
Image 1 of 1
Project Description & Specifications
Full architecture overview and implementation details
Dark Orbit – Multi-Vendor Marketplace & Telegram E-Commerce Platform
Dark Orbit is an e-commerce marketplace platform built on Laravel 8 featuring multi-vendor capabilities, multi-currency cryptocurrency payment gateways (Monero XMR, Bitcoin BTC, Litecoin LTC), PGP-based two-factor authentication (2FA), an integrated Telegram Bot store interface, escrow & dispute management, and built-in Tor onion service support.
Table of Contents
- Key Features
- Architecture Overview
- Technology Stack
- Prerequisites
- Local Development Setup
- Production Deployment Guide (botdigit.com)
- 1. Server Requirements & Dependencies
- 2. Code Deployment & Permissions
- 3. Environment Configuration (.env)
- 4. Database Setup & Migrations
- 5. Nginx Web Server & SSL Configuration
- 6. Systemd Services (Telegram Bot & Queue Worker)
- 7. Cryptocurrency Daemons (Monero / Bitcoin RPC)
- 8. Tor Hidden Service (.onion Vanity Address)
- User Roles & Permissions
- Directory Structure
- Maintenance & Useful Artisan Commands
Key Features
- Multi-Vendor Marketplace: Buyers, Sellers, Staff (Moderators), and Super Administrators.
- Cryptocurrency Payment Integration:
- Monero (XMR): Subaddress generation, daemon RPC communication, automated balance and transaction verification.
- Bitcoin (BTC): RPC daemon connection, multisig / direct escrow transaction processing.
- Litecoin (LTC): Client RPC support via Payment Gateway module.
- Escrow & Order Lifecycle:
- State machine:
Pending->Paid->Dispatched->Completed/Disputed/Cancelled/Finalized Early (FE). - Automated escrow holding until buyer release or dispute resolution by staff.
- State machine:
- Security & Privacy:
- PGP 2FA: Encrypted challenge-response during login.
- Security PIN & Secret Words: Secondary authentication for sensitive financial transfers and withdrawals.
- Auto-Logout & Session Invalidation: Session expiration and data sanitization.
- Captcha Integration: Anti-bot challenge on registration and authentication endpoints.
- Telegram Bot Storefront & Notifications:
- Native Telegram bot interface supporting
/shop,/cart,/orders,/profile,/support. - Real-time order status, payment received, and dispute notifications via Telegram.
- Native Telegram bot interface supporting
- Support & Dispute Arbitration:
- Ticket support system with direct buyer-seller-moderator resolution channels.
- Mass-messaging system for administrators to broadcast system notices.
- Tor Onion Support:
- Comes with
mkp224ovanity onion address generator for hosting as a Tor v3 Hidden Service.
- Comes with
Architecture Overview
graph TD
ClientWeb[Web Browser (botdigit.com)] -->|HTTPS / 443| Nginx[Nginx Reverse Proxy]
ClientTor[Tor Browser (.onion)] -->|SOCKS / Tor| TorDaemon[Tor Hidden Service]
TorDaemon --> Nginx
ClientTelegram[Telegram App] -->|Webhook / Polling| TGController[Telegram Bot Controller]
Nginx -->|FastCGI / PHP-FPM| LaravelApp[Laravel 8 Core Application]
LaravelApp --> DB[(MySQL / MariaDB)]
LaravelApp --> RedisCache[(Cache / Session Storage)]
LaravelApp --> MoneroRPC[Monero Wallet RPC (monero-wallet-rpc)]
LaravelApp --> BitcoinRPC[Bitcoin Core Daemon (bitcoind)]
Technology Stack
- Framework: Laravel 8.x
- Language: PHP 8.0 - 8.3 (tested and compatible with PHP 8.x)
- Database: MySQL 8.0 / MariaDB 10.5+ (SQLite supported for local testing)
- Web Server: Nginx + PHP-FPM
- Crypto Libraries:
monero-integrations/monerophp,singpolyma/openpgp-php - Bot SDK:
irazasyed/telegram-bot-sdk - Modular Engine:
nwidart/laravel-modules
Prerequisites
Ensure the target system has:
- PHP >= 8.0 with extensions:
php-fpm,php-mysql,php-bcmath,php-mbstring,php-xml,php-curl,php-zip,php-gd,php-sqlite3 - Composer 2.x
- MySQL 8.0+ / MariaDB
- Nginx
- Git & Unzip
Local Development Setup
- Clone or Navigate to the Project:
BASH
cd /Volumes/Mac2TB/Botdigit/Developer/Projects/darkorbit-main
- Install Dependencies:
BASH
composer install
- Configure Environment File:
BASH
cp .env.example .env php artisan key:generate
- Run Database Migrations & Seeders:
BASH
# If using SQLite for testing: touch database/database.sqlite php artisan migrate php artisan db:seed
- Create an Initial Admin User:
BASH
php artisan tinker --execute=" \$user = new \App\Models\User(); \$user->id = (string) \Illuminate\Support\Str::uuid(); \$user->username = 'admin'; \$user->password = bcrypt('YourPassword123'); \$user->secret_word = bcrypt('supersecret'); \$user->pin = bcrypt('123456'); \$user->admin = 1; \$user->seller = 1; \$user->reference_code = \Illuminate\Support\Str::random(15); \$user->save(); echo 'Admin Created: ' . \$user->username . PHP_EOL; " - Start the Local Development Server:
OpenBASH
php artisan serve --port=8000
http://127.0.0.1:8000in your web browser.
