |
| workbench/config/database.php | Workbench DB config improvements + MySQL SSL constant compatibility. |
| workbench/config/cors.php | Add strict_types. |
| workbench/config/cache.php | Add strict_types. |
| workbench/config/broadcasting.php | Add strict_types. |
| workbench/config/auth.php | Add strict_types and import-based model binding. |
| workbench/config/app.php | Add strict_types. |
| workbench/app/Providers/NovaServiceProvider.php | Register Nova routes correctly for Nova 4/5. |
| workbench/app/Policies/ServicePolicy.php | Add policy for new Service demo model. |
| workbench/app/Nova/Service.php | Add Nova resource for Service with abilities mapping. |
| workbench/app/Nova/Resource.php | Minor typing/import cleanup for Scout query docs. |
| workbench/app/Models/User.php | Use package HasRoles, add factories + impersonation support. |
| workbench/app/Models/Service.php | Add demo model implementing authorizations. |
| workbench/app/Models/Post.php | Add factories + generic return annotation for relation. |
| workbench/app/Http/Middleware/HandleInertiaRequests.php | Doc/import cleanup for Response typing. |
| tests/Unit/PermissionCacheTest.php | Add unit tests for PermissionCache wrapper. |
| tests/TestCase.php | Add Testbench base testcase, migrations + Nova resource registration. |
| tests/Pest.php | Configure Pest to use the package TestCase. |
| tests/Feature/ToolAndProviderTest.php | Add coverage for tool boot, provider hooks, and branches. |
| tests/Feature/SmokeTest.php | Add basic boot/schema/index-name regression coverage. |
| tests/Feature/ScopeAuthorizeTest.php | Add query-scope tests for instance-override semantics. |
| tests/Feature/OverrideTest.php | Add tests for override-role (“super admin”) behavior. |
| tests/Feature/NovaResourcesTest.php | Add coverage for resource trait auth + package resources/policies. |
| tests/Feature/ModelTest.php | Add coverage for authorizable relation + cache invalidation. |
| tests/Feature/HttpApiTest.php | Add coverage for API controllers, middleware, and validation. |
| tests/Feature/GranularPermissionTest.php | Add end-to-end granular permission behavior tests. |
| tests/Feature/GenerateResourcePermissionsTest.php | Add generator action/command coverage. |
| tests/Feature/GeneralPermissionTest.php | Add general (model-wide) permission behavior tests. |
| testbench.yaml | Enable package provider + adjust workbench settings. |
| src/Traits/HasRoles.php | Add instance memoization, general-vs-scoped permission resolution, cache wrapper. |
| src/Traits/Authorizations.php | Implement scopeAuthorize() matching instance-override semantics. |
| src/Traits/Authorizable.php | Switch gate check caching from Cache facade to PermissionCache wrapper. |
| src/Support/PermissionCache.php | Add config-driven cache wrapper for gate/permission checks. |
| src/Resources/Role.php | Typing/docs improvements and override-permission UI hook. |
| src/Resources/Permission.php | Typing/docs improvements and conditional MorphTo for authorizables. |
| src/Policies/Policy.php | Tighten signatures/return types to ?bool and improve typing. |
| src/PermissionBuilder.php | Add return type for translation loader. |
| src/NovaPermissionServiceProvider.php | Auto-run migrations + typed model binding for resources. |
| src/Models/Role.php | Minor typing/docs cleanup. |
| src/Models/Permission.php | Add authorizable relation typing + cache invalidation via PermissionCache. |
| src/Http/Requests/PermissionRequest.php | Add rules return typing doc. |
| src/Http/Requests/PermissionByGroupRequest.php | Add rules return typing doc. |
| src/Http/Requests/PermissionByAuthorizableRequest.php | Add rules return typing doc. |
| src/Http/Requests/AttachRequest.php | Add rules return typing doc + refine property type doc. |
| src/Http/Middleware/Authorize.php | Import-based typing/doc cleanup. |
| src/Http/Controllers/PermissionController.php | Fix null checks, orphan handling, and add stronger typing. |
| src/Contracts/Role.php | Simplify contract and update mixin typing. |
| src/Contracts/Permission.php | Add authorizable + serialization contract methods. |
| src/Contracts/HasAuthorizations.php | Add generic return typing for authorizations relation. |
| src/Actions/GenerateResourcePermissionsAction.php | Switch to updateOrCreate using new composite uniqueness semantics. |
| resources/js/stores/permission.ts | URL handling + robustness for fetch/generate flows. |
| resources/js/pages/Tool.vue | Debounced search UX + spinner + stable keys. |
| resources/js/helpers/client.ts | Guard against missing Axios response on network errors. |
| resources/js/components/PermissionGroup.vue | Re-fetch permissions on search and improve error handling. |
| README.md | Major documentation rewrite (granular permissions, caching, upgrading). |
| ray.php | Remove Ray config from repo/workbench sync. |
| phpstan.neon.dist | Raise PHPStan to level 8 and target relevant paths. |
| dist/css/tool.css | Rebuilt compiled tool CSS for updated UI. |
| database/migrations/add_override_permission_to_roles_table.php | Add override_permission flag to roles table. |
| database/migrations/add_authorizable_and_group_to_permissions_table.php.stub | Remove old stub migration approach. |
| database/migrations/add_authorizable_and_group_to_permissions_table.php | Add authorizable + group columns and fix MySQL index name length. |
| config/permission.php | Package Spatie config defaults pointing to package models. |
