Skip to content

agit8or1/clientst0r

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

1,243 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Client St0r

GitHub Stars Version 3.17.28 Production Ready License: MIT Django 6.0 Python 3.12+ Known Vulnerabilities Security Monitoring

Open-source, self-hosted MSP documentation platform β€” an alternative to IT Glue and Hudu. Full data ownership. No SaaS fees. Runs on your infrastructure.

If Client St0r saves you time or money, a ⭐ star helps others find it.

IT Glue Alternative β†’ Hudu Alternative β†’ What is ClientSt0r? β†’

A complete, self-hosted IT documentation platform designed for Managed Service Providers (MSPs) and IT departments. Built with Django 6, Client St0r provides secure asset management, encrypted password vault, knowledge base, PSA integrations, and comprehensive monitoring tools.

Client St0r is commonly evaluated as an open-source IT Glue alternative and a self-hosted Hudu alternative for MSP documentation.

πŸ“Έ Screenshots

All screenshots include demo data and are watermarked. Random background feature enabled. View full gallery β†’

🏠 Dashboard & Quick Access

Dashboard Quick Add

πŸ“¦ Asset Management

Assets Racks

πŸ” Password Vault & Security

Password Vault Personal Vault

πŸ“š Documentation & Knowledge Base

Knowledge Base Diagrams

πŸ”’ Security Dashboard

Security Dashboard Vulnerability Scans

🌐 Monitoring

Website Monitors Expirations

βš™οΈ System Management

System Updates System Status

🏒 Multi-Organization & Access

Organizations Access Management

πŸš— Service Vehicles & Fleet Inventory

Inventory Vehicles Dashboard

πŸ“¦ Inventory QR Codes

QR Code Print Sheet Shop Inventory Edit

🧾 Vehicle Receipt Scanning (AI OCR)

Receipt List & Cost Summary Add Receipt β€” AI Extract

πŸ“± Install App / Phone Shortcut

Install App Page PWA Phone Shortcut

πŸ“‹ View All Screenshots (46 total)

Core Features

  • Dashboard - Main dashboard with random backgrounds
  • Quick Add - Fast creation menu for assets, passwords, documents
  • Profile - User profile and settings
  • Favorites - Quick access to favorited items

Asset Management

Password Vault

Documentation & Diagrams

Workflows & Processes

  • Workflows - Process automation and tracking

Monitoring & Expirations

Security & Scanning

System Administration

MSP/Global Features (Staff Only)

Service Vehicles & Fleet Inventory

Receipt Scanning & Mobile

πŸ• About Luna

This project was developed with the assistance of Luna, a brilliant German Shepherd Dog with exceptional problem-solving abilities and a keen eye for security best practices. Luna's contributions to code review, architecture decisions, and bug hunting have been invaluable.

IT Glue / Hudu Alternative

If you're comparing documentation platforms for MSP workflows, Client St0r is designed to cover core documentation needs (assets, credentials, procedures/runbooks, and knowledge base content) while remaining fully self-hosted.

✨ Key Features

πŸ” Security & Authentication

  • Azure AD / Microsoft Entra ID SSO with auto-user creation
  • LDAP/Active Directory enterprise integration
  • Enforced TOTP 2FA with SSO bypass
  • AES-GCM Encryption for all sensitive data
  • Password Breach Detection via HaveIBeenPwned (k-anonymity)
  • Snyk Security Scanning with automated CVE detection
  • Rate Limiting, CSRF, XSS, SQL injection, SSRF, path traversal protection
  • Encrypted Backups with automatic retention policies

🏒 Multi-Organization Management & Access Control

  • Complete Organization Isolation - Manage multiple client organizations with data separation and 42 granular permissions
  • Four-Tier Access Levels - Owner, Admin, Editor, Read-Only
  • MSP User Types - Staff users (global access to all organizations) and Organization users (scoped to specific clients)

