tooinfinity / infinity-starter-kit
Infinity Starter Kit (Laravel + Inertia + React) a full-featured, modular Laravel starter kit powered by Laravel Chisel and Laravel Fortify.
Package info
github.com/tooinfinity/infinity-starter-kit
Type:project
pkg:composer/tooinfinity/infinity-starter-kit
Requires
- php: ^8.5.0
- erag/laravel-lang-sync-inertia: ^2.4
- inertiajs/inertia-laravel: v3.0.6
- laravel/chisel: ^0.1.1
- laravel/fortify: ^1.39.0
- laravel/framework: ^13.32.0
- laravel/wayfinder: ^0.1.21
- nunomaduro/essentials: ^1.2.0
- spatie/laravel-data: ^4.23
- spatie/laravel-permission: ^8.3
Requires (Dev)
- driftingly/rector-laravel: ^2.6.2
- fakerphp/faker: ^1.24.1
- larastan/larastan: ^3.12.1
- laravel/boost: ^2.9.1
- laravel/pail: ^1.2.7
- laravel/pao: ^1.1.5
- laravel/pint: ^1.32.1
- laravel/tinker: ^3.0.2
- mockery/mockery: ^1.6.15
- nunomaduro/collision: ^8.9.5
- pestphp/pest: ^5.2.1
- pestphp/pest-plugin-browser: ^5.0.1
- pestphp/pest-plugin-laravel: ^5.0.1
- pestphp/pest-plugin-type-coverage: ^5.0.2
- rector/rector: ^2.6.7
- roave/security-advisories: dev-latest
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-24 00:52:36 UTC
README
A full-featured, modular Laravel starter kit powered by Laravel Chisel, Laravel Fortify, and Spatie Laravel Permission.
Designed for speed and cleanliness: choose your features during composer create-project, and Chisel automatically prunes unused backend routes, controllers, actions, Inertia pages, traits, model interfaces, and Pest tests.
β‘ Tech Stack
- Framework: Laravel 13 (PHP 8.5+)
- Frontend SPA: Inertia.js v3 + React 19
- TypeScript & Routing: Laravel Wayfinder (
@/actions,@/routes) - Styling: Tailwind CSS v4 + Radix UI primitives + Lucide Icons
- Bundler: Vite-Plus / Bun
- Authentication: Laravel Fortify
- Authorization / RBAC: Spatie Laravel Permission
- Feature Pruning: Laravel Chisel
- Testing: Pest 5
π Quick Start
1. Create a New Project
composer create-project tooinfinity/infinity-starter-kit my-app
During setup, the post-create-project-cmd hook will automatically:
- Generate your application encryption key.
- Initialize your local database (
database/database.sqlite). - Run database migrations.
- Trigger the interactive
php artisan install:featurescommand powered by Chisel.
2. Select Your Features
When prompted:
Which authentication features would you like to enable?
[x] Registration
[x] Email verification
[x] Two-factor authentication
Which authorization features would you like to enable?
[x] Spatie Roles & Permissions (spatie/laravel-permission)
Select the features you want using Space, then press Enter.
3. Set Up Authorization (if enabled)
php artisan authorization:setup # Creates permissions + Super Admin role php artisan admin:setup # Creates admin user interactively
4. Start Development
cd my-app
composer run dev
π οΈ Implemented Modules
π Authentication Module
| Feature | Description | Chisel Pruning |
|---|---|---|
| Registration | User registration form, routes, and user creation action. | Removes /register route, registration page, and login page register links. |
| Email Verification | Native Fortify verification flow (MustVerifyEmail), verification notice page, resend notifications. |
Strips MustVerifyEmail interface, removes verification controllers, views, and tests. |
| Two-Factor Authentication | TOTP / QR codes, recovery codes, security settings page, and 2FA challenge flow. | Strips TwoFactorAuthenticatable trait, removes 2FA routes, settings UI, controllers, and tests. |
| Account & Security | Login/logout, password reset, profile updates, password change, appearance settings. | Core β always retained. |
π‘οΈ Authorization & RBAC Module
A Policy-Free role-based access control system powered by spatie/laravel-permission, PHP string-backed enums, and Laravel Gates.
