The open-source community foundation for Laravel.
Launch a private, branded community without rebuilding profiles, feeds,
spaces, messaging, moderation, and privacy from scratch.
Live beta · Product tour · Features · Quick start · Architecture · Contributing
Lineweb Social is not a generic feed demo and it is not trying to hide important platform decisions behind plugins. The core owns identity, visibility, conversations, moderation, and member safety so teams can build distinctive products without rebuilding the difficult boundaries first.
| Community-owned | Calm by default | Built to extend |
|---|---|---|
| Self-hosted source, data, rules, and branding stay under the operator's control. | Chronological feeds, explicit relationships, and low-noise notifications avoid engagement tricks. | Stable domain events, a contract-first API, and an allowlisted extension model create room for focused products. |
- Branded customer or product communities.
- Creator, professional, alumni, or membership networks.
- Local and interest-based social platforms.
- Private organizational communities.
- A focused social startup with its own media, commerce, events, learning, or professional layer.
The goal is a strong shared core—not a clone with someone else's product decisions baked in.
| Evaluate | Build locally | Run a pilot |
|---|---|---|
| Explore the live beta and product tour. | Start the complete Docker stack with one command. | Propose a controlled pilot with a real community. |
The public beta is for evaluation and controlled pilots. It is not yet a
stable 1.0, and the live installation must not be used for sensitive or
business-critical member data.
Every preview below uses synthetic local demo content. No private member data, credentials, database, uploads, or generated build output are part of the public repository.
The public landing experience shows the product instead of hiding it behind a generic marketing page. Login and registration continue the same visual system with clear hierarchy, responsive forms, passkey support, and familiar community context.
|
|
| Passkey-ready login with a focused return path | Clear registration and email-verification expectations |
Newly verified members receive an optional four-step route into the community: make the profile recognizable, join a Space, follow one person, and publish a first post. Every step reflects real account state, existing invite links keep priority, and members can open the feed or hide the guide at any time.
Suggestions reuse the same Space visibility, profile discovery, and mutual block policies as the rest of the platform. Lineweb Social does not create a behavioral profile, track guide views, or perform social actions automatically.
|
|
| Four real outcomes with privacy-safe discovery | App-like mobile guidance without a forced tour |
A responsive, chronological experience with clear publishing, conversation, relationship, and navigation paths. Direct replies add human context without recursive thread depth or changing the timeline's deterministic order.
The full social experience follows one visual system in light, dark, or the member's device preference. Contrast, hierarchy, and touch targets stay clear instead of treating dark mode as a simple color inversion.
Start with a community-wide overview, then focus on Posts, Spaces, People or Topics. Shareable search URLs, previous/next pages and a swipeable mobile category rail help members reach older matches. Every page reapplies current visibility and safety rules, with no separate search service to configure.
|
|
| The same search experience in dark mode | Focused discovery on mobile |
See the community search contract for ordering, privacy and pagination boundaries.
Members can share a short thought, one private normalized image, or both inside a Space. Every Story expires after 24 hours, keeps the Space and mutual block boundaries on every view, and stores no viewer identity. Authors can delete their own Story early, Space moderators can remove unsafe content with a minimal audit trail, and the scheduler permanently removes expired records and media.
|
|
|
| Space-aware viewer and clear retention boundary | Edge-to-edge mobile discovery rail | Immersive mobile Story with no horizontal overflow |
Members can reply directly to a top-level comment while the conversation stays chronological and easy to scan. A focused reply composer, clear parent identity, recipient-aware notifications, and a strict one-level boundary provide useful context without recursive thread depth.
|
|
|
| Chronological context on desktop | Readable one-level replies on mobile | Focused mobile reply composer |
Members can add a perspective to a post or send a clean repost without creating a second, detached copy. Shares remain in the original Space, preserve its visibility rules, and quietly drop source context if the original later becomes unavailable. A quote still belongs to its author; an empty repost does not survive without its source.
|
|
| Optional context with the original post kept visible | Focused, touch-friendly mobile share flow |
Members can publish a focused poll with two to four answers and an optional closing window. Each member has one changeable vote, while timelines and APIs receive aggregate results only. Drafts stay private, published choices stay immutable, and the server enforces Space membership before accepting a vote.
