Website Logo

πŸ“‚ social-media-platform-master-prompt.txt

Size: 14.02 KB

πŸ“„ File Preview:

# LIGHTWEIGHT SOCIAL MEDIA PLATFORM β€” MASTER DEVELOPMENT PROMPT

Build a professional, modern, secure, responsive and lightweight **standalone Social Media Platform** from scratch.

**Do NOT use WordPress, BuddyPress, WordPress plugins/themes, OneSignal or any third-party social-media CMS.** Build the complete system with its own backend, database, frontend, authentication, social features, notification system, messaging, moderation and custom Super Admin Panel.

The main priorities are:

**Simple + Fast + Secure + Mobile-first + Responsive + Low Hosting Usage + Complete Admin Control**

---

## 1. TECHNOLOGY

Use a lightweight production-ready stack.

Recommended:

- PHP 8.2+
- MySQL/MariaDB
- HTML5
- CSS3
- Vanilla JavaScript/lightweight JavaScript

The platform must work on normal shared hosting initially and be scalable to VPS/cloud later.

Use clean modular architecture. Do not put the complete application in one PHP file.

---

## 2. USER REGISTRATION & AUTHENTICATION

Implement:

- Registration
- Login/logout
- Email verification
- Forgot/reset password
- Change password
- Edit profile
- Account deletion
- Secure password hashing
- Secure sessions
- CSRF protection
- XSS protection
- SQL injection protection
- Rate limiting
- Brute-force protection

Each user's private data must be completely isolated from other users.

---

## 3. USER PROFILE

Public profile URL:

`platform.com/@username`

Profile includes:

- Profile photo
- Cover photo
- Username
- Display name
- Bio
- Website link
- Followers
- Following
- Posts
- Communities
- Verification badge

Profile actions:

- Follow/Unfollow
- Message
- Block
- Report
- Share profile

---

## 4. VERIFICATION SYSTEM

Create a blue verification system inspired by modern social networks but with an original implementation.

Default rule:

**500 followers = verification eligible**

500 followers should make the user eligible to request verification, not automatically verified.

Flow:

`500 Followers β†’ Eligible β†’ Request β†’ Admin Review β†’ Approve/Reject β†’ Blue Badge`

Admin must be able to change the required follower number from the Admin Panel without editing code.

Example:

`500 β†’ 1,000 β†’ 5,000`

Admin can also manually verify/unverify any user.

Users must clearly see verification information:

> β€œReach 500 followers to become eligible for profile verification.”

Show progress:

`420 / 500 followers`

After reaching the threshold:

> β€œCongratulations! You are eligible to request verification.”

---

## 5. HOME FEED

Create a fast social feed containing:

- Posts from followed users
- User's own posts
- Public recommended posts
- Community posts

Load only 10–20 posts initially.

Use pagination/infinite loading, lazy loading and efficient queries.

Never load thousands of posts at once.

---

## 6. POST SYSTEM

Users can create:

### Text Posts
Normal text and lightweight formatting.

### Image Posts
Multiple images per post.

Automatically:

- Validate MIME type
- Compress images
- Resize large images
- Convert to WebP/AVIF where appropriate
- Generate thumbnails
- Limit file size
- Secure uploads

Do not allow executable files.

Post actions:

- Like
- Reaction
- Comment
- Reply
- Repost
- Share
- Bookmark
- Edit own post
- Delete own post
- Report
- Copy link
- Pin post

---

## 7. VIDEO POLICY

To reduce hosting/storage usage:

**Do not allow direct video uploads initially.**

Allow safe external video links/embeds such as YouTube/Vimeo.

Direct video uploads may be added in the future.

---

## 8. REACTIONS & COMMENTS

Reactions:

- Like
- Love
- Laugh
- Wow
- Sad
- Angry

Comments support:

- Comment
- Reply
- Like/react
- Edit own comment
- Delete own comment
- Report

Use pagination for large comment sections.

---

## 9. FOLLOW & BOOKMARK

Users can:

- Follow
- Unfollow
- View followers
- View following

Bookmarks should store only:

`user_id + post_id`

Do not duplicate post content.

---

## 10. PRIVATE MESSAGING

Any registered user can privately message another user by default.

Chat supports:

- Text
- Emoji
- Optimized image
- Read/unread
- Timestamp
- Delete own message
- Block
- Report

Do not allow large video uploads.

Message privacy settings:

- Everyone
- Followers only
- Nobody

Default:

**Everyone**

Admin must be able to globally enable/disable messaging.

Use pagination for chat history.

---

## 11. NOTIFICATION SYSTEM

Do NOT use OneSignal.

Build notifications using the platform's own database and code.

