tooinfinity / infinity-starter-kit
Infinity Starter Kit (Laravel + Inertia + React) a full-featured, modular Laravel starter kit powered by Laravel Chisel and Laravel Fortify.
Package info
github.com/tooinfinity/infinity-starter-kit
Type:project
pkg:composer/tooinfinity/infinity-starter-kit
Requires
- php: ^8.5.0
- erag/laravel-lang-sync-inertia: ^2.4
- inertiajs/inertia-laravel: v3.0.6
- laravel/chisel: ^0.1.1
- laravel/fortify: ^1.39.0
- laravel/framework: ^13.32.0
- laravel/wayfinder: ^0.1.21
- nunomaduro/essentials: ^1.2.0
- spatie/laravel-data: ^4.23
- spatie/laravel-permission: ^8.3
Requires (Dev)
- driftingly/rector-laravel: ^2.6.2
- fakerphp/faker: ^1.24.1
- larastan/larastan: ^3.12.1
- laravel/boost: ^2.9.1
- laravel/pail: ^1.2.7
- laravel/pao: ^1.1.5
- laravel/pint: ^1.32.1
- laravel/tinker: ^3.0.2
- mockery/mockery: ^1.6.15
- nunomaduro/collision: ^8.9.5
- pestphp/pest: ^5.2.1
- pestphp/pest-plugin-browser: ^5.0.1
- pestphp/pest-plugin-laravel: ^5.0.1
- pestphp/pest-plugin-type-coverage: ^5.0.2
- rector/rector: ^2.6.7
- roave/security-advisories: dev-latest
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-23 00:05:07 UTC
README
A full-featured, modular Laravel starter kit powered by Laravel Chisel, Laravel Fortify, and Spatie Laravel Permission.
Designed for speed and cleanliness: choose your features during composer create-project, and Chisel automatically prunes unused backend routes, controllers, actions, Inertia pages, traits, model interfaces, and Pest tests.
β‘ Tech Stack
- Framework: Laravel 13 (PHP 8.5+)
- Frontend SPA: Inertia.js v3 + React 19
- TypeScript & Routing: Laravel Wayfinder (
@/actions,@/routes) - Styling: Tailwind CSS v4 + Radix UI primitives + Lucide Icons
- Bundler: Vite-Plus / Bun
- Authentication: Laravel Fortify
- Authorization / RBAC: Spatie Laravel Permission
- Feature Pruning: Laravel Chisel
- Testing: Pest 5
π Quick Start
1. Create a New Project
composer create-project tooinfinity/infinity-starter-kit my-app
During setup, the post-create-project-cmd hook will automatically:
- Generate your application encryption key.
- Initialize your local database (
database/database.sqlite). - Run database migrations.
- Trigger the interactive
php artisan install:featurescommand powered by Chisel.
2. Select Your Features
When prompted:
Which authentication features would you like to enable?
[x] Registration
[x] Email verification
[x] Two-factor authentication
Which authorization features would you like to enable?
[x] Spatie Roles & Permissions (spatie/laravel-permission)
Select the features you want using Space, then press Enter.
3. Set Up Authorization (if enabled)
php artisan authorization:setup # Creates permissions + Super Admin role php artisan admin:setup # Creates admin user interactively
4. Start Development
cd my-app
composer run dev
π οΈ Implemented Modules
π Authentication Module
| Feature | Description | Chisel Pruning |
|---|---|---|
| Registration | User registration form, routes, and user creation action. | Removes /register route, registration page, and login page register links. |
| Email Verification | Native Fortify verification flow (MustVerifyEmail), verification notice page, resend notifications. |
Strips MustVerifyEmail interface, removes verification controllers, views, and tests. |
| Two-Factor Authentication | TOTP / QR codes, recovery codes, security settings page, and 2FA challenge flow. | Strips TwoFactorAuthenticatable trait, removes 2FA routes, settings UI, controllers, and tests. |
| Account & Security | Login/logout, password reset, profile updates, password change, appearance settings. | Core β always retained. |
π‘οΈ Authorization & RBAC Module
A Policy-Free role-based access control system powered by spatie/laravel-permission, PHP string-backed enums, and Laravel Gates.
