Skip to main content
All updates
Bug fixPlatform·2026.09.24·

Behind-the-scenes database actions are now server-only by default

BookingBible tightened who may run its internal database actions. Anything new is now available only to BookingBible itself unless it is explicitly approved for the app or the web. Nothing changes on your screens, and there is nothing you need to do.

This is an internal security improvement. No screen changes, no amounts change,
and nothing you need to do.

## What changed

- **Server-only by default.** BookingBible's database has many small built-in
  actions (checking a permission, cancelling a booking, tallying storage). Until
  now, new ones could also be reached from a browser even when only
  BookingBible's own servers ever use them. From today every new action is
  available only to BookingBible itself, and one that the app or the web really
  needs must be approved on a written list, with a reason.
- **The existing ones were reviewed one by one.** Actions that only
  BookingBible's servers, scheduled jobs or automatic database steps use are
  now server-only. Actions your staff screens use directly, such as saving
  Command Center rules, applying a theme preset, or saving notification
  settings, keep working and still check that the person is allowed to do it
  at your venue.
- **Answers only about yourself.** Two permission checks now answer only about
  the person asking. Your staff's own permissions, and everything your screens
  show them, are unchanged.
- **Checked automatically, every day.** Every future change is checked before
  it ships, and the live system is re-checked daily, so an action left open by
  accident is flagged to the BookingBible team within a day.
Next update

Clients see exactly what cancelling a class costs, before they cancel

The cancel dialog now states your real rule for that booking at that moment — free, or late with the exact fee and what happens to the clip — in your venue's local time, and the late-cancellation receipt lists every detail.