Skip to content

Latest commit

 

History

72 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Lineweb Social self-hosted social platform shown across laptop and mobile

Lineweb Social

The open-source community foundation for Laravel.

Launch a private, branded community without rebuilding profiles, feeds,
spaces, messaging, moderation, and privacy from scratch.

Tests Release 0.2.0 beta 1 GPL 3.0 or later Laravel 13 React 19

Live beta · Product tour · Features · Quick start · Architecture · Contributing

A social foundation with a point of view

Lineweb Social is not a generic feed demo and it is not trying to hide important platform decisions behind plugins. The core owns identity, visibility, conversations, moderation, and member safety so teams can build distinctive products without rebuilding the difficult boundaries first.

Community-owned Calm by default Built to extend
Self-hosted source, data, rules, and branding stay under the operator's control. Chronological feeds, explicit relationships, and low-noise notifications avoid engagement tricks. Stable domain events, a contract-first API, and an allowlisted extension model create room for focused products.

What you can build on it

  • Branded customer or product communities.
  • Creator, professional, alumni, or membership networks.
  • Local and interest-based social platforms.
  • Private organizational communities.
  • A focused social startup with its own media, commerce, events, learning, or professional layer.

The goal is a strong shared core—not a clone with someone else's product decisions baked in.

Choose your path

Evaluate Build locally Run a pilot
Explore the live beta and product tour. Start the complete Docker stack with one command. Propose a controlled pilot with a real community.

The public beta is for evaluation and controlled pilots. It is not yet a stable 1.0, and the live installation must not be used for sensitive or business-critical member data.

Product tour

Every preview below uses synthetic local demo content. No private member data, credentials, database, uploads, or generated build output are part of the public repository.

Product identity from the first visit

The public landing experience shows the product instead of hiding it behind a generic marketing page. Login and registration continue the same visual system with clear hierarchy, responsive forms, passkey support, and familiar community context.

Lineweb Social product-led public landing page

Lineweb Social secure login experience Lineweb Social community registration experience
Passkey-ready login with a focused return path Clear registration and email-verification expectations

A useful first session, not a forced product tour

Newly verified members receive an optional four-step route into the community: make the profile recognizable, join a Space, follow one person, and publish a first post. Every step reflects real account state, existing invite links keep priority, and members can open the feed or hide the guide at any time.

Suggestions reuse the same Space visibility, profile discovery, and mutual block policies as the rest of the platform. Lineweb Social does not create a behavioral profile, track guide views, or perform social actions automatically.

Lineweb Social outcome-based Community Onboarding journey on desktop Lineweb Social Community Onboarding journey in the mobile app layout
Four real outcomes with privacy-safe discovery App-like mobile guidance without a forced tour

Community home

A responsive, chronological experience with clear publishing, conversation, relationship, and navigation paths. Direct replies add human context without recursive thread depth or changing the timeline's deterministic order.

Lineweb Social chronological feed, gallery publishing, and private messages across desktop and mobile

Light when you want it. Dark when you need it.

The full social experience follows one visual system in light, dark, or the member's device preference. Contrast, hierarchy, and touch targets stay clear instead of treating dark mode as a simple color inversion.

Lineweb Social native dark mode across laptop and mobile profile highlights

Find the conversation beyond the first few results

Start with a community-wide overview, then focus on Posts, Spaces, People or Topics. Shareable search URLs, previous/next pages and a swipeable mobile category rail help members reach older matches. Every page reapplies current visibility and safety rules, with no separate search service to configure.

Community search with focused categories and visible topic counts

Community search in dark mode Focused People search with a swipeable category rail on mobile
The same search experience in dark mode Focused discovery on mobile

See the community search contract for ordering, privacy and pagination boundaries.

Timely Stories without surveillance mechanics

Members can share a short thought, one private normalized image, or both inside a Space. Every Story expires after 24 hours, keeps the Space and mutual block boundaries on every view, and stores no viewer identity. Authors can delete their own Story early, Space moderators can remove unsafe content with a minimal audit trail, and the scheduler permanently removes expired records and media.