Notifications:

- New follower
- Follow request
- Like
- Reaction
- Comment
- Reply
- Mention
- Repost
- New private message
- Verification status
- Community activity
- Admin announcements

Header notification bell:

`πŸ”” 5`

Support unread/read and β€œMark all as read”.

### Notification Retention

Default:

**Delete notifications older than 30 days automatically.**

Admin can change retention:

`7 / 15 / 30 / 60 / 90 days`

Do not delete private messages through notification cleanup.

Optional native browser push can use Web Push API + Service Worker without OneSignal.

---

## 12. MENTIONS & HASHTAGS

Support:

`@username`

Mention creates a notification.

Support:

`#technology`

Hashtag pages:

`platform.com/hashtag/technology`

Normalize hashtags to prevent duplicates.

---

## 13. SEARCH & EXPLORE

Search:

- Users
- Posts
- Hashtags
- Communities

Use database indexes and efficient queries.

Explore page:

- Trending hashtags
- Popular public posts
- Suggested users
- Popular communities

Keep recommendation logic lightweight and cache results.

---

## 14. COMMUNITIES

Users can create communities.

Community:

- Name
- Description
- Logo
- Cover
- Rules
- Public/private setting

Features:

- Join
- Leave
- Posts
- Comments
- Members
- Admin
- Moderators
- Reports

Community admins can moderate their communities.

---

## 15. BLOCK, MUTE & REPORT

Users can:

- Block/unblock
- Mute/unmute
- Report

Reports can target:

- User
- Post
- Comment
- Community
- Message where appropriate

Reasons:

- Spam
- Harassment
- Abuse
- Fake account
- Inappropriate content
- Copyright concern
- Other

All reports go to Admin moderation.

---

# 16. CUSTOM SUPER ADMIN PANEL

Create a completely independent Admin Panel:

`platform.com/admin`

No WordPress admin.

Admin Panel must also be fully responsive.

### Dashboard

Show:

- Total users
- New users
- Active users
- Posts
- Comments
- Communities
- Pending reports
- Verification requests
- Storage usage
- Database size
- Media usage

### User Management

Admin can:

- Search/view users
- Activate
- Suspend
- Ban
- Delete
- Verify/unverify
- View reports
- Manage limits

### Content Management

Manage:

- Posts
- Comments
- Communities
- Reports
- Hashtags
- Media

### Admin Roles

Support:

- Super Admin β€” full access
- Moderator β€” moderation
- Support Admin β€” user support

Use granular permissions.

---

## 17. ADMIN GLOBAL SETTINGS

Important platform features must be controlled from Admin Panel without editing source code.

Settings:

- Registration ON/OFF
- Email verification
- Posts
- Comments
- Follow system
- Messaging
- Notifications
- Browser push
- Communities
- Verification
- Affiliate system
- Digital products
- Sponsored posts
- Media uploads
- Storage limits
- User limits
- Anti-spam
- Security
- SEO
- Maintenance mode
- Platform branding

---

## 18. LIGHT & DARK MODE

**Light Mode must be the default.**

Every new user starts in Light Mode.

User can manually switch to Dark Mode.

Remember the user's selected preference.

Apply modes to:

- Home
- Profile
- Feed
- Posts
- Comments
- Messages
- Notifications
- Search
- Communities
- Settings
- Login
- Admin Panel

Dark Mode must never be the default.

---

## 19. RESPONSIVE DESIGN

The entire platform must be mobile-first and responsive.

Support:

- Android
- iPhone
- Tablet
- Laptop
- Desktop
- Large screens

Mobile navigation can use:

`Home | Explore | Create | Notifications | Profile`

Admin Panel must also work properly on mobile.

---

## 20. LOW HOSTING USAGE

This is a critical requirement.

Use:

**One shared application + shared theme/assets + user-specific database records/media.**

Do NOT create separate application installations for each user.

Do not duplicate:

- PHP files
- CSS
- JavaScript
- Themes
- Framework files

for each user.

### Storage Optimization

- Compress images
- Resize images
- WebP/AVIF
- Generate thumbnails
- Limit upload size
- Limit user storage
- Do not store images as MySQL BLOBs
- Store media files separately
- Store only file path/metadata in database
- Do not store unnecessary logs
- Do not duplicate repost content

For reposts store:

`original_post_id + user_id`

For bookmarks store:

`user_id + post_id`

---

## 21. DATABASE PERFORMANCE

Use proper indexes for:

- user_id
- username
- post_id
- created_at
- followers
- comments
- notifications
- hashtags
- reports

Use pagination everywhere.

Never fetch entire tables unnecessarily.

Use prepared statements.

