A new 1.6.1 alpha release is now available for download and testing!
Attention: this is a pre-release version and is currently under active development. Please do not install, run or test this version on production environments, but only evaluate this new version on test and development servers.
Contribute to the testing rounds
Testing is a crucial aspect of software development, offering a meaningful opportunity for everyone to contribute, regardless of experience level.
You can install this package just like the original Easy!Appointments version and click through the existing and new functionality, making sure that the app works as expected.
Should you encounter any issues, please share them in the Github Issues page, in the Support Group, on the Discord Server or directly to info@easyappointments.org.
What’s New in Easy!Appointments 1.6.1
Version 1.6.1 is a maintenance release that follows up on the 1.6 launch. There are no new features this time around, and that is by design: the entire release is dedicated to closing security gaps, tightening validation across the booking page and the backend calendar, and smoothing out the rough edges that the community reported after 1.6 went out.
Security Hardening
The most important reason to test this release is security. The CAPTCHA can no longer be bypassed by simply leaving the field out of a login, password recovery or booking request, and login attempts are throttled again, so repeated wrong passwords are blocked as intended. Beyond the login flow, unauthorized users are now stopped from taking over or changing other people’s appointments, and unsafe links in the online meeting field are blocked so that they cannot run code on the calendar.
Stronger Validation & Clearer Errors
Invalid input is now handled where it belongs. Requests with invalid parameters respond with a proper “bad request” status instead of a server error, and services can no longer be saved with a negative price or a slot interval of zero. The price, slot interval and attendants number are checked before the form is even submitted, so mistakes surface immediately. Confusing messages such as “Start date value is latter than end date.” and “The operation could not completed.” have been corrected, and an outdated database schema now produces a clear message instead of a cryptic error.
A More Predictable Appointment Dialog
Several long-standing annoyances in the appointment dialog are gone. The phone number is validated exactly like it is on the booking page, the dialog scrolls to its validation message and clears invalid fields while you type, and scheduling conflicts are confirmed before the notification question rather than after it. The conflict dialog of a new appointment is no longer titled “Appointment Update”, placing an unavailability over an already booked appointment asks for a confirmation first, and rescheduling an appointment selects its date and time again by default.
Accurate Timezone Handling
Timezone labels now display the offset that is currently in effect, including during daylight saving time, so what you pick in the dropdown matches what your customers actually get. The timezone list itself has been cleaned up as well and no longer contains duplicate names, deprecated entries or malformed offsets.
Booking Page & Embedded Installations
Embedding the booking page on another website works properly again: both the booking error and the language switch error that appeared in embedded setups have been fixed. On top of that, the booking calendar switches months correctly, the page shows a message when no service or provider has been selected yet, and the cancel appointment text and button are displayed on a single line with even spacing.
Notifications & Backend Data
Appointment notes are shown correctly in email notifications again, and the “Mobile” number of providers and secretaries is saved when you create or edit them. A provider’s working plan now reports the affected days when it contains an invalid time range, and the automated test setup has been repaired so that the test suite runs again.
Note: Since this release contains four security fixes, it is worth putting high on your testing list. Feedback on the login, password recovery and booking flows is particularly valuable at this stage.
These highlights cover the main themes of this release. To see the full list of technical fixes, please refer to the Change Log section below.
Changelog
Fixed
- Requests with invalid parameters now respond with a “bad request” status instead of a server error
- Services can no longer be saved with a negative price or with a slot interval of zero
- The price, slot interval and attendants number of a service are now checked before the form is submitted
- Show a message with the affected days when the working plan of a provider has an invalid time range
- Ask for a confirmation when an unavailability is placed over an already booked appointment
- The appointment dialog now validates the phone number, just like the booking page does
- Timezone labels display the offset that is currently in effect, also during daylight saving time
- The timezone list no longer contains duplicate names, deprecated entries or malformed offsets
- When saving an appointment, the scheduling conflict is now confirmed before the notification question
- The scheduling conflict dialog of a new appointment is not titled “Appointment Update” anymore
- Show a message on the booking page when no service or provider has been selected yet
- The appointment dialog scrolls to its validation message and clears invalid fields while typing
- Fix the “Start date value is latter than end date.” and “The operation could not completed.” messages
- Security: The CAPTCHA can no longer be skipped by leaving the field out of the login, recovery or booking request
- Security: Login attempts are throttled again, so repeated wrong passwords are blocked as intended
- Security: Stop unauthorized users from taking over or changing other people’s appointments
- Security: Block unsafe links in the online meeting field so they cannot run code on the calendar
- When rescheduling an appointment, its date and time are selected again by default (#1940)
- Show the cancel appointment text and button on a single line with even spacing
- Fix the automated test setup
- The provider and secretary “Mobile” number is now saved when you create or edit them
- Fix a booking error that appeared when the booking page was embedded on another website
- Fix a language switch error when the booking page was embedded on another website
- The booking page now works when embedded on other websites
- Show a clear message when the database needs to be updated, instead of a confusing error
- Fix the month switching on the booking calendar (#1862)
- Show appointment notes correctly in email notifications (#1881)
Going Premium
Did you read this article, but you’re still not sure on how to proceed?
Reach out to info@easyappointments.org and have an expert take care of everything for you in zero time.
Get your free quote and get started now!