API cheat sheet
The whole surface at a glance. Follow the links for full signatures and behaviour.
Define a schema
Section titled “Define a schema”extends Warrant\Schema\WarrantSchema — see Schema API.
const model— managed Eloquent model (or''for a schema with no model); the model must name the schema back viaHasWarrantSchema- schema key — declared as the array key in
config/warrant.php, not on the class #[Ability] const X = '...'— declare an ability (addrequiredContext: [...]for per-ability required context keys)#[RequiredContext] const X = '...'— mark a context key required on every check (context keys need no declaration to be used)#[RowCondition]/#[GlobalCondition]methods — declare conditionspublic function implicitRules(): array|WarrantRuleSet— always-on rulesprotected function defaultContext(): array— default check-time contextpublic function forbiddenDenialMessage(WarrantDenialContext $c): string|Throwable|null— message when acannotdeniedpublic function ungrantedDenialMessage(WarrantUngrantedContext $c): string|Throwable|null— message when nothing grantedSchema::guard($user)— schema-bound engine for this schema (=Warrant::forSchema(Schema::class, $user))
Build rules
Section titled “Build rules”See Rule-building API.
WarrantRuleSet::fromSyntax(string $syntax, Model|WarrantSchema|string|null $schema = null, array $bindings = [])WarrantRuleSet::fromRules(Model|WarrantSchema|string $schema, WarrantRule|WarrantRuleBuilder|array ...$rules)WarrantRuleSet::build(Model|WarrantSchema|string $schema, Closure $callback)WarrantRule::fromSyntax(string $syntax, Model|WarrantSchema|string|null $schema = null, array $bindings = [])WarrantParser::parse(string $source, array $bindings = []): WarrantRule[]WarrantParser::parseSingleRule(string $source, array $bindings = []): WarrantRuleWarrantRule::build()— fluent builder:->if/andIf/orIf/ifNot/…,->ifCan/->ifCheck(+and/orforms, withRef::context/column/sql),->theyCan/theyCannot,->toRule()
Provide rules
Section titled “Provide rules”Implement Warrant\Rules\RuleResolver — see Providing rules.
resolve(RuleResolutionContext $context): WarrantRuleSet- context:
->user,->schemaKey,->schema,->model - register in
config/warrant.php→rule_resolver,schemas
Check access
Section titled “Check access”Reach the engine three ways — see Checking API. Checks live on the engine, not the model/schema.
- Facade (target names the schema):
Warrant::can($abilities, $target, $context = [], $user = null): bool Warrant::canAny(...)— ANY (ALL iscan; there is nomatchModeargument)Warrant::cannot(...),Warrant::authorize(...): void,Warrant::authorizeAny(...): void— throwing; 403 on denial (denial messages)Warrant::abilities($target, $context = [], $user = null): arrayWarrant::flush($user = null): void— drop memoized rule sets for one user, or (with no argument) all of them (resolution lifetime)- target forms:
$model(row),[Model::class|Schema::class, $id](row by key),Model::class/Schema::class/'schema_key'(no-target) - User-bound guard:
Warrant::guard($user)or$user->warrant()(use Warrant\AuthorizesWithWarrant) →WarrantGuard(->can/canAny/cannot/authorize/authorizeAny/abilities,->forSchema(...)) - Schema-bound guard:
Warrant::forSchema($schemaOrModel, $user)orSchema::guard($user)→WarrantGuardForSchema(same methods; target is just the row ornull) - Model query helpers (
use Warrant\HasWarrantSchema) — these keepAbilityMatchMode:->userHasAbility($abilities, $user = null, $matchMode = ALL, $context = [])— query scope->selectUserAbilities($user = null, $selectedAbilitiesKey = 'abilities', ?array $onlyAbilities = null, $context = [])— query scope$model->loadUserAbilities($user = null, $selectedAbilitiesKey = 'abilities', $context = [])— attach the ability list to an instance
context:— values for the rules’@contextkeys, merged overdefaultContext()Warrant\AbilityMatchMode::ALL | ANY— used by scopes, middleware, and the lower-level query methods- Laravel Gate —
$user->can($ability, $target),Gate::authorize,@can, andcan:route middleware resolve Warrant abilities (details); toggle withregister_gate
Reachability
Section titled “Reachability”Structural check — no conditions, no SQL, no context: (user still required); schema comes first, no matchMode (use *Any). See Reachability.
Warrant::reachabilityOf($schema, $ability, $user = null): ReachabilityWarrant::couldEverHave($schema, $abilities, $user = null): bool—!== NEVER(+couldEverHaveAny)Warrant::alwaysHas($schema, $abilities, $user = null): bool—=== ALWAYS(+alwaysHasAny)Warrant::neverHas($schema, $abilities, $user = null): bool—=== NEVER(+neverHasAny)Warrant::possibleAbilities($schema, $user = null) / guaranteedAbilities(...) / impossibleAbilities(...): array- also on
Warrant::guard($user)->...(schema-first) andWarrant::forSchema($schema, $user)->...(no schema arg) Warrant\Reachability::NEVER | MAYBE | ALWAYS
Middleware
Section titled “Middleware”Warrant\Middleware\WarrantMiddleware — see Middleware API.
::string($target, $abilities, $matchMode = ALL)::guard($target, $abilities, Closure $routes, $matchMode = ALL)::canView / canCreate / canUpdate / canDelete / canArchive($target, ?Closure)- reachability guards:
::couldEver / always / never($target, $abilities, ?Closure, $matchMode = ALL)— target-free, key-only (reachability) - aliases
warrant.could-ever[.any],warrant.always[.any],warrant.never[.any]— mode/match-mode in the alias; params areschemaKey,abilities...
Config — config/warrant.php
Section titled “Config — config/warrant.php”rule_resolver— class implementingWarrant\Rules\RuleResolver(no default; required)schemas— array of schema class-strings (registration is mandatory)register_gate— register theGate::beforehook so abilities resolve through Laravel’s Gate (defaulttrue)