Lineweb Social Community Stories on the chronological desktop feed

Lineweb Social private Community Story viewer on desktop Lineweb Social Community Stories rail in the mobile feed Lineweb Social Community Story viewer in the mobile app layout
Space-aware viewer and clear retention boundary Edge-to-edge mobile discovery rail Immersive mobile Story with no horizontal overflow

Threaded conversations without the maze

Members can reply directly to a top-level comment while the conversation stays chronological and easy to scan. A focused reply composer, clear parent identity, recipient-aware notifications, and a strict one-level boundary provide useful context without recursive thread depth.

Lineweb Social one-level threaded conversation on desktop Lineweb Social one-level threaded conversation on mobile Lineweb Social focused mobile reply composer
Chronological context on desktop Readable one-level replies on mobile Focused mobile reply composer

Share with context, not leakage

Members can add a perspective to a post or send a clean repost without creating a second, detached copy. Shares remain in the original Space, preserve its visibility rules, and quietly drop source context if the original later becomes unavailable. A quote still belongs to its author; an empty repost does not survive without its source.

Lineweb Social quote post dialog on desktop Lineweb Social quote post dialog in the mobile app layout
Optional context with the original post kept visible Focused, touch-friendly mobile share flow

Decisions without exposing individual votes

Members can publish a focused poll with two to four answers and an optional closing window. Each member has one changeable vote, while timelines and APIs receive aggregate results only. Drafts stay private, published choices stay immutable, and the server enforces Space membership before accepting a vote.

Lineweb Social community poll with aggregate results on desktop Lineweb Social community poll in the mobile app layout
Clear aggregate results on desktop Touch-friendly voting on mobile

Publishing without pressure

A focused composer supports accessible four-image galleries and keeps unfinished text and media private until the author chooses to publish. Members can return through a dedicated draft library, curate retained images without reuploading them, move a draft to another Space they can post in, and publish without changing its post identity.

Lineweb Social accessible four-image post composer on desktop Lineweb Social app-like four-image post composer on mobile Lineweb Social private draft library on mobile
Focused writing and explicit publication App-first mobile composer Private unfinished work

Accessible galleries in the timeline

Published galleries stay private behind the same post policy as their Space, preserve an accessible description for every image, and use touch-friendly swipe navigation with visible position and keyboard-sized controls.

Lineweb Social four-image gallery in the desktop timeline Lineweb Social swipeable four-image gallery in the mobile timeline
Policy-protected gallery on desktop Touch-first gallery on mobile

Spaces and community operations

Public, private, and hidden Spaces combine publishing context with explicit membership, account-specific and shareable invitations, role, ownership, moderation, and a bounded highlights layer that never reorders the chronological timeline.

Lineweb Social searchable Spaces directory Lineweb Social curated Space highlights on desktop Lineweb Social swipeable Space highlights on mobile
Searchable community directory Bounded curation without timeline ranking App-first swipe rail

Invite a real community

Owners and moderators can onboard a cohort with an expiring, limited-use link without exposing elevated roles. The full link is shown only once, its token is stored as a hash, and every successful membership or revocation becomes part of the Space audit history. Guests can preview safe Space details and return to the invitation after registration and email verification.

Lineweb Social shareable Space invite link management on desktop Lineweb Social public Space invitation experience on mobile
Bounded links, one-time token display, and accountable controls Focused guest onboarding on mobile

Gather beyond the timeline

Space owners and moderators can publish official in-person, online, or hybrid events with timezone-safe scheduling and bounded capacity. Members can answer Going or Interested without joining a public attendee directory: every shared surface exposes aggregate attendance plus only the current member's own RSVP. Cancellation remains visible and audited instead of silently deleting history.