Architecture
Permission enum (source of truth)
β
βΌ
Spatie Permission models
β
Gate::before() ββ Super Admin bypass
β
Form Request authorize() ββ Per-endpoint access control
β
Inertia shared props ββ Frontend authorization data
β
useAuthorization() hook / <Can> component ββ UI helpers
Key Design Decisions
- No Policies β All authorization uses
Gate::before()for super-admin bypass, Spatie permission checks, and Form Requestauthorize()methods. - PHP Enums β
App\Enums\PermissionandApp\Enums\Roleare the single source of truth for permission/role identifiers. No magic strings. - Two Setup Commands β Separation of concerns:
authorization:setupmanages permissions/roles,admin:setupmanages users. - Frontend UI Helpers β
useAuthorization()hook and<Can>component read shared Inertia props. These are UI helpers only; server-side authorization is the actual security boundary.
Permission Enum
enum Permission: string { case UsersView = 'users.view'; case UsersCreate = 'users.create'; case UsersUpdate = 'users.update'; case UsersDelete = 'users.delete'; }
Add your own permissions by extending the enum. Run php artisan authorization:setup to synchronize.
Role Enum
enum Role: string { case SuperAdmin = 'super-admin'; }
Only super-admin is included in the starter kit. Add application-specific roles as needed.
Super Admin Bypass
Configured in AppServiceProvider via Gate::before():
Gate::before(function (User $user, string $ability): ?true { if ($user->hasRole(Role::SuperAdmin->value)) { return true; } return null; });
Form Request Authorization
Use the Permission enum in Form Request authorize() methods:
public function authorize(): bool { return $this->user()?->can(Permission::UsersCreate->value) ?? false; }
Frontend Authorization
useAuthorization hook:
const { can, canAny, canAll, hasRole } = useAuthorization(); if (can('users.create')) { /* ... */ } if (canAny(['users.update', 'users.delete'])) { /* ... */ } if (hasRole('super-admin')) { /* ... */ }
Can component:
<Can permission="users.create"> <Button>Create User</Button> </Can> <Can permissions={['users.update', 'users.delete']} mode="any"> <Button>Manage Users</Button> </Can>
Chisel Pruning
When authorization is disabled, Chisel removes:
HasRolestrait fromUsermodelGate::before()fromAppServiceProvider- Authorization shared props from
HandleInertiaRequests config/permission.phpand Spatie migrationsapp/Enums/Permission.phpandapp/Enums/Role.php- Both setup commands
- Frontend hook,
<Can>component, and authorization types - All authorization tests
π Reporting & Analytics Module
A production-ready, read-only reporting engine designed to extract actionable insights directly from existing application models (users and audit_trails) without redundant tables or schema overhead.
Implemented Reports
| Report | Path | Metrics & Visualizations |
|---|---|---|
| User Activity & Growth | /reports/users |
Total users, active/inactive counts, period registrations, daily registration trend SVG chart, and filterable/sortable user listing. |
| Audit Trail Activity | /reports/audit |
Total audit events, active actors, top event & resource, event distribution breakdown, daily volume trend chart, and audit log table. |
Key Design Decisions
- Strictly Read-Only β Directly queries existing application tables; no parallel database models, snapshots, or migrations.
- Dedicated Query Services β Complex aggregations and filtering live in
App\Queries\Reporting, keeping controllers clean and invokable. - Spatie Data Transfer Objects β Typed contracts (
ReportSummaryCardData,ReportTimeSeriesPointData,ReportBreakdownItemData,ReportMetadataData) serialize seamlessly to Inertia. - Zero-Dependency Accessible Visualizations β Custom SVG/CSS charts featuring interactive tooltips, full keyboard/screen-reader accessibility, RTL layout support, and a companion tabular view switch.
- Secure Streaming CSV Export β Memory-efficient cursor streaming (
cursor()), Excel UTF-8 BOM (\xEF\xBB\xBF), and formula injection sanitization (=,+,-,@,\t,\rneutralized). - Granular RBAC Permissions β Protected via
Permission::ReportsView(reports.view) andPermission::ReportsExport(reports.export). - Trilingual Localization β Full translations available in English (
en), French (fr), and Arabic (ar).
Chisel Pruning
When reporting is unselected in Chisel, all 25 reporting files (controllers, queries, DTOs, translations, frontend components, pages, and tests) are cleanly deleted and routes are removed.
