Skip to content
Nevela 0.4.3: full authentication: two-factor, passkeys, emailed sign-in links, password reset, a profile picture and a list of devices.Authentication

Roles and policies

Each resource gets a policy at app/Policies/<Name>Policy.php with viewAny, view, create, update and delete. All five return true to begin with, which means any signed-in user can do everything. Change them before real use:

public function delete(User $user, Product $product): bool
{
return $user->role === 'admin';
}

Laravel checks the policy on every request and answers 403 when it says no. The dashboard shows that as an error message.

policies/index.ts can hide actions a role cannot use:

export const policies: Record<string, Policy> = {
Product: { read: ["admin", "staff"], create: ["admin"], update: ["admin"], delete: ["admin"] },
};

This only changes what is shown. Laravel’s policy is what is enforced, and a resource with no entry here shows every button and lets Laravel answer.

The role comes from a role attribute on the Laravel user. A fresh Laravel app has no such column; add one if you want roles.