Laravel Packages

Impersonation in Laravel with the Mirror Package

Published Updated
Impersonation in Laravel with the Mirror Package image

Mirror is an elegant user impersonation package for Laravel that lets administrators log in as other users to troubleshoot issues, provide support, and test user experiences. Secure user impersonation is paramount to production applications, and Mirror provides cryptographic verification to prevent session tampering.

It works by adding an Impersonatable trait to your User model and implementing two methods. These methods define which role can impersonate other roles, and which roles are allowed to be impersonated by those with impersonation abilities:

use Illuminate\Foundation\Auth\User as Authenticatable;
use Mirror\Concerns\Impersonatable;
 
class User extends Authenticatable
{
use Impersonatable;
 
public function canImpersonate(): bool
{
return $this->hasRole('admin');
}
 
public function canBeImpersonated(): bool
{
return ! $this->hasRole('super-admin');
}
}

From there, you can start impersonating and stop impersonating using the package's Mirror facade:

use Mirror\Facades\Mirror;
 
// Start impersonating a user
Mirror::start($user);
redirect()->route('dashboard');
 
// Stop impersonating
Mirror::stop();
redirect()->route('admin.users.index');

This package also includes methods for checking the state of impersonation, events, Blade directives, and more:

@impersonating
<div class="alert">
You're impersonating {{ auth()->user()->name }}.
<a href="{{ route('impersonation.leave') }}">Exit</a>
</div>
@endimpersonating
 
{{-- Check specific guard --}}
@impersonating('admin')
<div>Impersonating via admin guard</div>
@endimpersonating

Main Features

  • HMAC-SHA256 session integrity to prevent tampering
  • Configurable TTL expiration
  • Middleware for access control and TTL enforcement
  • Multi-guard support
  • Flexible URL redirection
  • Lifecycle events for audit logging

To start using this package in your Laravel project, you can install it via Composer and publish the package's configuration options:

composer require franbarbalopez/mirror
 
php artisan vendor:publish --tag=mirror

🧑‍💻 You can find the source code and documentation on GitHub: franbarbalopez/mirror

Paul Redmond photo

Staff writer at Laravel News. Full stack web developer and author.

Sponsored

acquaintsoft logo
Acquaint Softtech

Hire Laravel developers with AI expertise at $20/hr. Get started in 48 hours.

Visit Acquaint Softtech

The latest

View all →
Pause All Laravel Queues During a Deploy image

Pause All Laravel Queues During a Deploy

Read article
Laravel Terminal UI for the artisan dev Command image

Laravel Terminal UI for the artisan dev Command

Read article
Pause All Queues and a New artisan dev UI in Laravel 13.25 image

Pause All Queues and a New artisan dev UI in Laravel 13.25

Read article
Laravel monitoring that doesn't bill you by your traffic image

Laravel monitoring that doesn't bill you by your traffic

Read article
Mock PHP Classes in Tests With the Double Library image

Mock PHP Classes in Tests With the Double Library

Read article
Laravel Discount: Coupon Codes, Usage Limits, and Stacking image

Laravel Discount: Coupon Codes, Usage Limits, and Stacking

Read article