Architecture
Permission enum (source of truth)
β
βΌ
Spatie Permission models
β
Gate::before() ββ Super Admin bypass
β
Form Request authorize() ββ Per-endpoint access control
β
Inertia shared props ββ Frontend authorization data
β
useAuthorization() hook / <Can> component ββ UI helpers
Key Design Decisions
- No Policies β All authorization uses
Gate::before()for super-admin bypass, Spatie permission checks, and Form Requestauthorize()methods. - PHP Enums β
App\Enums\PermissionandApp\Enums\Roleare the single source of truth for permission/role identifiers. No magic strings. - Two Setup Commands β Separation of concerns:
authorization:setupmanages permissions/roles,admin:setupmanages users. - Frontend UI Helpers β
useAuthorization()hook and<Can>component read shared Inertia props. These are UI helpers only; server-side authorization is the actual security boundary.
Permission Enum
enum Permission: string { case UsersView = 'users.view'; case UsersCreate = 'users.create'; case UsersUpdate = 'users.update'; case UsersDelete = 'users.delete'; }
Add your own permissions by extending the enum. Run php artisan authorization:setup to synchronize.
Role Enum
enum Role: string { case SuperAdmin = 'super-admin'; }
Only super-admin is included in the starter kit. Add application-specific roles as needed.
Super Admin Bypass
Configured in AppServiceProvider via Gate::before():
Gate::before(function (User $user, string $ability): ?true { if ($user->hasRole(Role::SuperAdmin->value)) { return true; } return null; });
Form Request Authorization
Use the Permission enum in Form Request authorize() methods:
public function authorize(): bool { return $this->user()?->can(Permission::UsersCreate->value) ?? false; }
Frontend Authorization
useAuthorization hook:
const { can, canAny, canAll, hasRole } = useAuthorization(); if (can('users.create')) { /* ... */ } if (canAny(['users.update', 'users.delete'])) { /* ... */ } if (hasRole('super-admin')) { /* ... */ }
Can component:
<Can permission="users.create"> <Button>Create User</Button> </Can> <Can permissions={['users.update', 'users.delete']} mode="any"> <Button>Manage Users</Button> </Can>
Chisel Pruning
When authorization is disabled, Chisel removes:
HasRolestrait fromUsermodelGate::before()fromAppServiceProvider- Authorization shared props from
HandleInertiaRequests config/permission.phpand Spatie migrationsapp/Enums/Permission.phpandapp/Enums/Role.php- Both setup commands
- Frontend hook,
<Can>component, and authorization types - All authorization tests
π Reporting & Analytics Module
A production-ready, read-only reporting engine designed to extract actionable insights directly from existing application models (users and audit_trails) without redundant tables or schema overhead.
Implemented Reports
| Report | Path | Metrics & Visualizations |
|---|---|---|
| User Activity & Growth | /reports/users |
Total users, active/inactive counts, period registrations, daily registration trend SVG chart, and filterable/sortable user listing. |
| Audit Trail Activity | /reports/audit |
Total audit events, active actors, top event & resource, event distribution breakdown, daily volume trend chart, and audit log table. |
Key Design Decisions
- Strictly Read-Only β Directly queries existing application tables; no parallel database models, snapshots, or migrations.
- Dedicated Query Services β Complex aggregations and filtering live in
App\Queries\Reporting, keeping controllers clean and invokable. - Spatie Data Transfer Objects β Typed contracts (
ReportSummaryCardData,ReportTimeSeriesPointData,ReportBreakdownItemData,ReportMetadataData) serialize seamlessly to Inertia. - Zero-Dependency Accessible Visualizations β Custom SVG/CSS charts featuring interactive tooltips, full keyboard/screen-reader accessibility, RTL layout support, and a companion tabular view switch.