Lineweb Social official Space events and event studio on desktop Lineweb Social private RSVP controls in the mobile app layout
Official events and a focused creator studio Private, touch-friendly RSVP controls

Discovery without weakening privacy

People, posts, Spaces, relationships, and topics remain discoverable only when the current member is allowed to see them.

Lineweb Social chronological Following feed on desktop Lineweb Social chronological Following feed on mobile
People you chose, in chronological order Private relationship state on mobile

Profiles with an intentional first impression

Members can feature up to three of their own conversations without changing the chronological feed. Every Profile Highlight is rechecked against the current viewer's Space, moderation, mute, and block boundaries, while the mobile presentation stays swipe-first and app-like.

Lineweb Social creator profile with three privacy-safe highlights on desktop Lineweb Social edge-to-edge Profile Highlights rail on mobile
A deliberate creator-led introduction Swipe-first highlights on mobile

A guarded foundation for extensions

Operators can inspect every local extension manifest, its declared access, compatibility, activation state, pending schema, checksum integrity, and retained-data ownership plus immutable browser releases before deployment. A broken package is reported independently, while provider activation, backup-gated migrations, and asset publication stay in trusted deploy operations rather than the browser.

Lineweb Social extension schema and browser asset lifecycle center on desktop Lineweb Social immutable extension browser release details on mobile
Schema, immutable browser releases, and retained ownership at a glance Content-addressed CSS and ES modules with SRI
Lineweb Social privacy-aware topic trail on desktop Lineweb Social privacy-aware topic trail on mobile
Chronological, access-aware topic trails Mobile hashtag discovery

Useful notifications without inbox leakage

Members can keep delivery entirely in-app or opt into one daily email when unread updates are waiting. The queued digest exposes only category counts, rechecks access before delivery, and keeps private content and identities out of email.

Lineweb Social privacy-safe daily notification digest settings on desktop Lineweb Social daily notification digest settings in the mobile app layout
Separate in-app categories and opt-in email delivery Clear privacy boundary in an app-first layout

Private conversations with a visible safety boundary

Direct Messages are participant-only, block-aware, and honest about server access. A member can report the exact incoming message without exposing the surrounding conversation to administrators.

Lineweb Social participant-only Direct Messages on desktop Lineweb Social Direct Message thread on mobile
Focused two-person inbox and thread App-first mobile messaging
Lineweb Social evidence-limited Direct Message safety queue on desktop Lineweb Social privacy-aware Direct Message report dialog on mobile
Exact-message evidence and documented operator decisions Clear reporting scope before submission

Moderation and platform ownership

Space moderation and platform administration are separate permission boundaries. Community teams manage their Spaces; trusted platform operators work from a dedicated responsive control center with separate Overview, Members, Appeals, Safety, and append-only Audit surfaces. Account restrictions remain reason-required, account appeals are human-reviewed, and private safety reviews expose only the evidence a member explicitly submitted.

Lineweb Social accountable platform operations across desktop and mobile

Account decisions with a visible path back

Restricted members keep one clear Account Status surface, their data rights, and one bounded appeal for each distinct restriction. Operators review it in a dedicated queue; approval explicitly restores access and no automated system makes the final decision.

Lineweb Social human-reviewed account appeals queue on desktop Lineweb Social restricted member Account Status on mobile
Member context, internal record, and explicit operator action Clear status, human review, and preserved data rights
Lineweb Social Space moderation queue on mobile Lineweb Social privacy-aware member profile on mobile Lineweb Social low-noise notification center on mobile
Accountable moderation Complete member profiles Low-noise notifications

