Behind-the-scenes database actions are now server-only by default
BookingBible tightened who may run its internal database actions. Anything new is now available only to BookingBible itself unless it is explicitly approved for the app or the web. Nothing changes on your screens, and there is nothing you need to do.
This is an internal security improvement. No screen changes, no amounts change, and nothing you need to do. ## What changed - **Server-only by default.** BookingBible's database has many small built-in actions (checking a permission, cancelling a booking, tallying storage). Until now, new ones could also be reached from a browser even when only BookingBible's own servers ever use them. From today every new action is available only to BookingBible itself, and one that the app or the web really needs must be approved on a written list, with a reason. - **The existing ones were reviewed one by one.** Actions that only BookingBible's servers, scheduled jobs or automatic database steps use are now server-only. Actions your staff screens use directly, such as saving Command Center rules, applying a theme preset, or saving notification settings, keep working and still check that the person is allowed to do it at your venue. - **Answers only about yourself.** Two permission checks now answer only about the person asking. Your staff's own permissions, and everything your screens show them, are unchanged. - **Checked automatically, every day.** Every future change is checked before it ships, and the live system is re-checked daily, so an action left open by accident is flagged to the BookingBible team within a day.
Clients see exactly what cancelling a class costs, before they cancel
The cancel dialog now states your real rule for that booking at that moment — free, or late with the exact fee and what happens to the clip — in your venue's local time, and the late-cancellation receipt lists every detail.