πŸ“¦ Core Platform

  • Auto-Update System - One-click web updates (20-30 seconds, no SSH)
  • Asset Management - Comprehensive tracking with interactive rack/board visualization
  • Network Scanner - Automated network discovery with nmap, smart asset import, duplicate prevention
  • Interactive Racks - Drag-and-drop device positioning, realistic equipment visuals, zoom controls
  • Wall-Mounted Boards - 2D canvas layout for wall/ceiling equipment, snap-to-grid, free-form positioning
  • Patch Panels - Click-to-connect port management, visual cable paths, color-coded connections
  • Equipment Visuals - Type-specific indicators (LEDs, ports, drive bays), equipment model images
  • Password Vault - AES-GCM encrypted with breach detection, personal vaults, and Bitwarden import
  • Bitwarden Import - Import passwords from Bitwarden/Vaultwarden JSON exports (logins, notes, cards, identities, folders, custom fields, TOTP)
  • SMS/Navigation - Send location navigation links via SMS (Twilio, Plivo, Vonage, Telnyx, AWS SNS)
  • Documentation - Per-org docs with version control, templates, and global MSP knowledge base
  • Diagrams & Floor Plans - Draw.io integration, MagicPlan import, auto-generated flowcharts
  • Infrastructure - IPAM with subnet management, VLAN tracking, network closets, cable documentation
  • Service Vehicles - Fleet management with mileage tracking, maintenance schedules, fuel logs, damage reports with interactive diagrams, vehicle inventory, GPS location, insurance tracking, AI-powered receipt scanning with expense category totals
  • OS Package Scanner - System package vulnerability scanning (apt/yum/dnf), automated security update detection, scheduled scans
  • Monitoring - Website uptime, SSL certificates, domain expiration, custom alerts, WAN monitoring
  • Workflows - Process automation with audit logging, PSA integration, execution tracking
  • Scheduling - Staff scheduling with calendar view, shift management, and coverage tracking
  • Inventory Module - Standalone inventory management with barcode scanning, stock levels, and reorder alerts
  • Locations in Organizations - Manage multiple locations per organization with address, type, status, and floor plan support
  • Firewall Management - iptables firewall rules, GeoIP country blocking, IP whitelist/blacklist
  • Intrusion Prevention - Fail2ban integration with ban management and IP checking
  • Reporting & Analytics - Advanced reports, custom dashboards, scheduled reports, data visualization
  • Backup/Restore - Encrypted backups, automated scheduling, retention policies, one-click restore
  • Progressive Web App - Install on any device via /core/install/ β€” QR code, one-tap install prompt, Add to Home Screen guide for Android and iOS; PWA shortcuts for Scan Receipt and Vehicles on Android long-press
  • Native Mobile App - React Native app for iOS and Android with full feature access

πŸ”Œ Integrations & APIs

  • 8 PSA Providers - ConnectWise, Autotask, HaloPSA, Kaseya BMS, Syncro, Freshservice, Zendesk, ITFlow
  • 5 RMM Providers - Tactical RMM (full), NinjaOne, Datto, Atera, CW Automate (infrastructure ready)
  • 3 Network Integrations - UniFi, Omada, and Grandstream β€” auto-discover and sync network devices as assets with scheduled sync support
  • Organization Auto-Import - Automatically create orgs from PSA companies or RMM sites
  • Asset Mapping - Auto-link RMM devices to assets
  • Data Import - CSV/spreadsheet import with visual field mapper; import from Hudu and IT Glue
  • REST API v1 - Full-featured REST API with authentication and rate limiting
  • GraphQL API v2 - Modern GraphQL API with filtering, pagination, and real-time capabilities
  • Webhook Support - Event-driven integrations with external systems

For complete feature details, see FEATURES.md

πŸ†• What's New

Latest Release - v3.17.x (April 2026)

πŸŽ‰ New in v3.17:

  • 🧾 Vehicle Receipt Scanning with AI OCR - Photograph receipts directly from your phone; Claude vision API automatically extracts vendor, date, amount, tax, expense category, and odometer reading; receipts tab on vehicle detail shows per-category cost summary cards (Fuel, Maintenance, Repair, Total); duplicate prevention via SHA-256 image hashing
  • πŸ“± Install App / Add to Home Screen - Dedicated install page (/core/install/) with QR code of your server URL, downloadable QR PNG, one-tap PWA install button (Android/desktop), and step-by-step instructions for Android Chrome, iPhone/iPad Safari, and desktop; per-vehicle receipt shortcuts also available
  • πŸ”’ Automated Security Scan Alerts - Opt-in daily scheduled security scan emails all superusers when vulnerabilities are found; toggle on/off from Security Dashboard
  • 🎨 Active Client Indicator - Organization shown as an amber pill with pulsing dot in the navbar so users always know which client they're working under

Bug Fixes in v3.17:

  • TRMM MAC address sync β€” per-agent detail fetch now triggered when MAC is missing, not just when RAM/disks are absent (#108)
  • M365 mailbox usage in documents β€” mailbox usage data now included in generated M365 documents (#106)
  • UniFi asset categorization β€” Security Gateway (ugw) added to type map; model field used as fallback (#105)
  • IPAM asset link field β€” IP address form and subnet detail table asset link corrected (#111)

Previous Release - v3.16.x (March 2026):

  • 🌐 Omada & Grandstream Network Integrations - Auto-discover and sync network devices from TP-Link Omada and Grandstream controllers as assets, with configurable scheduled sync
  • πŸ“₯ Data Import with CSV Field Mapper - Import any data (assets, passwords, contacts, documents) from CSV/spreadsheets with a visual field mapper; also import directly from Hudu or IT Glue
  • 🏒 Locations Integrated into Organizations - Manage multiple physical locations per organization directly from the org detail page
  • 🧭 Streamlined Navigation - Consolidated top navigation into a single Operations dropdown

Service Vehicles Fleet Management (v3.9.0+, receipts v3.17.11+)

Complete fleet management system for tracking service vehicles with comprehensive features:

  • Vehicle Tracking: Make, model, year, VIN, license plate, mileage, condition status
  • Maintenance Management: Service history, recurring schedules, costs, repair tracking, overdue detection
  • Fuel Tracking: Fuel purchases with automatic MPG calculation, cost analysis, efficiency trends
  • Damage Reports: Interactive vehicle diagrams with clickable areas, photo uploads, repair status, insurance claims
  • Vehicle Inventory: Per-vehicle inventory tracking (cables, tools, supplies), low-stock alerts
  • User Assignments: Assignment history with mileage tracking, active assignment management
  • Insurance Tracking: Policy details, expiration warnings, premium tracking
  • GPS Location: Store current vehicle coordinates (6 decimal precision), last update timestamp
  • Receipt Scanning: Photograph receipts with your phone; AI (Claude vision) extracts vendor, date, amount, tax, category; per-category totals (fuel, maintenance, repair); duplicate prevention via image hashing
  • Phone Shortcut: QR code per vehicle links directly to Add Receipt on your phone; Add to Home Screen supported on Android and iOS
  • Dashboard & Analytics: Fleet statistics, maintenance alerts, fuel costs, receipt expense totals, vehicle cards with status
  • Feature Toggle: Enable/disable vehicles module via system settings

OS Package Security Scanner (v3.9.0+)

Automated vulnerability scanning for system packages with security update tracking:

  • Multi-Platform Support: apt (Debian/Ubuntu), yum/dnf (RedHat/CentOS), pacman (Arch)
  • Security Updates: Detect security-specific updates from official repositories
  • Scheduled Scans: Automated daily scans with configurable schedule
  • Dashboard Widget: Security status overview on security dashboard
  • Scan History: Track scan results over time with trend visualization
  • Manual Triggers: Run scans on-demand via web interface
  • Package Details: Total packages, upgradeable packages, security updates count
  • Alert System: Webhook notifications for critical security updates

Enhanced Rack Device Management (v3.10.0+)

Improved drag-and-drop with native HTML5 events and better UX:

