justinandClaude Opus 4.6 b14c8c6436 security: fix XSS, path traversal, account oracle, email injection
- Escape all DB values in embed widget innerHTML (XSS via pet names)
- Remove account existence oracle from login error messages
- Derive upload extension from MIME type, not client filename
- Add path traversal guard in deleteUpload
- Restrict mustChangePassword bypass to /api/worker/ only
- HTML-escape all user input in outbound email templates

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-27 12:57:52 -05:00

FosterFlow

Open-source rescue management platform — self-host free or use FosterFlow Cloud.

Modern, fast, mobile-first website and management system built for animal rescues. Everything a foster-based rescue needs, nothing it doesn't.


What It Does

  • Pet Management — Profiles, photos, medical records, foster assignments, status tracking
  • Applications — Adoption, foster, volunteer, surrender forms with configurable questions
  • Foster Portal — Dedicated dashboard for fosters to submit updates, photos, supply requests
  • Donations & Expenses — Stripe payments, multi-source tracking, financial reports
  • Events — Listings with optional Facebook auto-posting
  • Content CMS — Editable page sections, newsletter, happy tails / success stories
  • Analytics — Human traffic, bot detection, honeypot, AI job tracking
  • Role-Based Access — 9 roles from sysadmin to foster with granular permissions
  • Bot Protection — Dynamic robots.txt, honeypot tarpit, managed blocklist/whitelist
  • AI Features — Pet name generator (Ollama), expandable job queue

Tech Stack

  • SvelteKit 2 + Svelte 5 (runes)
  • Tailwind CSS 4
  • Drizzle ORM + MariaDB/MySQL
  • Node.js adapter for production
  • Stripe for payments
  • Nodemailer for email
  • Ollama for local AI (optional)

SaaS Architecture

FosterFlow supports multi-tenant deployment:

  • Self-hosted — One rescue, one server, free forever
  • FosterFlow Cloud — Automated onboarding, subdomain provisioning, managed hosting

See docs/SAAS.md for the multi-tenant architecture. See docs/ONBOARDING.md for automated provisioning.

Quick Start (Docker)

The fastest way to get running:

git clone https://github.com/yourusername/fosterflow
cd fosterflow
cp .env.example .env
# Edit .env — set SESSION_SECRET and SITE_DOMAIN at minimum
docker compose up

On first run, migrate and seed the database:

docker compose exec app npx drizzle-kit push
docker compose exec app npx tsx scripts/seed.ts

Then open http://localhost:3000 and log in with admin@example.com / changeme.

Quick Start (Manual)

git clone https://github.com/yourusername/fosterflow
cd fosterflow
cp .env.example .env
# Edit .env with your database URL, SMTP settings, etc.
npm install
npx drizzle-kit push
npx tsx scripts/seed.ts
npm run dev

Self-Hosted vs FosterFlow Cloud

Self-Hosted FosterFlow Cloud
Cost Free $19/mo
Hosting You manage Fully managed
SSL You configure Automatic
Backups You configure Daily, included
Updates Manual Automatic
Subdomain Your domain yourrescue.fosterflow.app
Setup assist Community support $50 one-time migration

License

MIT — use it, fork it, save some dogs.


Built with love by JRei — started as Almost Home Canine Rescue's website, now open for every rescue.

S
Description
Open-source rescue management platform — self-host free or use FosterFlow Cloud
Readme
536 KiB
Languages
Svelte 62.1%
TypeScript 37.8%