// the find
liketrek/TREK
A self-hosted travel/trip planner with real-time collaboration, interactive maps, PWA support, SSO, budgets, packing lists, and more.
TREK is a self-hosted, real-time collaborative trip planner — think an open-source Wanderlog/TripIt with maps, bookings, shared budgets, packing lists, and a journal. It's aimed at people who want to run their own travel-planning stack instead of handing itineraries to a SaaS, and at groups who actually plan trips together rather than solo.
The offline story is unusually complete for a self-hosted app: service worker precaches routes, IndexedDB holds trips/places/file blobs, and writes queue with an idempotency key so a flaky connection on a trip can't double-apply a mutation — most 'PWA' self-hosted projects stop at caching static assets. The plugin system is sandboxed per-process with 63 grantable permissions, an outbound host allowlist, and sha256+minisign-pinned registry downloads, which is a lot more rigor than the typical 'drop a JS file in a folder' plugin model. Real-time sync is a plain WebSocket layer rather than a CRDT framework bolted on, which keeps the mental model simple for a planner where last-write-wins per field is usually fine. Route optimization (nearest-neighbor + 2-opt over OSRM) and the multi-leg flight/train model with a bundled airport timezone table are genuinely useful, not just checkbox features.
SQLite backs a multi-user, real-time collaborative app — fine for a household, but write contention under concurrent edits from several trip members is a real question the README doesn't address, and there's no migration path to Postgres mentioned. The feature surface is enormous (journal, atlas, collections, MCP, plugins, AI parsing, AirTrail sync) and most of it ships off by default, which means the well-tested path is a small core and the rest is combinatorial addon interaction that's hard to have actually exercised. The MCP server exposes 199 tools with OAuth — powerful, but it's also the biggest attack surface in the project and the kind of thing that's easy to under-scope in practice even with 29 granular scopes. AGPL is the right call for a self-hosted tool, but it's worth flagging to anyone considering it as a dependency in a commercial product, not just a personal deployment.