π§© Chisel-Based Optional Module System
The Infinity Starter Kit features a deterministic, dependency-aware module composition and removal system built on Laravel Chisel. The system operates strictly as a project generation and transformation toolβthere are no runtime module registries or database toggles. Generated code is clean, ordinary Laravel code.
Module Categories
- Core (Permanent): Authentication foundation (Laravel Fortify), base layout, Inertia v3 infrastructure, React 19 application shell, shared UI primitives (shadcn/ui), TypeScript configs, and SQLite database foundation. Core functionality can never be pruned.
- Optional Modules:
- Authorization (
authorization): Spatie Roles & Permissions, PHP enums, Gate super-admin bypass, frontend<Can>component anduseAuthorizationhook. - Settings (
settings): Key-value application settings storage,Settingmodel, settings controllers, forms, and pages. - User Management (
user-management): Administrative user directory, creation/edit modals, role assignment, user activation/deactivation. - Localization (
localization): Trilingual support (EN, FR, AR), RTL layout switching,Localeenum,LanguageSelectorcomponent, and@erag/lang-sync-inertia. - Notifications (
notifications): Database and email notification center, user preference toggles, notification dropdown and bell. - Audit Trails (
audit-trails): Searchable activity log tracking user actions, IP addresses, user agents, and timestamps. - Reporting & Analytics (
reporting): Read-only dashboards, SVG trend charts, date filtering, and streaming CSV exports.
- Authorization (
πΊοΈ Dependency Graph & Compatibility Matrix
Modules declare their requirements explicitly. Dependencies are automatically resolved during installation, and reverse dependencies are strictly validated before removal.
Authentication (Core)
β
βββ Authorization
β β
β βββ User Management
β β β
β β βββ Reporting
β β
β βββ Reporting
β
βββ Settings
β
βββ Localization
β β
β βββ Notifications
β
βββ Audit Trails
β
βββ Reporting
| Module | Identifier | Depends On | Composer Packages | NPM Packages | Permissions |
|---|---|---|---|---|---|
| Authorization | authorization |
Core (Authentication) | spatie/laravel-permission |
β | authorization.manage |
| Settings | settings |
Core | β | β | settings.manage |
| User Management | user-management |
authorization |
spatie/laravel-data |
β | users.view, users.create, users.update, users.delete, users.manage-roles, users.manage-password |
| Localization | localization |
Core | erag/laravel-lang-sync-inertia |
@erag/lang-sync-inertia |
β |
| Notifications | notifications |
localization |
β | β | β |
| Audit Trails | audit-trails |
Core (Authentication) | β | β | audit.view |
| Reporting | reporting |
authorization, audit-trails, user-management |
spatie/laravel-data |
β | reports.view, reports.export |
π¦ Installation Flow
During composer create-project, the post-create-project-cmd hook triggers php artisan install:features, prompting:
Which authentication features would you like to enable?
[x] Registration
[x] Email verification
[x] Two-factor authentication
Which optional modules should be installed?
[x] Authorization
[x] Settings
[x] User Management
[x] Localization
[x] Notifications
[x] Audit Trails
[x] Reporting
Non-Interactive Installation
Pass answers as a JSON string via the --answers option:
php artisan install:features --answers='{"auth_features":["registration","two-factor-authentication"],"optional_modules":["authorization","settings","user-management","localization","notifications","audit-trails","reporting"]}' --no-interaction
If a module is selected, its required dependencies are automatically included (e.g. selecting user-management automatically retains authorization). Unselected modules have all exclusive code, routes, permissions, translations, and dependencies cleanly pruned.
ποΈ Removing an Optional Module
You can safely remove an optional module at any time using the module:remove Artisan command:
php artisan module:remove reporting
Reverse Dependency Validation
If another installed module depends on the module you wish to remove, removal is safely blocked:
$ php artisan module:remove audit-trails ERROR Cannot remove Audit Trails because Reporting depends on it. Remove Reporting first.
To remove audit-trails, remove reporting first.
Database Safety Warning
Warning
Database Data Safety: Removing a module removes its source code, routes, views, configuration, and dependencies. It does not automatically destroy production database data or drop tables. If the module previously migrated tables (e.g. audit_trails, settings), manage database rollbacks explicitly according to your data retention policies.