|
|
| Clear aggregate results on desktop | Touch-friendly voting on mobile |
A focused composer supports accessible four-image galleries and keeps unfinished text and media private until the author chooses to publish. Members can return through a dedicated draft library, curate retained images without reuploading them, move a draft to another Space they can post in, and publish without changing its post identity.
|
|
|
| Focused writing and explicit publication | App-first mobile composer | Private unfinished work |
Published galleries stay private behind the same post policy as their Space, preserve an accessible description for every image, and use touch-friendly swipe navigation with visible position and keyboard-sized controls.
|
|
| Policy-protected gallery on desktop | Touch-first gallery on mobile |
Public, private, and hidden Spaces combine publishing context with explicit membership, account-specific and shareable invitations, role, ownership, moderation, and a bounded highlights layer that never reorders the chronological timeline.
|
|
|
| Searchable community directory | Bounded curation without timeline ranking | App-first swipe rail |
Owners and moderators can onboard a cohort with an expiring, limited-use link without exposing elevated roles. The full link is shown only once, its token is stored as a hash, and every successful membership or revocation becomes part of the Space audit history. Guests can preview safe Space details and return to the invitation after registration and email verification.
|
|
| Bounded links, one-time token display, and accountable controls | Focused guest onboarding on mobile |
Space owners and moderators can publish official in-person, online, or hybrid events with timezone-safe scheduling and bounded capacity. Members can answer Going or Interested without joining a public attendee directory: every shared surface exposes aggregate attendance plus only the current member's own RSVP. Cancellation remains visible and audited instead of silently deleting history.
|
|
| Official events and a focused creator studio | Private, touch-friendly RSVP controls |
People, posts, Spaces, relationships, and topics remain discoverable only when the current member is allowed to see them.
|
|
| People you chose, in chronological order | Private relationship state on mobile |
Members can feature up to three of their own conversations without changing the chronological feed. Every Profile Highlight is rechecked against the current viewer's Space, moderation, mute, and block boundaries, while the mobile presentation stays swipe-first and app-like.
|
|
| A deliberate creator-led introduction | Swipe-first highlights on mobile |
Operators can inspect every local extension manifest, its declared access, compatibility, activation state, pending schema, checksum integrity, and retained-data ownership plus immutable browser releases before deployment. A broken package is reported independently, while provider activation, backup-gated migrations, and asset publication stay in trusted deploy operations rather than the browser.
|
|
| Schema, immutable browser releases, and retained ownership at a glance | Content-addressed CSS and ES modules with SRI |
|
|
| Chronological, access-aware topic trails | Mobile hashtag discovery |
Members can keep delivery entirely in-app or opt into one daily email when unread updates are waiting. The queued digest exposes only category counts, rechecks access before delivery, and keeps private content and identities out of email.
|
|
| Separate in-app categories and opt-in email delivery | Clear privacy boundary in an app-first layout |
Direct Messages are participant-only, block-aware, and honest about server access. A member can report the exact incoming message without exposing the surrounding conversation to administrators.
|
|
| Focused two-person inbox and thread | App-first mobile messaging |
|
|
| Exact-message evidence and documented operator decisions | Clear reporting scope before submission |
Space moderation and platform administration are separate permission boundaries. Community teams manage their Spaces; trusted platform operators work from a dedicated responsive control center with separate Overview, Members, Appeals, Safety, and append-only Audit surfaces. Account restrictions remain reason-required, account appeals are human-reviewed, and private safety reviews expose only the evidence a member explicitly submitted.