  • Native Drag Events: Replaced SortableJS with HTML5 drag-and-drop for better reliability
  • Visual Feedback: Blue highlight on valid drop targets, grab/grabbing cursor states
  • Collision Detection: Prevents overlapping devices, validates space before drop
  • Real-time Updates: API-driven position updates with error handling
  • Device Wiring: Connection management with SVG cable visualization between devices
  • Port Configuration: Label and configure network ports on rack-mounted equipment

Network Scanner & Asset Discovery (v3.8.0)

Scan your network to automatically discover and import devices into your asset inventory:

  • Automated Discovery: Uses nmap to scan network ranges (CIDR, IP ranges, single IPs)
  • Intelligent Matching: Matches devices by MAC address (primary) or IP address (secondary)
  • Smart Import: Preview what will be created/updated, select devices to import, avoid duplicates
  • Device Detection: Auto-identifies servers, switches, routers, printers, cameras, phones, APs
  • Rich Metadata: Captures IP, MAC, hostname, OS, open ports, services, vendor info
  • Conflict Resolution: Flags potential duplicates for manual review
  • Selective Import: Checkbox selection for each discovered device
  • Update Existing: Updates existing assets with latest network data without creating duplicates
# Run scanner
python3 scripts/network_scanner.py 192.168.1.0/24

# Upload scan file to: Assets β†’ Import Network Scan
# Review matches, select devices, confirm import

Wall-Mounted Board Layout (v3.7.0)

Transform rack visualization into a 2D board for wall/ceiling mounted equipment:

  • Dual View Modes: Toggle between vertical rack view and horizontal board layout
  • Free-Form Positioning: Drag devices anywhere on 2D canvas
  • Snap-to-Grid: 50px grid overlay with toggle for precise alignment
  • Drag-to-Resize: Resize devices visually by dragging corners
  • Zoom Controls: Zoom in/out works in both rack and board views
  • Asset Sidebar: Drag assets directly from sidebar onto board or rack

Realistic Device Visuals (v3.7.0)

Devices now look like actual equipment with type-specific visual indicators:

  • Equipment Images: Display actual product photos from equipment models
  • Server Visuals: Drive bays + power/status/activity LEDs
  • Network Equipment: Port indicators (24/48 ports) + link status LEDs
  • Patch Panels: Port grid layout with visual numbering
  • UPS/PDU: Power outlet indicators + dual power LEDs
  • Wireless APs: Signal indicator (πŸ“‘) + status LEDs
  • Security Cameras: Recording indicator (πŸ“Ή) + activity LED
  • Storage Devices: Drive bay grid + activity LEDs
  • Auto-Scaling: Visual indicators scale with device size

Interactive Patch Panel Management (v3.6.0)

Click-to-connect interface for managing patch panel connections:

  • Click-to-Connect: Click source port β†’ click destination port to create connection
  • Visual Connections: SVG curved lines show cable paths between connected ports
  • Color-Coded Cables: Customize cable colors for visual organization
  • Port Status: Color-coded ports (available, in-use, reserved)
  • Connection Details: Track destination, cable type, notes per port
  • Drag Assets to Ports: Drag assets from sidebar directly to ports
  • Port Grid View: Visual 24/48 port layouts matching physical panels
  • Quick Disconnect: Right-click or button to disconnect ports

Previous Highlights (v2.76):

  • Asset Lifespan Tracking - Track purchase dates, expected lifespan, and end-of-life reminders
  • Bitwarden/Vaultwarden Import - Import passwords with folders, TOTP, custom fields
  • SMS/Navigation Links - Send location navigation via SMS (Google Maps, Apple Maps, Waze)
  • Firewall & GeoIP - iptables management with country blocking
  • Fail2ban Integration - Automated intrusion prevention
  • Progressive Web App - Install on mobile devices with offline support

For complete version history, see CHANGELOG.md

πŸš€ Quick Start

One-Line Installation (Recommended)

The easiest way to install Client St0r:

git clone https://github.com/agit8or1/clientst0r.git && cd clientst0r && bash install.sh

