Users on the Brand step can type their website URL and click 'Preencher' (Portuguese) / 'Autofill' (English). The backend fetches their homepage, parses standard meta tags, and returns: - name ← og:site_name | title (suffix stripped at ' | ', ' - ') - description ← meta[name=description] | og:description - language ← <html lang> mapped to en / pt-BR / es - logo ← apple-touch-icon | largest link[rel*=icon] | og:image The logo is downloaded, validated (mime whitelist, 2MB max), and attached to the workspace's 'logo' media collection so the avatar updates immediately. Zero LLM calls, zero external APIs. Uses symfony/dom-crawler + symfony/css-selector (newly required) for meta extraction. Everything else (Http client, workspace media, Intervention) was already in the project. Security: - SSRF guardrail: resolves the host, rejects private / loopback / link-local ranges, enforces http(s) scheme on both the initial page fetch and the logo download. - Rate limited at 10 req/min per user via the throttle middleware alias on the route. - Logo content-type must be one of the allowed image mimes; wrong types are silently dropped so users never see broken images. UX: - 'Autofill' button next to the website input, disabled until there is a URL; shows a spinner while running. - If a logo was captured, a small preview appears below the input so users can see what was pulled before saving. - Success and error paths both surface as vue-sonner toasts, with translations in en / pt-BR / es. - Failures leave the form untouched — nothing is destructively overwritten if parsing gave us nothing. Tests (16 new): action-level coverage for happy path, title-suffix fallback, language code normalization across 6 locales, scheme rejection, private-range SSRF rejection, implicit https prefixing, empty sites, upstream errors, and wrong-mime logo rejection. Plus two controller-level tests for the autofill endpoint. |
||
|---|---|---|
| .claude/skills | ||
| .github | ||
| app | ||
| bootstrap | ||
| config | ||
| database | ||
| docs/superpowers | ||
| lang | ||
| maizzle | ||
| public | ||
| resources | ||
| routes | ||
| storage | ||
| stubs | ||
| tests | ||
| .editorconfig | ||
| .env.ci | ||
| .env.example | ||
| .env.testing | ||
| .gitattributes | ||
| .gitignore | ||
| .mcp.json | ||
| .prettierignore | ||
| .prettierrc | ||
| artisan | ||
| boost.json | ||
| CLAUDE.md | ||
| components.json | ||
| compose.yaml | ||
| composer.json | ||
| composer.lock | ||
| eslint.config.js | ||
| GEMINI.md | ||
| LICENSE.md | ||
| package-lock.json | ||
| package.json | ||
| phpunit.xml | ||
| pint.json | ||
| README.md | ||
| tsconfig.json | ||
| vite.config.ts | ||
The open-source social media scheduling platform
Schedule, manage, and publish content to all your social media accounts from one place.
Self-hosted. Privacy-focused. No limits.
Documentation • Roadmap • Community
Why TryPost?
Tired of paying expensive monthly fees for social media scheduling tools? Want full control over your data? TryPost is the solution.
| 100% Open Source | Inspect the code, contribute, make it yours |
| Self-Hosted | Your data stays on your servers |
| No Limits | Schedule unlimited posts, connect unlimited accounts |
| Privacy First | No tracking, no analytics, no data selling |
Features
| Visual Calendar | Drag and drop posts across your content calendar |
| Post Composer | Create and preview posts for multiple platforms at once |
| Media Library | Upload images and videos with automatic optimization |
| Team Collaboration | Invite team members with role-based permissions (Owner, Admin, Member) |
| Workspaces | Manage multiple brands or clients separately |
| REST API | Full API with Bearer token authentication |
| MCP Server | AI-ready with Model Context Protocol support |
| Google Login | Sign up and log in with Google OAuth |
| Notifications | In-app and email notifications for post status |
| i18n | Available in English, Spanish, and Portuguese |
Supported Platforms
X (Twitter) |
TikTok |
|||
YouTube |
Threads |
Bluesky |
Mastodon |
Tech Stack
| Layer | Technology |
|---|---|
| Backend | Laravel 13, PHP 8.4 |
| Frontend | Vue 3, Inertia.js v3, Tailwind CSS v4 |
| Database | PostgreSQL |
| Queue | Redis + Laravel Horizon |
| WebSockets | Laravel Reverb |
| API | REST with Bearer token auth |
| MCP | Laravel MCP for AI integrations |
| Payments | Laravel Cashier (Stripe) |
Getting Started
Get TryPost running in minutes:
| Installation Guide | Step-by-step setup |
| Docker Setup | Run with Laravel Sail |
| Configuration | Environment setup |
| Platform Setup | Connect your social accounts |
Quick Start
git clone https://github.com/trypost-it/trypost.git
cd trypost
cp .env.example .env
composer install
npm install
php artisan key:generate
php artisan migrate
npm run build
API
TryPost includes a REST API for programmatic access. All endpoints are under /api and require a Bearer token.
curl -H "Authorization: Bearer tp_your_token" \
https://your-domain.com/api/posts
See the API documentation for all available endpoints.
MCP Server
TryPost ships with a Model Context Protocol (MCP) server at /mcp/trypost, enabling AI assistants to manage your social media directly.
Contributing
We love contributions! Check the issues for open tasks.
- Discussions - Ask questions, share ideas
- Issues - Report bugs, request features
License
TryPost is licensed under the Functional Source License (FSL).
You can: Use for personal or business use, self-host, modify and contribute.
You cannot: Offer as a competing SaaS, white-label and resell.
If TryPost helps you, please give us a star