Restricted members keep one clear Account Status surface, their data rights, and one bounded appeal for each distinct restriction. Operators review it in a dedicated queue; approval explicitly restores access and no automated system makes the final decision.
|
|
| Member context, internal record, and explicit operator action | Clear status, human review, and preserved data rights |
|
|
|
| Accountable moderation | Complete member profiles | Low-noise notifications |
| Area | Included today |
|---|---|
| Accounts | Verified registration, stable handles, passkeys, two-factor authentication, strong password defaults, active-account enforcement, and one human-reviewed appeal per restriction. |
| Onboarding | Optional outcome-based first-session guide, invitation-aware entry, privacy-safe Space and People suggestions, real progress, and a dismissal preference without behavioral tracking or automatic actions. |
| Profiles | Editable member identity, headlines, author-curated three-post highlights, real chronological activity, public/shared/private visibility, and discovery opt-out. |
| Spaces | Public/private/hidden communities, searchable directory, join/leave rules, account-specific and limited-use shareable invitations, roles, ownership transfer, member removal, bounded curated highlights, and official events with private RSVPs. |
| Publishing | Focused composer, author-only drafts, private four-image WebP galleries with per-image alt text and swipe navigation, bounded private-first polls, 24-hour Space Stories with no viewer tracking, chronological posts, privacy-safe quote posts and reposts, comments, permanent conversations, and author controls. |
| Discovery | Policy-filtered search across posts, Spaces, People and Topics, focused category filters, navigable result pages, Unicode hashtags, chronological topic trails and privacy-aware Following. |
| Interactions | Typed Like, Celebrate, and Insightful reactions, private Saved Posts, follows, mentions, one-level direct replies, same-Space quote/repost actions, comments, copy links, and conversation shortcuts. |
| Messaging | Canonical one-to-one conversations, participant-only history, unread state, block-aware delivery, and responsive inbox/thread views. |
| Trust and safety | Mute, mutual block, Safety recovery, post/comment reporting, Space moderation queues, Direct Message reporting, and audited decisions. |
| Notifications | Database-backed replies, mentions, and moderation alerts with per-category preferences, category-filtered inbox views, destination access revalidation, and opt-in privacy-safe daily email digests. |
| Platform operations | Dedicated responsive control center, console-granted administrators, focused member, appeals, and private-safety queues, transactional suspension/reinstatement, session and API-token revocation, and searchable append-only audit history. |
| Data rights | Password-confirmed personal JSON export and self-service deletion with active-community ownership safeguards. |
| Developer surface | Contract-first bearer API, scoped expiring Sanctum tokens, domain events, OpenAPI draft, allowlisted extension providers, checksum-owned migrations, and immutable SRI-backed CSS/ES-module releases. |
The core does not rank a member's home or Following feed. Products can add a different discovery layer later without making the shared social graph depend on opaque engagement scoring.
Visibility, mute, block, moderation, account access, report evidence, and audit history are server-side contracts—not frontend decoration.
Direct Messages and private media are access-controlled by the application. Messages are not end-to-end encrypted, and server operators retain normal database access.
The current extension foundation accepts configured local manifests with known
permissions and UI slots. Administrators can review each manifest,
compatibility, and active state; deployers explicitly allowlist reviewed
providers and enforce the same contract with php artisan platform:extensions. Reviewed schema changes run only from explicit,
backup-gated CLI commands while providers are disabled; applied source is
checksum locked and removed source retains its data. Pre-built browser assets
use explicit content-addressed publication and SRI; their same-origin JavaScript
is reviewed trusted code, not a sandbox. Remote downloads, arbitrary ZIP
installation, browser actions, and destructive uninstall are intentionally
unavailable.
Important
0.2.0-beta.1 is the first production-shaped public beta. It is suitable for
evaluation and controlled community pilots, but it is not a stable 1.0
release and operators should review the documented boundaries below.
The following are deliberately still outside the supported core:
- Message attachments, group conversations, realtime presence, and delivery receipts.
- Video, audio, story formats, and direct-to-object-storage uploads.
- Recurring events, ticket sales, public attendee directories, reminders, and external calendar or conferencing synchronization.
- Web/mobile push delivery, instant email, and custom digest schedules.
- Advanced indexed search, a stable JavaScript UI-slot SDK, and destructive extension uninstall lifecycles.
- Complete audit archival/export and deployment-specific retention tooling.
- A production support, upgrade, and compatibility policy.