Feature map

Area Included today
Accounts Verified registration, stable handles, passkeys, two-factor authentication, strong password defaults, active-account enforcement, and one human-reviewed appeal per restriction.
Onboarding Optional outcome-based first-session guide, invitation-aware entry, privacy-safe Space and People suggestions, real progress, and a dismissal preference without behavioral tracking or automatic actions.
Profiles Editable member identity, headlines, author-curated three-post highlights, real chronological activity, public/shared/private visibility, and discovery opt-out.
Spaces Public/private/hidden communities, searchable directory, join/leave rules, account-specific and limited-use shareable invitations, roles, ownership transfer, member removal, bounded curated highlights, and official events with private RSVPs.
Publishing Focused composer, author-only drafts, private four-image WebP galleries with per-image alt text and swipe navigation, bounded private-first polls, 24-hour Space Stories with no viewer tracking, chronological posts, privacy-safe quote posts and reposts, comments, permanent conversations, and author controls.
Discovery Policy-filtered search across posts, Spaces, People and Topics, focused category filters, navigable result pages, Unicode hashtags, chronological topic trails and privacy-aware Following.
Interactions Typed Like, Celebrate, and Insightful reactions, private Saved Posts, follows, mentions, one-level direct replies, same-Space quote/repost actions, comments, copy links, and conversation shortcuts.
Messaging Canonical one-to-one conversations, participant-only history, unread state, block-aware delivery, and responsive inbox/thread views.
Trust and safety Mute, mutual block, Safety recovery, post/comment reporting, Space moderation queues, Direct Message reporting, and audited decisions.
Notifications Database-backed replies, mentions, and moderation alerts with per-category preferences, category-filtered inbox views, destination access revalidation, and opt-in privacy-safe daily email digests.
Platform operations Dedicated responsive control center, console-granted administrators, focused member, appeals, and private-safety queues, transactional suspension/reinstatement, session and API-token revocation, and searchable append-only audit history.
Data rights Password-confirmed personal JSON export and self-service deletion with active-community ownership safeguards.
Developer surface Contract-first bearer API, scoped expiring Sanctum tokens, domain events, OpenAPI draft, allowlisted extension providers, checksum-owned migrations, and immutable SRI-backed CSS/ES-module releases.

Product principles

Chronological before algorithmic

The core does not rank a member's home or Following feed. Products can add a different discovery layer later without making the shared social graph depend on opaque engagement scoring.

Safety belongs in the core

Visibility, mute, block, moderation, account access, report evidence, and audit history are server-side contracts—not frontend decoration.

Private means policy-enforced, not magically encrypted

Direct Messages and private media are access-controlled by the application. Messages are not end-to-end encrypted, and server operators retain normal database access.

Extension points should not bypass the platform

The current extension foundation accepts configured local manifests with known permissions and UI slots. Administrators can review each manifest, compatibility, and active state; deployers explicitly allowlist reviewed providers and enforce the same contract with php artisan platform:extensions. Reviewed schema changes run only from explicit, backup-gated CLI commands while providers are disabled; applied source is checksum locked and removed source retains its data. Pre-built browser assets use explicit content-addressed publication and SRI; their same-origin JavaScript is reviewed trusted code, not a sandbox. Remote downloads, arbitrary ZIP installation, browser actions, and destructive uninstall are intentionally unavailable.

Beta status

Important

0.2.0-beta.1 is the first production-shaped public beta. It is suitable for evaluation and controlled community pilots, but it is not a stable 1.0 release and operators should review the documented boundaries below.

The following are deliberately still outside the supported core:

  • Message attachments, group conversations, realtime presence, and delivery receipts.
  • Video, audio, story formats, and direct-to-object-storage uploads.
  • Recurring events, ticket sales, public attendee directories, reminders, and external calendar or conferencing synchronization.
  • Web/mobile push delivery, instant email, and custom digest schedules.
  • Advanced indexed search, a stable JavaScript UI-slot SDK, and destructive extension uninstall lifecycles.
  • Complete audit archival/export and deployment-specific retention tooling.
  • A production support, upgrade, and compatibility policy.

This boundary is intentional: the public source should be honest about what is implemented, tested, and supported.