- Secure Streaming CSV Export β Memory-efficient cursor streaming (
cursor()), Excel UTF-8 BOM (\xEF\xBB\xBF), and formula injection sanitization (=,+,-,@,\t,\rneutralized). - Granular RBAC Permissions β Protected via
Permission::ReportsView(reports.view) andPermission::ReportsExport(reports.export). - Trilingual Localization β Full translations available in English (
en), French (fr), and Arabic (ar).
Chisel Pruning
When reporting is unselected in Chisel, all 25 reporting files (controllers, queries, DTOs, translations, frontend components, pages, and tests) are cleanly deleted and routes are removed.
π§© Chisel-Based Scaffolding & Feature Installation
The Infinity Starter Kit features a deterministic, declarative feature configuration and pruning system built on Laravel Chisel (matching the architecture of official starter kits like laravel/react-starter-kit). The system operates strictly as a one-time project generation and scaffolding tool. Once configured via php artisan install:features, Chisel prunes all unselected features, cleans up its own installer files (chisel.php, InstallFeaturesCommand.php, and Chisel requirements), leaving behind pure, zero-overhead Laravel application code.
Feature Categories
- Core (Permanent): Authentication foundation (Laravel Fortify), base layout, Inertia v3 infrastructure, React 19 application shell, shared UI primitives (shadcn/ui), TypeScript configs, and SQLite database foundation. Core functionality is never pruned.
- Optional Modules:
- Authorization (
authorization): Spatie Roles & Permissions, PHP enums, Gate super-admin bypass, frontend<Can>component anduseAuthorizationhook. - Settings (
settings): Key-value application settings storage,Settingmodel, settings controllers, forms, and pages. - User Management (
user-management): Administrative user directory, creation/edit modals, role assignment, user activation/deactivation. - Localization (
localization): Trilingual support (EN, FR, AR), RTL layout switching,Localeenum,LanguageSelectorcomponent, and@erag/lang-sync-inertia. - Notifications (
notifications): Database and email notification center, user preference toggles, notification dropdown and bell. - Audit Trails (
audit-trails): Searchable activity log tracking user actions, IP addresses, user agents, and timestamps. - Reporting & Analytics (
reporting): Read-only dashboards, SVG trend charts, date filtering, and streaming CSV exports.
- Authorization (
πΊοΈ Feature Compatibility Matrix
| Module | Identifier | Composer Packages | Frontend Packages (Bun) | Permissions |
|---|---|---|---|---|
| Authorization | authorization |
spatie/laravel-permission |
β | authorization.manage |
| Settings | settings |
β | β | settings.manage |
| User Management | user-management |
spatie/laravel-data |
β | users.view, users.create, users.update, users.delete, users.manage-roles, users.manage-password |
| Localization | localization |
erag/laravel-lang-sync-inertia |
@erag/lang-sync-inertia |
β |
| Notifications | notifications |
β | β | β |
| Audit Trails | audit-trails |
β | β | audit.view |
| Reporting | reporting |
spatie/laravel-data |
β | reports.view, reports.export |
π¦ Installation Flow
During composer create-project, the post-create-project-cmd hook triggers php artisan install:features, prompting:
Which authentication features would you like to enable?
[x] Registration
[x] Email verification
[x] Two-factor authentication
Which optional modules should be installed?
[x] Authorization
[x] Settings
[x] User Management
[x] Localization
[x] Notifications
[x] Audit Trails
[x] Reporting
Non-Interactive Installation
Pass answers as a JSON string via the --answers option:
php artisan install:features --answers='{"auth_features":["registration","two-factor-authentication"],"optional_modules":["authorization","settings","user-management","localization","notifications","audit-trails","reporting"]}' --no-interaction
Unselected modules have all exclusive code, routes, permissions, translations, and dependencies cleanly pruned.
Post-Installation Self-Cleanup
Upon finishing execution, Chisel automatically cleans up the repository:
- Strips
@php artisan install:features --ansiand"laravel/chisel"fromcomposer.json. - Formats all PHP code using Laravel Pint (
vendor/bin/pint --format agent). - Re-generates Wayfinder typed routes and actions (
php artisan wayfinder:generate --with-form --no-interaction). - Deletes
chisel.php,app/Console/Commands/InstallFeaturesCommand.php, and Chisel installer tests.