This boundary is intentional: the public source should be honest about what is implemented, tested, and supported.
| Layer | Stack |
|---|---|
| Backend | PHP 8.3+, Laravel 13, Fortify, Sanctum |
| Frontend | React 19, Inertia 3, TypeScript, Tailwind CSS 4 |
| Interface primitives | Radix UI, Lucide icons |
| Default local database | SQLite |
| Quality | PHPUnit, PHPStan/Larastan, Pint, ESLint, Prettier, TypeScript |
| License | GPL-3.0-or-later |
Requirements: Docker with Compose v2, OpenSSL, and curl.
git clone https://github.com/drewmt/lineweb-social.git
cd lineweb-social
./bin/docker-setupOpen http://127.0.0.1:8080. The command builds the application, starts
MariaDB, runs migrations, starts the queue worker and scheduler, and waits for
the health endpoint. Generated secrets stay in the ignored .env.docker file;
database and private media persist in named volumes. Read the
Docker evaluation guide for lifecycle and reset commands.
Requirements:
- PHP 8.3+ with GD/WebP, EXIF, Fileinfo, and SQLite support.
- Composer 2.
- Node.js 22 and npm.
git clone https://github.com/drewmt/lineweb-social.git
cd lineweb-social
composer run setup
composer run devcomposer run setup installs dependencies, creates the local environment,
generates the application key, runs migrations, and builds the frontend. The
default example mailer writes messages to the local log; configure a real
transactional provider before inviting members in a deployment. Daily email
delivery is off by default; enabling it also requires Laravel's scheduler and a
worker that processes the notifications queue (for example,
php artisan queue:work --queue=notifications,default). Read the
notification delivery contract before turning it on.
After an owner has registered and verified their email, a trusted operator can prepare an idempotent private starter Space without creating a shared demo account or password:
php artisan platform:starter-community owner@example.com --confirmThe starter includes welcome, introductions, and roadmap prompts plus one
highlighted post. Read the starter community contract
for customization and safety boundaries.
composer run ci:check
npm run build
composer validate --strict
composer audit
npm audit --omit=devThe implementation is intentionally documented around boundaries rather than only code structure.
| Contract | Documentation |
|---|---|
| Platform boundaries and extension direction | docs/platform-architecture.md |
| Reproducible local Docker evaluation | docs/docker.md |
| Idempotent first-community bootstrap | docs/starter-community.md |
| Extension manifests and compatibility inspection | docs/extensions.md |
| Extension migration ownership and rollback | docs/extension-migrations.md |
| Extension browser assets and integrity | docs/extension-assets.md |
| Authenticated API and machine-readable draft | docs/api-v1.md · docs/openapi.json |
| Direct Messages | docs/direct-messages.md |
| Chronological comments and direct replies | docs/conversations.md |
| Private message reporting and evidence retention | docs/message-reporting.md |
| Post/comment moderation and domain events | docs/moderation.md |
| Notification privacy and delivery categories | docs/notifications.md |
| Private post drafts and publication boundary | docs/post-drafts.md |
| Post polls and aggregate-result boundary | docs/post-polls.md |
| Post media validation and lifecycle | docs/media.md |
| Unicode topics and visibility | docs/topics.md |
| Official Space events and private RSVP boundary | docs/space-events.md |
| Shareable Space invite links and onboarding | docs/space-invite-links.md |
| Platform administration | docs/platform-administration.md |
| Account status and human-reviewed appeals | docs/account-appeals.md |
| Personal export and account deletion | docs/privacy-and-data-rights.md |
| Example extension manifest | extensions/example-polls/extension.json |
Contributions are welcome when they strengthen the shared core without weakening privacy, moderation, or authorization boundaries.
- Read
CONTRIBUTING.md. - Check existing issues and pull requests before starting.
- Open an issue before a large architectural change.
- Keep changes focused, tested, documented, and compatible with the public contracts.
Please also follow the Code of Conduct and report
security concerns through SECURITY.md, not a public issue.
Lineweb Social is free and open-source software licensed under
GPL-3.0-or-later.
Created by Andrew Matia and Lineweb.
Copyright © 2026 Andrew Matia and Lineweb.





















