Production Deployment Guide (botdigit.com)
1. Server Requirements & Dependencies
On your Ubuntu/Debian production server:
sudo apt update && sudo apt upgrade -y
sudo apt install -y nginx mysql-server php8.2-fpm php8.2-mysql php8.2-bcmath \
php8.2-mbstring php8.2-xml php8.2-curl php8.2-zip php8.2-gd php8.2-cli \
composer git unzip tor supervisor certbot python3-certbot-nginx
2. Code Deployment & Permissions
Clone or copy the application to /var/www/botdigit.com:
sudo mkdir -p /var/www/botdigit.com
# Copy project files into /var/www/botdigit.com
cd /var/www/botdigit.com
composer install --no-dev --optimize-autoloader
# Set proper ownership and permissions
sudo chown -R www-data:www-data /var/www/botdigit.com
sudo find /var/www/botdigit.com -type f -exec chmod 644 {} \;
sudo find /var/www/botdigit.com -type d -exec chmod 755 {} \;
sudo chmod -R 775 /var/www/botdigit.com/storage /var/www/botdigit.com/bootstrap/cache
3. Environment Configuration (.env)
Edit /var/www/botdigit.com/.env:
APP_NAME="Dark Orbit" APP_ENV=production APP_KEY=base64:YOUR_GENERATED_APP_KEY APP_DEBUG=false APP_URL=https://botdigit.com DB_CONNECTION=mysql DB_HOST=127.0.0.1 DB_PORT=3306 DB_DATABASE=darkorbit DB_USERNAME=darkorbit_user DB_PASSWORD=YOUR_STRONG_DATABASE_PASSWORD SESSION_DRIVER=file CACHE_DRIVER=file QUEUE_CONNECTION=database # Telegram Configuration TELEGRAM_BOT_TOKEN=YOUR_TELEGRAM_BOT_TOKEN TELEGRAM_WEBHOOK_URL=https://botdigit.com/telegram/webhook TELEGRAM_WEBHOOK_TOKEN=YOUR_SECRET_WEBHOOK_TOKEN # Monero / Bitcoin Node Settings MONERO_HOST=127.0.0.1 MONERO_PORT=18083 MONERO_USERNAME=monero_rpc_user MONERO_PASSWORD=monero_rpc_password BITCOIND_HOST=127.0.0.1 BITCOIND_PORT=8332 BITCOIND_USERNAME=bitcoinrpc BITCOIND_PASSWORD=bitcoin_rpc_password
4. Database Setup & Migrations
Log in to MySQL and create the database:
CREATE DATABASE darkorbit CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; CREATE USER 'darkorbit_user'@'localhost' IDENTIFIED BY 'YOUR_STRONG_DATABASE_PASSWORD'; GRANT ALL PRIVILEGES ON darkorbit.* TO 'darkorbit_user'@'localhost'; FLUSH PRIVILEGES; EXIT;
Run migrations and seed default categories:
php artisan migrate --force php artisan db:seed --force php artisan config:cache php artisan route:cache php artisan view:cache
5. Nginx Web Server & SSL Configuration
Create the Nginx virtual host configuration: /etc/nginx/sites-available/botdigit.com
server {
listen 80;
listen [::]:80;
server_name botdigit.com www.botdigit.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name botdigit.com www.botdigit.com;
root /var/www/botdigit.com/public;
index index.php index.html;
# SSL Certificates (managed via Certbot)
# ssl_certificate /etc/letsencrypt/live/botdigit.com/fullchain.pem;
# ssl_certificate_key /etc/letsencrypt/live/botdigit.com/privkey.pem;
# Security Headers
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
charset utf-8;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
error_page 404 /index.php;
location ~ \.php$ {
fastcgi_pass unix:/var/run/php/php8.2-fpm.sock;
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
include fastcgi_params;
fastcgi_hide_header X-Powered-By;
}
location ~ /\.(?!well-known).* {
deny all;
}
}
Enable the site and obtain SSL with Let's Encrypt:
sudo ln -s /etc/nginx/sites-available/botdigit.com /etc/nginx/sites-enabled/ sudo nginx -t sudo systemctl reload nginx # Issue Free SSL Certificate sudo certbot --nginx -d botdigit.com -d www.botdigit.com
6. Systemd Services (Telegram Bot & Queue Worker)
To keep the Telegram bot polling and background queues running persistently:
A. Telegram Bot Service
Create /etc/systemd/system/telegram-bot.service:
[Unit] Description=Dark Orbit Telegram Bot After=network.target mysql.service [Service] User=www-data Group=www-data Restart=always RestartSec=5 ExecStart=/usr/bin/php /var/www/botdigit.com/artisan telegram:polling [Install] WantedBy=multi-user.target
Enable and start the service:
sudo systemctl daemon-reload sudo systemctl enable telegram-bot sudo systemctl start telegram-bot
B. Queue Worker Service
Create /etc/systemd/system/darkorbit-worker.service:
[Unit] Description=Dark Orbit Queue Worker After=network.target [Service] User=www-data Group=www-data Restart=always ExecStart=/usr/bin/php /var/www/botdigit.com/artisan queue:work --sleep=3 --tries=3 [Install] WantedBy=multi-user.target
sudo systemctl enable darkorbit-worker sudo systemctl start darkorbit-worker
7. Cryptocurrency Daemons (Monero / Bitcoin RPC)
Monero Wallet RPC Setup
Start monero-wallet-rpc with RPC authentication:
monero-wallet-rpc \
--daemon-address node.monero.net:18081 \
--rpc-bind-port 18083 \
--rpc-bind-ip 127.0.0.1 \
--rpc-login monero_rpc_user:monero_rpc_password \
--wallet-file /var/monero/market_wallet \
--password-file /var/monero/wallet_pass.txt \
--disable-rpc-login=false \
--confirm-external-bind
8. Tor Hidden Service (.onion Vanity Address)
Edit /etc/tor/torrc:
HiddenServiceDir /var/lib/tor/darkorbit_hidden_service/ HiddenServicePort 80 127.0.0.1:80
Restart Tor:
sudo systemctl restart tor sudo cat /var/lib/tor/darkorbit_hidden_service/hostname
User Roles & Permissions
| Role | Access Level | Description |
|---|---|---|
| Buyer | Default user | Browse categories, cart, checkout with BTC/XMR/LTC, leave feedback, open support & dispute tickets. |
| Seller | Vendor | Product management (listings, offers, delivery methods, images), sales dashboard, vacation mode. |
| Staff / Mod | Moderator | Notice management, featured products, dispute arbitration, support tickets, mass message broadcast. |
| Admin | Superuser | Full system control, category management, user edit/ban/impersonate, commission collection & fund withdrawal. |
Directory Structure
darkorbit-main/ ├── app/ │ ├── Http/ │ │ ├── Controllers/ # Admin, Auth, Index, Order, Product, Seller, Staff, Telegram, User │ │ ├── Middleware/ # Auth, PGP 2FA, Role verifications │ │ └── Requests/ # Form validations (Login, Register, etc.) │ ├── Marketplace/ # Payment logic (Bitcoin, Monero, Multisig) │ ├── Models/ # User, Product, Order, Dispute, TelegramUser, etc. │ └── Tools/ # PGP cryptographic helpers, MoneroLib ├── config/ # coins.php, telegram.php, database.php, etc. ├── database/ │ ├── migrations/ # Table schemas (users, products, orders, telegram_users) │ └── seeders/ # CategorySeeder, DatabaseSeeder ├── Modules/ │ ├── Forum/ # Internal community discussion forum │ ├── Jabber/ # XMPP notification gateway │ └── PaymentGateway/ # Multi-currency payment processing engine ├── public/ # Web assets (CSS, JS, images, uploaded media) ├── resources/views/ # Blade templates (marketplace, admin, auth, seller) ├── routes/web.php # Core routing definitions └── mkp224o/ # Tor vanity key generator
Maintenance & Useful Artisan Commands
# Clear application cache php artisan cache:clear && php artisan config:clear && php artisan view:clear # Optimize application for production php artisan optimize # Check Telegram Bot status & health curl http://127.0.0.1:8000/telegram/health # Run test suite php artisan test
License & Support
Developed for botdigit.com. All rights reserved.
Why Choose Dark Orbit Marketplace?
| Capability | Botdigit ✅ | Others ❌ |
|---|---|---|
| AI Agent Integration (Claude/GPT) | Verified | Outdated Mockup |
| Escrow Protection (14-day window) | Yes — No Risk | Immediate release |
| Git Repository Sync | Direct Sync | Manual ZIP |
| Anti-Malware Scanned Build | Verified Build | Unchecked Upload |
Git-Sync Architecture
Auto-sync your codebase with the creator's secure GitHub repo. No manual ZIP downloads.
AI-Agent Optimized
Every component is modular and structured for clean parsing by AI coding tools.
This premium agency is verified by Botdigit to sell high-quality digital templates, services, and software frameworks.
Frequently Asked Questions
Link your repo to auto-sync downstream branches from the creator.
Built for clean parsing by Claude, GPT-4o, Cursor, and Copilot — fully modular.