β Developer Checklist: Adding a New Scaffolding Feature
Adding a new optional module or feature in chisel.php is simple and declarative:
- Add Question Option:
Add the feature identifier and label to the
optional_modulesquestion inchisel.php. - Register Selected Handler:
Use
->selected('optional_modules', '<feature>', then: fn(Chisel $c) => ..., else: fn(Chisel $c) => ...):- In
then: use$c->files(...)->removeSectionMarkers('<tag>')to strip markers when kept. - In
else:- AST mutations via
$c->php('...')->removeImport(...)->removeTrait(...) - Strip sections via
$c->files(...)->removeSection('<tag>') - Delete exclusive files via
$c->files(...)->delete() - Prune exclusive packages via
$c->file('composer.json')->removeLinesContaining(...) - Prune empty directories using
chiselPruneEmptyDirectories(__DIR__, [...])
- AST mutations via
- In
- Handle Shared Packages:
Use
->selectedAny('optional_modules', ['<feature1>', '<feature2>'], else: ...)for packages shared across multiple features. - Wrap Shared Code in Markers:
Surround feature-specific routes, sidebar items, and type definitions with
/* @chisel-<tag> */and/* @end-chisel-<tag> */. - Verify with Pint & Pest:
Run
vendor/bin/pint --format agentandphp artisan test.
π§ͺ Testing & Quality Control
# Run full test suite with 100% code coverage requirement composer test # Run all unit and feature tests vendor/bin/pest tests/Unit tests/Feature --compact # Check type coverage (100% required) vendor/bin/pest --type-coverage --min=100 # Static analysis (PHPStan at max level) vendor/bin/phpstan analyse # Code formatting & styling composer run lint
π Key Directory Structure
βββ app/
β βββ Actions/ # Reusable business logic actions
β βββ Console/Commands/ # Artisan commands
β β βββ InstallFeaturesCommand.php
β β βββ SetupAuthorizationCommand.php
β β βββ SetupAdminUserCommand.php
β βββ Data/ # Spatie Data transfer objects
β β βββ Reporting/ # Report summary, series, and breakdown DTOs
β βββ Enums/ # PHP string-backed enums
β β βββ AuditEvent.php
β β βββ Permission.php
β β βββ ReportCategory.php
β β βββ ReportType.php
β β βββ Role.php
β βββ Http/
β β βββ Controllers/ # Inertia HTTP controllers
β β β βββ AuditTrails/
β β β βββ Reporting/ # Invokable reporting & export controllers
β β β βββ Users/
β β βββ Middleware/ # HandleInertiaRequests (shares auth data)
β β βββ Requests/ # Form Requests with authorize() & validation
β βββ Models/ # Eloquent models (User, AuditTrail, Setting)
β βββ Queries/ # Read-only query & export services
β β βββ AuditTrails/
β β βββ Reporting/ # UserReportQuery, AuditReportQuery, CSV streams
β β βββ Users/
β βββ Providers/ # AppServiceProvider (Gate::before)
βββ chisel.php # Feature pruning configuration
βββ config/
β βββ fortify.php
β βββ permission.php # Spatie Permission config
βββ database/migrations/ # Users, Audit Trails, Settings, Permissions
βββ lang/ # Localized translations (en, fr, ar)
βββ resources/js/
β βββ components/
β β βββ can.tsx # <Can> authorization component
β β βββ reports/ # Summary cards, SVG charts, date range filters
β βββ hooks/
β β βββ use-authorization.ts # useAuthorization() hook
β βββ pages/
β β βββ reports/ # Catalog index, Users report, Audit report
β βββ types/
β βββ auth.ts # Auth type with permissions/roles
β βββ reports.ts # Report DTO & filter type definitions
βββ tests/
βββ Feature/
β βββ Authorization/ # RBAC + command tests
β βββ Reporting/ # Report queries, controllers, exports, and pruning tests
βββ Unit/
βββ Enums/ # Enum tests
βββ Reporting/ # Report type & category tests
π License
This starter kit is open-sourced software licensed under the MIT license.