This automated installer will:

  • βœ… Install all prerequisites (Python 3.12, pip, venv, MariaDB server & client)
  • βœ… Create virtual environment and install dependencies
  • βœ… Generate secure encryption keys automatically
  • βœ… Create .env configuration file
  • βœ… Setup database and user
  • βœ… Create log directory
  • βœ… Run migrations
  • βœ… Create superuser account
  • βœ… Collect static files
  • βœ… Start production server automatically (Gunicorn with systemd)
  • βœ… Configure auto-update permissions (sudoers for one-click web updates)

When the installer finishes, your server is RUNNING and ready to use!

Smart Detection

The installer automatically detects existing installations and offers:

  1. Upgrade/Update - Pull latest code, run migrations, restart service (zero downtime)
  2. System Check - Verify all components are working properly
  3. Clean Install - Remove everything and reinstall from scratch
  4. Exit - Leave existing installation untouched

No manual cleanup needed! The installer handles everything.

Web-Based Auto-Update (NEW in 2.14.21!)

Once installed, you can update Client St0r directly from the web interface:

  1. Navigate to System Settings β†’ System Updates
  2. Click "Check for Updates Now" to detect new versions
  3. Click "Apply Update" when an update is available
  4. Watch real-time progress through all 5 steps:
    • Step 1: Git Pull
    • Step 2: Install Dependencies
    • Step 3: Run Migrations
    • Step 4: Collect Static Files
    • Step 5: Restart Service
  5. Page automatically reloads with the new version (20-30 seconds total)

No SSH access required! Non-technical users can update safely from the web interface.

System Requirements:

  • Ubuntu 20.04+ or Debian 11+
  • 2GB RAM minimum (4GB recommended)
  • Internet connection for package installation

Optional Features

LDAP/Active Directory Integration

By default, Client St0r installs with Azure AD SSO support but without LDAP/Active Directory. This is because LDAP requires C compilation and system libraries.

If you need LDAP/AD support, install it after the main installation:

# Install system build dependencies
sudo apt-get update
sudo apt-get install -y build-essential python3-dev libldap2-dev libsasl2-dev

# Install LDAP Python packages
cd ~/clientst0r
source venv/bin/activate
pip install -r requirements-optional.txt
sudo systemctl restart clientst0r-gunicorn.service

Note: Azure AD SSO does not require these packages. LDAP is only needed for on-premises Active Directory or other LDAP servers.

Mobile App (iOS & Android)

Client St0r includes a native React Native mobile app for iOS and Android devices.

Features:

  • πŸ“± Native iOS and Android apps
  • πŸ” Secure token-based authentication
  • πŸ“Š Dashboard with quick stats
  • πŸ’Ό Asset management on the go
  • πŸ”’ Password vault access
  • πŸ“š Document browsing
  • πŸŒ™ Dark mode optimized for mobile
  • πŸ”„ Real-time sync via GraphQL API

Prerequisites:

  • Node.js 18+
  • Expo CLI
  • Client St0r backend with GraphQL enabled

Setup:

# 1. Install GraphQL dependencies on backend
cd ~/clientst0r
source venv/bin/activate
pip install -r requirements-graphql.txt
sudo systemctl restart clientst0r-gunicorn.service

# 2. Set up mobile app
cd ~/clientst0r/mobile-app
npm install

# 3. Configure API URL
# Edit app.json and set your Client St0r server URL

# 4. Start development server
npm start

# 5. Run on device
# - iOS: Press 'i' or run: npm run ios
# - Android: Press 'a' or run: npm run android

For complete mobile app documentation, see mobile-app/README.md

Manual Installation

If you prefer to install manually or need more control:

Click to expand manual installation steps

Prerequisites

  • Python 3.12+
  • MariaDB 10.5+ or MySQL 8.0+
  • Nginx (production only)
# 1. Clone repository
git clone https://github.com/agit8or1/clientst0r.git
cd clientst0r