| config/nova-permission.php | New cache config shape + clarified comments. |
| composer.json | Update supported versions + add scripts for analysis/coverage/mutation + dev deps refresh. |
| .styleci.yml | Remove StyleCI config. |
| .scrutinizer.yml | Remove Scrutinizer config. |
| .gitignore | Update ignored paths for build/auth/cache artifacts. |
| .github/workflows/update-changelog.yml | Add release-triggered changelog automation. |
| .github/workflows/run-tests.yml | Add CI test matrix for Nova/Laravel/PHP and enforce 100% on primary job. |
| .github/workflows/run-mutation-tests.yml | Add mutation testing workflow. |
| .github/workflows/phpstan.yml | Add PHPStan workflow. |
| .github/workflows/code-style.yml | Add Pint workflow. |
| .github/dependabot.yml | Add Dependabot config for composer/actions/npm. |
| .gitattributes | Exclude dev/test/workbench sources from Composer package export. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+23
to
+27
| /** | ||
| * @extends resource<Model> | ||
| * | ||
| * @property-read string $guard_name | ||
| */ |
Comment on lines
+22
to
+26
| /** | ||
| * @extends resource<Model> | ||
| * | ||
| * @property-read string $guard_name | ||
| */ |
Comment on lines
+4
to
10
| use Laravel\Nova\Actions\ActionResource; | ||
| use Workbench\App\Nova\Post; | ||
|
|
||
| return [ | ||
| 'authorizable_models' => [ | ||
| \Workbench\App\Nova\Post::class, | ||
| Post::class, | ||
| ], |
Comment on lines
+106
to
+112
| const searching = ref<boolean>(false) | ||
| const commitSearch = _.debounce((value: string) => { | ||
| store.setSearch(value) | ||
| store.data().finally(() => { | ||
| searching.value = false | ||
| }) | ||
| }, 500) |
mikaelpopowicz
force-pushed
the
release/v2.0.0
branch
2 times, most recently
from
July 27, 2026 06:57
ea4c9b0 to
bb91385
Compare
Modernize the package to the bbs-lab quality bar (Pint, PHPStan level 8, 100% test coverage, mutation, GitHub Actions CI) and fix several real permission bugs surfaced while writing the tests. Breaking changes: - Require PHP ^8.2, Laravel Nova 4 & 5, spatie/laravel-permission ^6. - Your authenticatable model must use BBSLab\NovaPermission\Traits\HasRoles (not Spatie's) and implement CanOverridePermission. - Package migrations are now real .php files that auto-run on `migrate` (no publish step); only spatie's migration must be published. - The base Policy methods now return ?bool. Highlights: - General vs granular (per-instance) permissions with a clear instance-override rule; Authorizations::scopeAuthorize() mirrors it for index filtering. - Optional, config-driven gate cache (disabled by default). - Permission builder search (debounce + loader); impersonation-ready workbench that doubles as a manual test harness and usage demo. See the pull request description for the full changelog.
mikaelpopowicz
force-pushed
the
release/v2.0.0
branch
from
July 27, 2026 07:24
bb91385 to
6b209f3
Compare
- Resources/Permission, Resources/Role: use `@extends \Laravel\Nova\Resource<Model>` in the class docblock. Pint's phpdoc_types had lowercased it to `resource`, which reads as the PHP `resource` keyword and is fragile for PHPStan generic inference; the fully-qualified form is correct and survives formatting. - Tool.vue: guard the permission-builder search spinner with a monotonic token so a slower earlier request can no longer clear it while a newer, still in-flight search is running. Rebuilt dist/. (The third review point — registering Service in the workbench's authorizable_models — was already addressed in the release commit.)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A correctness, quality and tooling overhaul of
bbs-lab/nova-permission. The existing general/granular permission features (which were partly broken in 1.x) now actually work, the package is modernized to PHP 8.2+ / Nova 4 & 5 / spatie-permission 6, and it gains a full test suite, PHPStan level 8, Pint and GitHub Actions CI. This is not a feature release — the permission model already existed; v2.0.0 fixes and hardens it.Warning
Breaking release. See Upgrading at the bottom and UPGRADE.md.
Breaking changes
^8.2, Laravel Nova^4.0 || ^5.0, spatie/laravel-permission^6.0..phpfiles that auto-run onphp artisan migrate(the.php.stubpublish step is gone); only spatie's migration is published.gate_cacheconfig key is replaced by an opt-incachesection (disabled by default).Policymethods now return?bool.Fixed
authorizable/groupcolumns and never replaced spatie'sunique(name, guard_name), so a same-name per-instance permission could not be created; andAuthorizations::scopeAuthorize()filtered against a hardcodedchambers.idcolumn left over from another project. Now a composite unique index on(name, guard_name, authorizable_id, authorizable_type)(explicit, MySQL-safe name) + a dynamic scope.Changed
config('nova-permission.cache.enabled'), defaultfalse); was always-on viagate_cache.Post+Serviceresources for general vs granular, Nova impersonation).Added
Upgrading from 1.x
BBSLab\NovaPermission\Traits\HasRoles(not Spatie's) and implementCanOverridePermission— the policies callhasPermissionToOnModel(), which only exists on the package trait. (This was already required in 1.x; it is now documented.)php artisan migrate(package migrations apply automatically). The new composite unique index replaces spatie'sunique(name, guard_name); existing rows are unaffected.Policy, keep overrides typedModel $modeland returning?bool.gate_cacheconfig with the new opt-incachesection.