khrnchn/dms: The 48-Hour Enterprise Application

How the modern TALL stack and Filament allow a single developer to build multi-tenant, compliance-ready architecture over a weekend.

6 min read • View on GitHub • More from khrnchn

A wide shot of a watchmaker at a small desk assembling a massive bank vault door, symbolizing a solo developer building an enterprise system.
Modern frameworks provide immense leverage, allowing solo developers to construct enterprise-grade systems with minimal code.
Key Takeaways

The Illusion of Scale

Enterprise software is traditionally defined by its bulk. Multi-tenancy, granular audit trails, and role-based access control (RBAC) usually require entire teams and months of planning. The khrnchn/dms repository shatters this assumption. Built as a Final Year Project speedrun, it delivers a compliance-ready document management system with a shockingly tiny codebase.

The disparity between the system's capabilities and its code footprint is the real story. By leveraging Laravel 11 and Filament v3, the author eliminates thousands of lines of boilerplate. It proves that a single developer can now wield the architectural leverage previously reserved for well-funded engineering departments.

Moving the Backend to the UI

The core architectural shift in khrnchn/dms is its reliance on Filament Resources. Instead of sprawling controllers, form requests, and blade views, the entire CRUD lifecycle is defined in a single PHP class.

Filament collapses the MVC stack, generating complex interfaces and handling state directly from a singular resource definition.

Take file handling as an example. DocumentResource.php manages not just the upload, but the automatic extraction of metadata. It uses an afterStateUpdated hook to capture file size and type, ensuring the database stays perfectly synced with the filesystem without a dedicated controller.

FileUpload::make('file')
    ->afterStateUpdated(function (Get $get, Set $set, ?TemporaryUploadedFile $state) {
        if ($state) {
            $set('file_size', $state->getSize());
            $set('file_type', $state->getClientOriginalExtension());
        }
    });

The Two-Key State Machine

The most complex business logic resides in the AccessRequest model. It implements a strict sequential approval chain. A request starts as pending. A Manager approves it and sets an expiry date, transitioning the state to pending file admin. Finally, a File Admin grants the ultimate access.

A close-up of a brass lock mechanism with two distinct keyholes, where turning the first key unblocks the path for the second.
The intermediate pending state acts as a physical two-key system, requiring sequential clearance without the overhead of a dedicated state machine package.

Rather than pulling in a heavy state machine library, the project uses simple status columns and Filament UI actions. The state transitions happen directly from the table view via modal forms, keeping the logic tight and the user experience frictionless.

Enums as Bouncers

For role-based access control, the author outright rejects heavy database-driven permission packages like Spatie. Instead, they rely entirely on native PHP 8.1 Enums. A single Role.php file centralizes all authorization logic.

ArchitectureTraditional RBAC (e.g. Spatie)Enum RBAC (khrnchn/dms)
StorageDatabase tables (roles, permissions, pivot tables)In-code PHP 8.1 Enum class
ComplexityHigh (requires migrations, caching, complex eager loading)Low (stateless, zero database queries overhead)
Type SafetyString-based checks, prone to typosStrictly typed, IDE auto-completion native

This enum acts as a bouncer at every level. It secures backend queries by automatically scoping database calls to a user's department. It also secures the frontend routing, with Filament's navigation naturally hiding restricted panels based on simple enum helper methods.