# 2. Install system dependencies
sudo apt-get update
sudo apt-get install -y python3.12 python3.12-venv python3-pip mariadb-client mariadb-server

# 3. Create virtual environment
python3.12 -m venv venv
source venv/bin/activate

# 4. Install Python dependencies
pip install --upgrade pip
pip install -r requirements.txt

# 5. Generate secrets
python3 -c "from cryptography.fernet import Fernet; print('APP_MASTER_KEY=' + Fernet.generate_key().decode())"
python3 -c "import secrets; print('SECRET_KEY=' + secrets.token_urlsafe(50))"
python3 -c "import secrets; print('API_KEY_SECRET=' + secrets.token_urlsafe(50))"

# 6. Create .env file
# Copy the generated secrets from step 5 into this file
cat > .env << 'EOF'
DEBUG=True
SECRET_KEY=<paste_secret_key_here>
ALLOWED_HOSTS=localhost,127.0.0.1

DB_NAME=clientst0r
DB_USER=clientst0r
DB_PASSWORD=your_secure_password
DB_HOST=localhost
DB_PORT=3306

APP_MASTER_KEY=<paste_master_key_here>
API_KEY_SECRET=<paste_api_key_secret_here>

EMAIL_BACKEND=django.core.mail.backends.console.EmailBackend
SITE_NAME=Client St0r
SITE_URL=http://localhost:8000
EOF

# 7. Start MariaDB and create database
sudo systemctl start mariadb
sudo mysql << 'EOSQL'
CREATE DATABASE clientst0r CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'clientst0r'@'localhost' IDENTIFIED BY 'your_secure_password';
GRANT ALL PRIVILEGES ON clientst0r.* TO 'clientst0r'@'localhost';
FLUSH PRIVILEGES;
EOSQL

# 8. Run migrations
python3 manage.py migrate

# 9. Create superuser
python3 manage.py createsuperuser

# 10. Collect static files
python3 manage.py collectstatic --noinput

# 11. Run development server
python3 manage.py runserver 0.0.0.0:8000

Visit http://localhost:8000 and log in with the credentials you created in step 9.

πŸ“š Documentation

Installation:

  • INSTALL.md - Complete installation guide (quick start, upgrade, troubleshooting)

Core Documentation:

  • ORGANIZATIONS.md - Complete guide to organizations, user types, roles, and permissions
  • SECURITY.md - Security best practices and vulnerability disclosure
  • CONTRIBUTING.md - Development and contribution guidelines
  • CHANGELOG.md - Version history and release notes
  • deploy/ - Production deployment configs (Nginx, Gunicorn, systemd services)

πŸ—οΈ Architecture

Technology Stack

  • Framework: Django 6.0
  • API: Django REST Framework 3.15
  • Database: MariaDB 10.5+ (MySQL 8.0+ supported)
  • Web Server: Nginx + Gunicorn
  • Authentication: django-two-factor-auth (TOTP)
  • Encryption: Python cryptography (AES-GCM)
  • Password Hashing: Argon2
  • Frontend: Bootstrap 5, vanilla JavaScript

Design Philosophy

  • βœ… Flexible Deployment - Pure systemd deployment OR optional Docker
  • βœ… No Redis - systemd timers for scheduling (Redis optional for Docker)
  • βœ… Minimal Dependencies - Only essential packages
  • βœ… Security First - Built with security in mind
  • βœ… Self-Hosted - Complete data control
  • βœ… Mobile-First - Responsive design with PWA support
  • βœ… API-Driven - REST and GraphQL APIs for integrations

πŸ”’ Security

Client St0r has undergone comprehensive security auditing and continuous vulnerability monitoring:

Continuous Security Monitoring

  • βœ… Automated CVE Scanning - Codebase scanned for known vulnerabilities and CVEs
  • βœ… AI-Assisted Detection - Pattern matching for SQL injection, XSS, CSRF, path traversal
  • βœ… Dependency Monitoring - Python packages checked against security advisories
  • βœ… Weekly Manual Audits - Regular security reviews by development team
  • βœ… Alert-Only System - No automated code changes, human verification required