---

## 22. AUTOMATIC CLEANUP

Automatically clean:

- Expired sessions
- Old notifications
- Temporary files
- Failed uploads
- Deleted media
- Old security logs
- Cache files

Admin can configure retention periods.

---

## 23. STORAGE LIMITS

Admin can configure:

- Profile image size
- Post image size
- Storage per user
- Images per post
- Maximum posts
- Maximum communities
- Message media limits

No important limits should be permanently hard-coded.

---

## 24. SECURITY & ANTI-SPAM

Implement:

- Secure password hashing
- CSRF
- XSS prevention
- SQL injection prevention
- Prepared queries
- Rate limiting
- Secure sessions/cookies
- Security headers
- Secure file uploads
- MIME validation
- Permission checks
- Admin authorization
- Login protection

Anti-spam limits for:

- Posts
- Comments
- Follows
- Messages
- Login attempts
- Reports

Add CAPTCHA support for suspicious activity.

---

## 25. SEO

Public content supports:

- SEO title
- Meta description
- Canonical URL
- Open Graph
- Sitemap
- Robots.txt

Private content must not be indexed when privacy settings prohibit it.

---

# 26. USER EARNING SYSTEM

Do NOT implement:

- Paid Subscription
- Referral System
- Ad Revenue Sharing
- Virtual Coins
- Gifts
- Creator Bonus

Users can earn only through:

### Affiliate Marketing
Users can add approved affiliate links to posts.

### Sponsored Posts
Brands/advertisers can work with creators for sponsored content.

### Digital Products
Users can sell eligible digital products such as:

- PDF
- Ebook
- Template
- Design
- Other digital files

These features must be controlled by Admin.

---

## 27. DIGITAL PRODUCTS

If enabled, creators can:

- Add product
- Upload digital file
- Set price
- Add description
- Add cover image
- Publish
- View sales

Use secure download URLs.

Admin controls:

- Enable/disable marketplace
- Maximum file size
- Commission %
- Product limits
- Allowed file types
- Refund settings

---

## 28. PLATFORM MONETIZATION

Platform owner can earn through:

- Google AdSense where policy-compliant
- Direct sponsorship
- Platform affiliate marketing
- Digital product transaction commission

Do NOT implement creator AdSense revenue sharing.

---

## 29. SPONSORED CONTENT

Sponsored posts must be clearly identified.

Structure:

`Advertiser β†’ Creator β†’ Sponsored Post`

Payment can initially be handled outside the platform.

Admin can moderate sponsored content.

---

## 30. AFFILIATE SYSTEM

Admin can:

- Enable/disable affiliate links
- Configure allowed domains
- Review reported links
- Remove inappropriate links

Validate URLs and block malicious links.

---

## 31. PRIVACY

Provide:

- Public/private profile
- Message privacy
- Content privacy
- Account deletion
- Data export architecture
- Privacy policy
- Terms page

Collect only necessary user information.

---

## 32. BACKUP & INSTALLATION

Create installation wizard:

`Database β†’ Admin Account β†’ Platform Settings β†’ Email β†’ Storage β†’ Security β†’ Finish`

After installation disable/lock installer.

Prepare:

- Database backup
- Media backup
- Configuration backup
- Restore architecture

Do not keep unlimited backups on the same hosting account.

---

## 33. CODE QUALITY

Use clean modular architecture with separate modules for:

- Authentication
- Users
- Profiles
- Posts
- Comments
- Reactions
- Followers
- Messaging
- Notifications
- Communities
- Media
- Verification
- Affiliate
- Digital Products
- Sponsored Content
- Moderation
- Admin
- Settings

Never expose database credentials, API keys or secrets.

Normal users must never see server/database errors.

---

# FINAL PRODUCT REQUIREMENTS

The finished platform must be:

- Standalone
- WordPress-free
- BuddyPress-free
- OneSignal-free
- Fully responsive
- Mobile-first
- Light Mode by default
- Dark Mode optional
- Secure
- Lightweight
- Low-storage
- Low-hosting-load
- Scalable
- Easy to use
- Fully controlled by custom Admin Panel

Core user flow:

**Register β†’ Profile β†’ Follow β†’ Post β†’ Like/Comment/Repost β†’ Message β†’ Communities β†’ Reach 500 Followers β†’ Request Verification β†’ Admin Approval β†’ Blue Badge**

User earning:

**Affiliate + Sponsored Posts + Digital Products**

Platform earning:

**AdSense + Sponsorship + Affiliate + Digital Product Commission**

Do not add features that were explicitly excluded above.

Prioritize **speed, simplicity, security, low hosting usage and maintainability** over unnecessary complexity.
⬇️ Download Now