Getting Started
Follow these steps to run Omega Social Media locally: the Laravel backend with its Vue frontend first, then the Expo mobile app.
Installation
Backend and Web Frontend
git clone <repository-url> omega-social-media && cd omega-social-media
composer install
npm install
Make sure you have PHP 8.2+, Composer 2.x, Node.js with npm, MySQL, Redis, and FFmpeg installed. The project is designed to be served by Laravel Herd locally, or any web server pointing at public/.
For a production build of the web assets, run npm run build. It builds the Vite bundles and then compiles the dark-theme stylesheets for the desktop, mobile, auth, business, and admin entries with the Tailwind CLI.
Configuration
After copying .env.example, configure at least the following:
- Database credentials (
DB_DATABASE,DB_USERNAME,DB_PASSWORD). APP_URL,SANCTUM_STATEFUL_DOMAINS, andSESSION_DOMAINso they match the domain you serve the app from.- Redis (
REDIS_HOST,REDIS_PORT,REDIS_PASSWORD) and setQUEUE_CONNECTION=redisto use Horizon. The example file defaults tosync. - Reverb keys (
REVERB_APP_ID,REVERB_APP_KEY,REVERB_APP_SECRET) and the matchingVITE_REVERB_*values for the browser client.BROADCAST_CONNECTIONis marked "Never change this" in.env.exampleand isreverb. - Stripe keys (
STRIPE_PUBLIC_KEY,STRIPE_SECRET_KEY,STRIPE_WEBHOOK_SECRET) and, for creator payouts,STRIPE_CONNECT_ENABLED=true. - Agora credentials (
AGORA_APP_ID,AGORA_APP_CERTIFICATE) for live streaming. - FFmpeg paths (
FFMPEG_PATH,FFPROBE_PATH) if the binaries are not discoverable. - Mail settings for transactional email, and AWS S3 credentials if you store media on S3.
- For production,
APP_ENV=production,APP_DEBUG=false, and optionally Sentry DSNs.
Environment Variables
Names and meanings are taken from .env.example. Never commit real values.
Application
- Name
APP_NAME- Type
- string
- Description
Application display name.
- Name
APP_ENV- Type
- string
- Description
Environment (local, production). Default:
local
- Name
APP_KEY- Type
- string
- Description
Encryption key, generated via
php artisan key:generate.
- Name
APP_SALT- Type
- string
- Description
Application salt value. Left empty in the example file.
- Name
APP_DEBUG- Type
- boolean
- Description
Debug mode. Disable in production. Default:
true
- Name
APP_URL- Type
- string
- Description
Base URL of the application.
- Name
APP_TIMEZONE- Type
- string
- Description
Application timezone.
- Name
APP_LOCALE- Type
- string
- Description
Default locale. Default:
ro.APP_FALLBACK_LOCALEandAPP_FAKER_LOCALEfollow the same pattern.
- Name
APP_DEFAULT_CURRENCY- Type
- string
- Description
Default currency. Default:
RON
- Name
APP_API_PREFIX- Type
- string
- Description
URL prefix for API routes. Default:
api
- Name
APP_API_KEY- Type
- string
- Description
API key used by the
api.keymiddleware.
- Name
SANCTUM_STATEFUL_DOMAINS- Type
- string
- Description
Domains treated as stateful by Sanctum.
- Name
ADMIN_EMAIL- Type
- string
- Description
Administrator email address.
- Name
APP_ADMIN_PREFIX- Type
- string
- Description
URL prefix of the admin panel. Default:
admin
- Name
PWA_ENABLED- Type
- boolean
- Description
Enable PWA features. Default:
false
Database, Cache, Queue & Session
- Name
DB_CONNECTION- Type
- string
- Description
Database driver. Default:
mysql
- Name
DB_HOST / DB_PORT- Type
- string
- Description
Database host and port. Defaults:
localhost,3306
- Name
DB_DATABASE / DB_USERNAME / DB_PASSWORD- Type
- string
- Description
Database name and credentials.
- Name
QUEUE_CONNECTION- Type
- string
- Description
Queue driver. Example default:
sync. Userediswith Horizon.
- Name
CACHE_STORE- Type
- string
- Description
Cache driver. Default:
file
- Name
SESSION_DRIVER- Type
- string
- Description
Session driver. Default:
file
- Name
SESSION_DOMAIN- Type
- string
- Description
Cookie domain for sessions.
- Name
REDIS_CLIENT / REDIS_HOST / REDIS_PORT / REDIS_PASSWORD- Type
- string
- Description
Redis connection. Client default:
phpredis.
- Name
FILESYSTEM_DISK- Type
- string
- Description
Default filesystem disk. Default:
local
Real-time (Reverb)
- Name
BROADCAST_CONNECTION- Type
- string
- Description
Broadcast driver. Must stay
reverb.
- Name
REVERB_APP_ID / REVERB_APP_KEY / REVERB_APP_SECRET- Type
- string
- Description
Reverb application credentials.
- Name
REVERB_SERVER_HOST / REVERB_SERVER_PORT- Type
- string
- Description
Address the Reverb server binds to. Defaults:
0.0.0.0,13000
- Name
REVERB_HOST / REVERB_PORT / REVERB_SCHEME- Type
- string
- Description
Address the backend uses to reach Reverb. Port default:
13000
- Name
VITE_REVERB_APP_KEY / VITE_REVERB_HOST / VITE_REVERB_PORT / VITE_REVERB_SCHEME- Type
- string
- Description
Reverb connection settings exposed to the browser client.
- Name
VITE_REVERB_CONNECTION_STATUS- Type
- string
- Description
Toggles the connection status indicator in the web client. Default:
off
Payments
- Name
STRIPE_ENABLED- Type
- boolean
- Description
Enable the Stripe payment provider. Default:
true
- Name
STRIPE_PUBLIC_KEY / STRIPE_SECRET_KEY- Type
- string
- Description
Stripe API keys.
- Name
STRIPE_WEBHOOK_SECRET- Type
- string
- Description
Stripe webhook signing secret.
- Name
STRIPE_WEBHOOK_TOLERANCE- Type
- string
- Description
Webhook timestamp tolerance in seconds. Default:
300
- Name
CASHIER_CURRENCY / CASHIER_CURRENCY_LOCALE- Type
- string
- Description
Cashier currency and locale. Defaults:
ron,ro
- Name
STRIPE_CONNECT_ENABLED- Type
- boolean
- Description
Enable Stripe Connect creator payouts. Default:
false
- Name
STRIPE_CONNECT_COUNTRY- Type
- string
- Description
Country used for Connect accounts. Default:
RO
- Name
PLATFORM_COMMISSION_RATE- Type
- number
- Description
Platform commission percentage. Default:
20
- Name
PAYPAL_ENABLED / PAYPAL_CLIENT_ID / PAYPAL_SECRET_KEY / PAYPAL_MODE- Type
- string
- Description
PayPal settings. Disabled by default; mode default
sandbox.
Live Streaming
- Name
AGORA_APP_ID- Type
- string
- Description
Agora application ID.
- Name
AGORA_APP_CERTIFICATE- Type
- string
- Description
Agora app certificate used to sign RTC tokens.
- Name
AGORA_TOKEN_EXPIRY- Type
- number
- Description
RTC token lifetime in seconds. Default:
3600
Media, Storage & Integrations
- Name
FFMPEG_PATH / FFPROBE_PATH- Type
- string
- Description
Paths to the FFmpeg and FFprobe binaries.
- Name
FFMPEG_TIMEOUT / FFMPEG_THREADS / FFMPEG_TEMP_DIR- Type
- string
- Description
FFmpeg process timeout (default
3600), thread count (default12), and temp directory.
- Name
AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_DEFAULT_REGION / AWS_BUCKET- Type
- string
- Description
S3 storage credentials. Region default:
eu-north-1.
- Name
GIPHY_API_KEY / VITE_GIPHY_API_KEY- Type
- string
- Description
Giphy API keys for GIF search on the server and in the browser.
- Name
SMS_DRIVER- Type
- string
- Description
SMS driver. Default:
log
- Name
IPINFO_TOKEN / IP_GEOLOCATION_DRIVER- Type
- string
- Description
IP geolocation provider token and driver. Driver default:
ipinfo.
- Name
TRANSLATION_SERVICE_API_URL / TRANSLATION_SERVICE_API_KEY- Type
- string
- Description
External translation service endpoint and key.
- Name
MAIL_MAILER / MAIL_HOST / MAIL_PORT / MAIL_USERNAME / MAIL_PASSWORD / MAIL_FROM_ADDRESS- Type
- string
- Description
Mail settings. The example targets a local Mailpit/Mailhog on
127.0.0.1:1025.
Social Login
- Name
GOOGLE_LOGIN_ENABLED / GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET- Type
- string
- Description
Google login. Disabled by default.
- Name
APPLE_LOGIN_ENABLED / APPLE_CLIENT_ID / APPLE_CLIENT_SECRET- Type
- string
- Description
Apple login. Disabled by default.
- Name
FACEBOOK_LOGIN_ENABLED / TWITTER_LOGIN_ENABLED / TELEGRAM_LOGIN_ENABLED- Type
- boolean
- Description
Facebook, Twitter, and Telegram login flags, each with matching
*_CLIENT_IDand*_CLIENT_SECRETvariables.
Mobile Deep Linking & Notifications
- Name
MOBILE_REDIRECT_ENABLED- Type
- boolean
- Description
Prompt mobile visitors to open the native app or go to the store. Default:
false
- Name
MOBILE_APP_SCHEME- Type
- string
- Description
App URL scheme. Config fallback:
omega-social
- Name
MOBILE_IOS_BUNDLE_ID / MOBILE_APP_STORE_URL / MOBILE_APP_STORE_ID- Type
- string
- Description
iOS identifiers and store links.
- Name
MOBILE_ANDROID_PACKAGE / MOBILE_PLAY_STORE_URL / MOBILE_ANDROID_SHA256_FINGERPRINT- Type
- string
- Description
Android identifiers and store links.
- Name
NOTIFICATIONS_EMAIL_ENABLED / NOTIFICATIONS_BROADCAST_ENABLED / NOTIFICATIONS_PUSH_ENABLED- Type
- boolean
- Description
Toggle user notification channels. Defaults:
false,true,false.
Monitoring, Ads & Demo
- Name
SENTRY_LARAVEL_DSN / VITE_SENTRY_DSN_PUBLIC- Type
- string
- Description
Sentry DSNs for the backend and the browser. Optional.
- Name
ADS_DEFAULT_APPROVAL- Type
- boolean
- Description
Whether new ad campaigns are approved by default. Default:
false
- Name
DEMO_MODE / DEMO_ALLOW_RESET / DEMO_PRODUCT_URL- Type
- string
- Description
Demo mode flags.
DEMO_MODEdefaults tofalse.
- Name
DEPLOY_USER / DEPLOY_HOST / DEPLOY_REPOSITORY / DEPLOY_APP_DIR / DEPLOY_RELEASE_DIR / DEPLOY_BRANCH- Type
- string
- Description
Used by the Envoy deployment script. See the Development page.
Mobile App Setup
The mobile app lives in the mobile/ directory and has its own package.json. It is an Expo SDK 54 app (React Native 0.81, Expo Router) that consumes the backend's /api/mobile endpoints.
cd mobile
npm install
EXPO_PUBLIC_API_URL is the base URL of the mobile API. If it is not set, the app falls back to http://localhost:8000/api/mobile. A physical device cannot reach localhost on your computer, so use your machine's LAN address there. The same variable is used by the HTTP client and by the WebSocket authentication endpoint (/broadcasting/auth).
Expo Go vs Development Client
- Expo Go — Works for most screens. Live streaming (
react-native-agora) and native Stripe payments (@stripe/stripe-react-native) are not available there: the app detects the Expo Go environment and disables Agora, and the Stripe provider and hook skip the native module. - Development client —
expo-dev-clientis a dependency, and thedevelopmentprofile ineas.jsonsetsdevelopmentClient: truewith internal distribution and an iOS simulator build. Use it to test live streaming and payments.
eas build --profile development --platform ios
EAS Profiles
- Name
development- Type
- build profile
- Description
Development client, internal distribution, iOS simulator.
- Name
preview- Type
- build profile
- Description
Internal distribution.
- Name
production- Type
- build profile
- Description
Auto-incremented build numbers, with
EXPO_PUBLIC_API_URLset in the profile'senvto the production mobile API URL.
The repository also contains mobile/DEPLOY_GUIDE.md, a step-by-step App Store and Google Play submission guide.
Basic Usage Flow
- Register or sign in on the web app, or through social login if a provider is enabled.
- Complete onboarding and set up your profile (avatar, cover, personal info).
- Post text, images, videos, or reels, and add stories.
- Follow people and browse the discover, following, and nearby feeds.
- Chat in real time with other users.
- Go live from the mobile app and receive donations from viewers.
- Buy credits, send donations, and convert earned credits to cash.
- Connect Stripe to receive creator payouts, then request a withdrawal.
- Publish marketplace products and job listings, or run an ad campaign from the business area.
- Moderate reports, users, and content from the admin panel.
Examples
Creating an Admin User
php artisan admin:add
The admin panel is served under the prefix set in APP_ADMIN_PREFIX (default admin) and requires the admin role.
Authenticating from the Mobile API
All mobile responses use the shape {"status": true/false, "message": "...", "data": ...}. Authentication endpoints are public; everything else requires a Sanctum bearer token.
curl -X POST http://localhost:8000/api/mobile/auth/login \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"identity": "user@example.com", "password": "secret"}'
Demo Mode
Set DEMO_MODE=true and run php artisan demo:seed to create demo admin, user, and moderator accounts. php artisan demo:reset resets the demo data; both commands only run when demo mode is enabled, and DEMO_ALLOW_RESET controls whether resetting is allowed.