Fixed Vulnerabilities

  • βœ… SQL Injection - Parameterized queries and identifier quoting
  • βœ… SSRF - URL validation with IP blacklisting
  • βœ… Path Traversal - Strict file path validation
  • βœ… IDOR - Object access verification
  • βœ… Insecure File Uploads - Type, size, and extension validation
  • βœ… Hardcoded Secrets - Environment variable enforcement
  • βœ… Weak Encryption - AES-GCM with validated keys
  • βœ… CSRF Protection - Multi-domain support

Security Features

  • All passwords encrypted with AES-GCM
  • API keys hashed with HMAC-SHA256
  • Rate limiting on all endpoints
  • Brute-force protection
  • Security headers (CSP, HSTS)
  • Private file serving
  • Audit logging
  • Password breach detection (HaveIBeenPwned integration)

Security Disclosure: If you discover a vulnerability, please email agit8or@agit8or.net. See SECURITY.md for details.

🀝 Contributing

We welcome contributions! Here's how you can help:

πŸ’‘ Feature Requests & Ideas

Have an idea for a new feature? We use a community-driven voting system:

  1. Start with a Discussion β†’ Share your idea
  2. Vote on existing ideas β†’ Browse and upvote (πŸ‘ reactions)
  3. Track the Roadmap β†’ View what's being built

Popular ideas (high votes + alignment with project goals) are promoted to Feature Request issues and added to the Roadmap.

πŸ“– Read the full guide: docs/FEATURE_REQUESTS.md

πŸ› Bug Reports

Found a bug? Report it here

πŸ”¨ Code Contributions

Ready to contribute code? See CONTRIBUTING.md for guidelines.

Development Setup

# 1. Fork and clone
git clone https://github.com/agit8or1/clientst0r.git
cd clientst0r

# 2. Create feature branch
git checkout -b feature/amazing-feature

# 3. Make changes and test
python3 manage.py test

# 4. Commit and push
git commit -m 'Add amazing feature'
git push origin feature/amazing-feature

# 5. Open Pull Request

πŸ“ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ™ Acknowledgments

  • Luna the GSD - Development assistance, security review, and bug hunting
  • Django & DRF - Excellent web framework
  • Bootstrap 5 - Beautiful, responsive UI
  • Font Awesome - Icon library
  • Community - All contributors and users

πŸ“Š Project Status

  • Version: 3.16.5
  • Release Date: March 2026
  • Status: Production Ready
  • Maintained: Yes
  • Security: Continuous monitoring, automated scanning, HaveIBeenPwned integrated

πŸ’¬ Support

πŸ’ Supporting This Project

If you find Client St0r useful for your MSP or IT department, please consider supporting the developer's business: MSP Reboot - Professional MSP services and consulting.

Your support allows me to continue developing open-source tools like Client St0r and contribute to the MSP community. Thank you!

πŸ—ΊοΈ Roadmap

  • Mobile-responsive UI improvements βœ…
  • Advanced reporting and analytics βœ…
  • Backup/restore functionality βœ…
  • Docker deployment option (optional) βœ…
  • Additional PSA/RMM integrations βœ…
  • API v2 with GraphQL βœ…
  • MagicPlan floor plan integration βœ…
  • Mobile app (development plan complete) βœ…

⚑ Performance

  • Handles 1000+ assets per organization
  • Sub-second page load times
  • Efficient database queries
  • Optimized for low-resource environments
  • Horizontal scaling support

Made with ❀️ and πŸ• by the Client St0r Team and Luna the German Shepherd


Keywords

Open-source IT Glue alternative Β· Self-hosted Hudu alternative Β· MSP documentation platform Β· IT documentation system Β· MSP knowledge base Β· self-hosted IT documentation

About

Client St0r - IT Documentation Platform for MSPs and IT Teams | Managed by Chinook the Shepsky 🐾

Topics

Resources

License

Contributing

Security policy

Stars

Watchers

Forks

Packages

 
 
 

Contributors