β Developer Checklist: Adding a New Optional Module
Adding a new optional module is predictable and structured:
- Define module case in
App\Enums\Module: Add a new enum case, identifier,label(),description(), andchiselTag(). - Declare module dependencies:
Specify any prerequisite modules in
Module::dependencies(). - Map owned files:
Add all module-exclusive files (actions, controllers, models, queries, requests, pages, tests) to
Module::ownedFiles(). - Map shared files:
Add any core/shared files containing chisel section markers (
/* @chisel-[tag] */) toModule::sharedFiles(). - Declare Composer packages:
Specify packages in
Module::composerPackages(). Packages used across multiple modules (e.g.,spatie/laravel-data) will only be pruned when all consuming modules are removed. - Declare NPM packages:
Specify frontend packages in
Module::npmPackages(). - Declare permissions:
Add module permissions to
App\Enums\Permissionwrapped in chisel markers, and register them inModule::permissions(). - Register routes:
Add route definitions in
routes/web.phpwrapped in chisel markers, and document them inModule::routes(). - Add translations:
Create dedicated translation files in
lang/{en,fr,ar}/[module].php. - Implement frontend code:
Place components and pages under
resources/js/and export types inresources/js/types/index.tswith chisel markers. - Create migrations:
Provide isolated migrations with clear ownership (e.g.
create_[module]_table.php). - Configure Chisel transformations:
chisel.phpautomatically discovers the new module options throughModule::options(). - Add installation & removal tests:
Ensure the module is covered in
tests/Unit/Modules/ModuleTest.phpandModuleResolverTest.php. - Verify static analysis & type safety:
Run
vendor/bin/phpstan analyse(levelmax) andbun run test:types. - Update documentation: Add the module to the compatibility matrix and roadmap.
- Format code:
Run
vendor/bin/pint --format agentandbun run lint.
π§ͺ Testing & Quality Control
# Run full test suite with 100% code coverage requirement composer test # Run all unit and feature tests vendor/bin/pest tests/Unit tests/Feature --compact # Check type coverage (100% required) vendor/bin/pest --type-coverage --min=100 # Static analysis (PHPStan at max level) vendor/bin/phpstan analyse # Code formatting & styling composer run lint
π Key Directory Structure
βββ app/
β βββ Actions/ # Reusable business logic actions
β βββ Console/Commands/ # Artisan commands
β β βββ InstallFeaturesCommand.php
β β βββ SetupAuthorizationCommand.php
β β βββ SetupAdminUserCommand.php
β βββ Data/ # Spatie Data transfer objects
β β βββ Reporting/ # Report summary, series, and breakdown DTOs
β βββ Enums/ # PHP string-backed enums
β β βββ AuditEvent.php
β β βββ Permission.php
β β βββ ReportCategory.php
β β βββ ReportType.php
β β βββ Role.php
β βββ Http/
β β βββ Controllers/ # Inertia HTTP controllers
β β β βββ AuditTrails/
β β β βββ Reporting/ # Invokable reporting & export controllers
β β β βββ Users/
β β βββ Middleware/ # HandleInertiaRequests (shares auth data)
β β βββ Requests/ # Form Requests with authorize() & validation
β βββ Models/ # Eloquent models (User, AuditTrail, Setting)
β βββ Queries/ # Read-only query & export services
β β βββ AuditTrails/
β β βββ Reporting/ # UserReportQuery, AuditReportQuery, CSV streams
β β βββ Users/
β βββ Providers/ # AppServiceProvider (Gate::before)
βββ chisel.php # Feature pruning configuration
βββ config/
β βββ fortify.php
β βββ permission.php # Spatie Permission config
βββ database/migrations/ # Users, Audit Trails, Settings, Permissions
βββ lang/ # Localized translations (en, fr, ar)
βββ resources/js/
β βββ components/
β β βββ can.tsx # <Can> authorization component
β β βββ reports/ # Summary cards, SVG charts, date range filters
β βββ hooks/
β β βββ use-authorization.ts # useAuthorization() hook
β βββ pages/
β β βββ reports/ # Catalog index, Users report, Audit report
β βββ types/
β βββ auth.ts # Auth type with permissions/roles
β βββ reports.ts # Report DTO & filter type definitions
βββ tests/
βββ Feature/
β βββ Authorization/ # RBAC + command tests
β βββ Reporting/ # Report queries, controllers, exports, and pruning tests
βββ Unit/
βββ Enums/ # Enum tests
βββ Reporting/ # Report type & category tests
π License
This starter kit is open-sourced software licensed under the MIT license.