Technology

Layer Stack
Backend PHP 8.3+, Laravel 13, Fortify, Sanctum
Frontend React 19, Inertia 3, TypeScript, Tailwind CSS 4
Interface primitives Radix UI, Lucide icons
Default local database SQLite
Quality PHPUnit, PHPStan/Larastan, Pint, ESLint, Prettier, TypeScript
License GPL-3.0-or-later

Quick start

Docker evaluation (recommended)

Requirements: Docker with Compose v2, OpenSSL, and curl.

git clone https://github.com/drewmt/lineweb-social.git
cd lineweb-social
./bin/docker-setup

Open http://127.0.0.1:8080. The command builds the application, starts MariaDB, runs migrations, starts the queue worker and scheduler, and waits for the health endpoint. Generated secrets stay in the ignored .env.docker file; database and private media persist in named volumes. Read the Docker evaluation guide for lifecycle and reset commands.

Native development

Requirements:

  • PHP 8.3+ with GD/WebP, EXIF, Fileinfo, and SQLite support.
  • Composer 2.
  • Node.js 22 and npm.
git clone https://github.com/drewmt/lineweb-social.git
cd lineweb-social
composer run setup
composer run dev

composer run setup installs dependencies, creates the local environment, generates the application key, runs migrations, and builds the frontend. The default example mailer writes messages to the local log; configure a real transactional provider before inviting members in a deployment. Daily email delivery is off by default; enabling it also requires Laravel's scheduler and a worker that processes the notifications queue (for example, php artisan queue:work --queue=notifications,default). Read the notification delivery contract before turning it on.

Bootstrap the first community

After an owner has registered and verified their email, a trusted operator can prepare an idempotent private starter Space without creating a shared demo account or password:

php artisan platform:starter-community owner@example.com --confirm

The starter includes welcome, introductions, and roadmap prompts plus one highlighted post. Read the starter community contract for customization and safety boundaries.

Quality checks

composer run ci:check
npm run build
composer validate --strict
composer audit
npm audit --omit=dev

Architecture and contracts

The implementation is intentionally documented around boundaries rather than only code structure.

Contract Documentation
Platform boundaries and extension direction docs/platform-architecture.md
Reproducible local Docker evaluation docs/docker.md
Idempotent first-community bootstrap docs/starter-community.md
Extension manifests and compatibility inspection docs/extensions.md
Extension migration ownership and rollback docs/extension-migrations.md
Extension browser assets and integrity docs/extension-assets.md
Authenticated API and machine-readable draft docs/api-v1.md · docs/openapi.json
Direct Messages docs/direct-messages.md
Chronological comments and direct replies docs/conversations.md
Private message reporting and evidence retention docs/message-reporting.md
Post/comment moderation and domain events docs/moderation.md
Notification privacy and delivery categories docs/notifications.md
Private post drafts and publication boundary docs/post-drafts.md
Post polls and aggregate-result boundary docs/post-polls.md
Post media validation and lifecycle docs/media.md
Unicode topics and visibility docs/topics.md
Official Space events and private RSVP boundary docs/space-events.md
Shareable Space invite links and onboarding docs/space-invite-links.md
Platform administration docs/platform-administration.md
Account status and human-reviewed appeals docs/account-appeals.md
Personal export and account deletion docs/privacy-and-data-rights.md
Example extension manifest extensions/example-polls/extension.json

Contributing

Contributions are welcome when they strengthen the shared core without weakening privacy, moderation, or authorization boundaries.

  1. Read CONTRIBUTING.md.
  2. Check existing issues and pull requests before starting.
  3. Open an issue before a large architectural change.
  4. Keep changes focused, tested, documented, and compatible with the public contracts.

Please also follow the Code of Conduct and report security concerns through SECURITY.md, not a public issue.

License and credits

Lineweb Social is free and open-source software licensed under GPL-3.0-or-later.

Created by Andrew Matia and Lineweb.

Copyright © 2026 Andrew Matia and Lineweb.

About

Open-source Laravel community platform for private, branded social networks with profiles, feeds, messaging, moderation, privacy, and Docker setup.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

31 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages