Production Update 1.2.4
Summary
First Open Defects pass: 24 of 40 tracker items shipped. Agent terminate is live with blockers, Super Admin root accounts cannot be deleted by peers, System Admin can edit role module actions and create System Admin, withdrawal review defaults to awaiting or fraud-flagged items and shows reject / review reasons, dashboards get custom date range, Admin gets a global audit log, and player-facing fake ticker / guest “active session” badges are gone. The remaining 18 items stay on the list below as Todo or In Progress.
Added
- Admins can terminate an Agent from Agent detail. The flow previews blockers first (open shops, outstanding shop funding debt, active players) and asks the admin to type terminate to confirm. KIOSK-433Module: Agent Management · Portal: Admin
- Super/System Admin Audit Log page records actor, action, target, before and after values, and timestamp for admin, player, agent, and withdrawal actions. KIOSK-414Module: Admin Audit Log · Portal: Admin
- System Admin can mark a Super Admin as a root (owner) account. Super Admin cannot delete or terminate a root Super Admin or their own account. Delete requires typing delete plus a reason. Grant/revoke root, delete, and terminate write audit rows.Module: Admin accounts · Portal: Admin
- Super Agent Financials now has a Credits Withdrawn Back card (credits returned up the chain in the selected period). KIOSK-421Module: Super Agent Dashboard · Portal: Super Agent
- Super Agent Overview shows Outstanding Online Debt as a headline KPI. KIOSK-422Module: Super Agent Dashboard · Portal: Super Agent
- Admin Agent Network adds Owners with Debt and Wholesale Cash Margin, plus Top Agents and Top Shops ranking charts. KIOSK-424Module: Admin Dashboard · Portal: Admin
- Admin footer shows the app version and git SHA so a retest can be tied to a build. KIOSK-443Module: Admin shell · Portal: Admin
- Unknown Admin URLs now open a Page not found screen instead of silently landing on Player management. KIOSK-444Module: Admin routing · Portal: Admin
Fixed
- Withdrawal Requests opens on items that need review: awaiting admin or fraud-flagged, not the full 700+ queue. Flagging rules are written on the page. Internal game-to-wallet transfers are not fraud-flagged. KIOSK-427Module: Withdrawal Review · Portal: Admin
- Rejected withdrawals show who rejected, the reason, and the time on the detail screen. KIOSK-428Module: Withdrawal Review · Portal: Admin
- A payout that skipped auto-approve now stores and displays the triggering rule (amount vs threshold, bonus In Review, fraud flag, or auto-approve failed) — not only the $200 amount limit. KIOSK-429Module: Withdrawals · Portal: Admin, Shop, Player
- Portals use English locale and one date format. The Admin HTML lang is en, not vi. KIOSK-437Module: Locale · Portal: Admin, Super Agent, Agent, Shop, Cashier
- Dashboards accept Today, This week, This month, 7d, 30d, and a custom date range. Shop counter deposit and redemption ledgers use the same range controls. KIOSK-418Module: Dashboards · Portal: Admin, Super Agent, Agent, Shop
- The player win ticker is no longer a generated $43 sequence. Guests see nothing. Signed-in players see their own completed game-to-wallet recalls. KIOSK-439Module: Player home · Portal: Player
- Signed-out visitors no longer see ACTIVE SESSION / $0 on game cards. That badge only appears for a signed-in player with a real session. KIOSK-440Module: Player home · Portal: Player
- Admin Financials “Total Credits Issued” and Agent Network “Network Credits Issued” are named and tooled separately so the two scopes are not read as the same KPI. KIOSK-420Module: Admin Dashboard · Portal: Admin
- Super Agent Finance cards are named Credits Sold, Credit Cost, and Credit Margin, with breakdowns that add up to those totals. KIOSK-423Module: Super Agent Dashboard · Portal: Super Agent
- Browser tab title is Admin - Kiosk Gaming (was Kisok gamming). KIOSK-438Module: Admin shell · Portal: Admin
- Cash Transactions no longer renders the page header twice. KIOSK-442Module: Cash Transactions · Portal: Admin
- Admin role labels are consistent (Finance Admin, not Finance Manager) across header, tables, and permission dialogs. KIOSK-415Module: Admin roles · Portal: Admin
Known Issues
- No. 1 Payments stop halfway and never resolve — TodoModule: Payments
- No. 2 Support backlog is unattended — TodoModule: Support
- No. 3 Dashboard rollup job is not running — In Progress (KIOSK-417)Module: Dashboards
- No. 4 Frontend shows modules the backend refuses — DoneModule: RBAC
- No. 5 Roles reach areas outside their remit — DoneModule: RBAC
- No. 7 No way to edit role permissions / create System Admin — DoneModule: RBAC
- No. 9 Down providers presented as active — TodoModule: Game providers
- No. 10 Admin account changes during handover have no freeze — TodoModule: Admin accounts
- No. 14 Players cannot cancel a deposit — TodoModule: Deposits
- No. 15 A cashier cannot be given a shift — TodoModule: Cashier
- No. 18 Integration Logs does not show the full failure picture — TodoModule: Integration Logs
- No. 20 Player ledger shows money moving the wrong way — TodoModule: Player ledger
- No. 29–40 remaining medium/low items — Todo (see list below)Module: Open Defects
Affected Modules
- Agent Management
- Withdrawal Review
- Admin Audit Log
- Dashboards
- Locale and dates
- Player home
- Admin shell
- Admin accounts
Affected Portals
- Admin Portal
- Super Agent Portal
- Agent Portal
- Shop Portal
- Cashier Portal
- Player Portal
Related Jira Tickets
This note is for QA and PM. It is the 1.2.4 snapshot of Open Defects items 1–40 (list of 11 September 2026): 24 Done, 1 In Progress, 15 Todo at that release.
Each Done item says what was wrong, what you could do on screen after 1.2.4, and what to check. It does not describe how the code was written.
Items still open in 1.2.4 and later closed (or still open) are on Version 1.2.5. Do not treat a “not in this build” line below as the current production status.
1.2.1, 1.2.2, and 1.2.3 exist as placeholders and are not documented here.
Critical
1. Payments stop halfway and never resolve
Not in 1.2.4. A gateway deposit could stay Pending after the player stopped paying. Closed in 1.2.5.
2. Support backlog is unattended and every new ticket is about missing money
Not a product change. Someone must own the customer support queue (tickets are mostly “missing money”). Still open on 1.2.5.
3. Dashboard rollup job is not running
Not in 1.2.4. Admin showed “Rollup many days behind” and the gap grew every day. Closed in 1.2.5.
4. Frontend shows modules the backend refuses
Portals: Admin
What was wrong: The menu showed pages the signed-in admin was not allowed to use. Opening them failed. Reviewers thought the role was broken.
What we shipped: The menu only lists modules that admin is allowed. Pages that need a finance-only action (wallet refund, auto-refund) stay hidden unless that admin has withdrawal management. If the module is not granted, it does not appear.
What to check: Log in as each role. The sidebar matches that role's remit. Type the URL of a hidden module — access is denied. A granted module opens and its actions work.
5. Roles reach areas outside their remit
Portals: Admin
What was wrong: A role (especially Platform Admin) could still reach Players, Cashiers, Shops, or other catalog areas that were not their job.
What we shipped: Each role has a template of modules. Extra Platform Admin access to Players / Cashiers / Shops was removed. Typing the URL of a module that role does not have is denied.
What to check: Platform Admin cannot open Players / Cashiers / Shops from the menu or by URL. System Admin still can. Changing a role template (no. 7) changes what that role can open after save.
6. An Agent account cannot be terminated
Portals: Admin
What was wrong: There was no safe way to terminate an Agent in the panel.
What we shipped: Agent detail → Danger zone → Terminate agent.
Before confirm, the page lists blockers: open shops, unpaid shop funding
debt, active players. The admin must type terminate. Terminate stays
blocked until those blockers are gone.
What to check: An agent with an open shop cannot be terminated (blockers
listed). After shops / debt / players are clear, typing terminate
completes. A typo in the confirm box does nothing.
7. No way to edit role permissions, and System Admin cannot create System Admin
Portals: Admin
What was wrong: Nobody could change what a role may do. System Admin could not create another System Admin.
What we shipped: Role & Permission Management — System Admin edits View / Create / Edit / Approve / Delete / Manage per module for each lower role. System Admin's own template is full access and read-only. Save can push the template onto existing admins of that role (on by default). Create Admin includes System Admin in the role list. The Audit Log records the permission change.
What to check: Edit a lower role, save, log in as that role — menu and actions match. Create a System Admin. System Admin cannot strip their own template.
8. The owner account is not protected from deletion
Portals: Admin
What was wrong: A Super Admin could delete the owner account (or themselves) with no extra protection.
What we shipped: System Admin can mark a Super Admin as root
(owner). Only Super Admin accounts can be root. Another Super Admin can see
root / not root but cannot change it. They can delete or terminate other
Super Admins except a root account, and they cannot delete themselves.
Delete asks them to type delete and a reason (at least 10 characters).
Audit Log records grant/revoke root, delete, and terminate.
What to check: Try to delete a root account — refused. Try to delete yourself — refused. Delete a non-root Super Admin with confirm + reason — works, and Audit Log has the row.
9. Providers that are down are presented to players as active
Not in 1.2.4. Players still saw a down provider as playable. Closed in 1.2.5.
10. Admin accounts are being changed during the handover, with no audit trail
Partial in 1.2.4. Freezing accounts so nobody can edit them is still an ops decision. The Audit Log in no. 19 already records create / update / terminate / permission changes. Occupancy of empty roles is in 1.2.5.
High
11. Withdrawal review opens the whole queue
Portals: Admin
What was wrong: Opening Withdrawal Requests showed the entire history (hundreds of rows). Reviewers could not see what needed a person today.
What we shipped: The page opens on needs review only: waiting for admin, or flagged as unusual (and payouts that skipped auto-approve). The page lists the rules: new player, sudden large deposit or withdrawal, unusual activity. A later tightening for internal game-to-wallet moves is in 1.2.5.
What to check: Open the page with no extra filter. You should not see every completed payout. The flagging copy on the page matches what you see in the list.
12. Rejected withdrawals carry no reason and no audit trail
Portals: Admin
What was wrong: A rejected withdrawal did not show who rejected it, why, or when.
What we shipped: Withdrawal detail shows the rejecting admin (or Shop / System), the reason, and the time. That action is written to the admin action log.
What to check: Reject a test withdrawal with a reason. Detail shows actor, reason, time. A second admin can find the same facts without asking chat.
13. A $10 withdrawal required manual approval although the threshold is $200
Portals: Admin, Shop, Player
What was wrong: A small payout still sat in the review queue. The screen only mentioned the $200 cap, so it looked like a bug.
What we shipped: The record stores and shows the real reason a person is needed, not only the dollar cap. Typical reasons: amount at or above the auto-approve limit; Welcome Bonus still in review (every payout needs a person); unusual-profit / fraud flag; auto-approve limit is $0; automatic approval failed. Shop approval shows the same reason.
What to check: Find a small payout that needs review. The reason on the row must be one of the above, not a blank “because $200”. A clean payout under the limit with no flags should not sit in review.
14. Players cannot cancel a deposit
Not in 1.2.4. Players could not cancel an unpaid deposit. Closed in 1.2.5.
15. A cashier cannot be given a shift
Not in 1.2.4. Shop could not assign a cashier to a shift. Closed in 1.2.5.
16. The admin panel declares itself as Vietnamese
Portals: Admin, Super Agent, Agent, Shop, Cashier
What was wrong: The Admin site announced itself as Vietnamese. Dates
showed Vietnamese month labels (for example thg 9).
What we shipped: Admin language is English. Dates on Admin, Super Agent, Agent, Shop, and Cashier shift windows use the shared English format.
What to check: Browser page language is English. No Vietnamese month labels on those portals. New dates look like English months / numbers.
17. No custom date range on any dashboard
Portals: Admin, Super Agent, Agent, Shop
What was wrong: Dashboards had no way to pick an arbitrary from–to range.
What we shipped: Today, this week, this month, last 7 days, last 30 days, or a custom from–to (in the report timezone). Wired on Admin, Super Agent, Agent, and Shop dashboards, and on shop Counter deposits / Counter redemptions. Admin Cash Transactions and wallet screens as a whole waited for no. 30 in 1.2.5.
What to check: Switch each preset; figures change with the window. Custom from–to only includes those days. Shop counter lists follow the same control.
18. Integration Logs does not show the full failure picture
Not in 1.2.4. A provider could fail while the log still looked successful. Closed in 1.2.5.
19. There is no global admin audit log
Portals: Admin (Super Admin / System Admin)
What was wrong: Nobody could answer “who changed this admin / player / withdrawal?” after the fact.
What we shipped: Audit Log page: who did it, what they did, what they touched, before/after, notes, IP, time. Filter by actor, type of target, target id, action, and date range. Covered actions include create / update / terminate admin, permission changes, terminate player or agent, approve / reject withdrawal.
What to check: Perform one of those actions. A row appears with the right actor and target. Filters narrow the list. A role that is not Super / System Admin does not get the page.
20. The player ledger shows money moving the wrong way
Not closed in 1.2.4. Still open: need bug screenshots plus the exact screen and role before QA can re-test. See 1.2.5.
Medium and low
21. Public redeem ticker is generated, not real activity
Portals: Player
What was wrong: The home ticker showed fake step amounts (around $43), not real redemptions. Guests also saw masked contact details.
What we shipped: The fake ticker is gone. Guests see an empty ticker. A signed-in player only sees their own completed game → main wallet recalls.
What to check: Signed out — empty ticker, no fake dollars, no other people's emails/phones. Signed in — only that player's real completed recalls.
22. Signed-out visitors are told they have active sessions
Portals: Player
What was wrong: Game cards showed ACTIVE SESSION / $0 to people who were not logged in.
What we shipped: Balance and session state only appear for a signed-in player.
What to check: Signed out — no active session badge and no $0 wallet on game cards. Signed in — real session / balance for that player only.
23. The same KPI name shows two different values
Portals: Admin
What was wrong: Two cards looked like the same KPI but the numbers disagreed, so finance did not know which to trust.
What we shipped: They are named differently and each has a tooltip:
- Total Credits Issued (Financials) — includes online player deposits.
- Network Credits Issued (Agent Network) — network credit purchases and converts only, no online player deposits.
The Agent Network credits chart follows the network-only number.
What to check: Open both tabs for the same period. Names and tooltips disagree on purpose. Adding player deposits to the network number should land near the Financials number (same window).
24. Credits Withdrawn Back card does not exist
Portals: Super Agent
What was wrong: Super Agent Financials had no card for credits sent back up the chain.
What we shipped: Credits Withdrawn Back is on Super Agent Financials for the selected period.
What to check: After a known credit return in the period, the card moves. A period that excludes that day does not include it.
25. Outstanding Online Debt is not a headline KPI on the Super Agent portal
Portals: Super Agent
What was wrong: Outstanding online debt existed in the business but was not in the Super Agent headline row.
What we shipped: Outstanding Online Debt is a headline KPI on Super Agent Overview.
What to check: A Super Agent with known debt sees a non-zero headline that matches the debt view / ledger. Zero debt shows zero, not a missing card.
26. Three finance KPI rows are a naming mismatch
Portals: Super Agent
What was wrong: Three finance rows used names that did not match what the numbers were, and a second unofficial total confused the page.
What we shipped: One name each, no extra total:
| Card | Meaning |
|---|---|
| Credits Sold | Earned from selling credits to agents (cash + online + converts) |
| Credit Cost | Paid up the chain for credits |
| Credit Margin | Sold minus cost |
Breakdown chips add up to those cards. Credits sent back up are Credits Withdrawn Back (no. 24), not a fourth name for margin.
What to check: Sold − Cost = Margin on the same period. Chips under a card add to that card.
27. Agent Network KPIs are incomplete
Portals: Admin
What was wrong: Admin Agent Network was missing two numbers finance asked for.
What we shipped:
- Owners with Debt — how many shops / agents / super agents currently have outstanding online debt (a live count, not a period total).
- Wholesale Cash Margin — face value of credits minus the cash those super agents were expected to pay on platform → super-agent cash sales.
What to check: A known indebted owner increases the count. A cash credit sale in the period moves Wholesale Cash Margin; a period that excludes that sale does not.
28. Top Shops and Top Agents ranking charts are absent from Admin
Portals: Admin
What was wrong: Admin could not see which agents or shops bought the most credits without opening each portal.
What we shipped: Agent Network has Top Agents and Top Shops for the selected period.
What to check: A known large buyer in the period appears near the top. Changing the period changes the ranking. Empty period → empty or zero chart, not another tab's data.
29. Notifications need bulk management
Not in 1.2.4. No View all / Mark all read on the Admin bell. Closed in 1.2.5.
30. Time filters are missing on Cash Transactions and wallet screens
Partial in 1.2.4. Shop counter deposit / redemption lists got the date range with no. 17. Admin Cash Transactions and wallet screens waited for 1.2.5.
31. The browser title contains two spelling errors
Portals: Admin
What was wrong: The browser tab title was misspelled.
What we shipped: Title is Admin - Kiosk Gaming. The installed-app name matches.
What to check: Look at the browser tab on any Admin page. Same title after refresh.
32. Cash Transactions renders its page header twice
Portals: Admin
What was wrong: Cash Transactions showed the title and description twice.
What we shipped: One title / description block.
What to check: Open Cash Transactions. One heading, one description.
33. There is no version or build badge
Portals: Admin
What was wrong: QA could not tell which build they were testing.
What we shipped: The Admin footer shows the app version and build id next to Kiosk Admin © 2026.
What to check: Footer is visible on a normal Admin page. After a new deploy, the build id changes.
34. Unknown routes land silently on Player management
Portals: Admin
What was wrong: A typo in the Admin URL opened Player management with no error, so testers thought they were on the right page.
What we shipped: Unknown paths show Page not found with Go Back and Go to Dashboard.
What to check: Open a made-up Admin path. You must not land on Players. Both buttons work.
35. Role labels are inconsistent between accounts
Portals: Admin
What was wrong: The same role had different names on the header, in tables, and in permission dialogs (for example Finance Admin vs Finance Manager). Permission names looked like programmer ids.
What we shipped: One label everywhere: System Admin, Super Admin, Platform Admin, Finance Admin, Operation Admin, Support Admin. Permission dialogs use readable names (Wallet Management, not a camel-case id).
What to check: The same admin shows the same role name on header, list, and permission UI.
36. Payout limits are not shown to players, and minimum deposit is inconsistent
Not in 1.2.4. Players could not see payout limits; min deposit could disagree with Admin. Closed in 1.2.5.
37. Four of six admin roles are assigned to nobody
Not closed as a product screen in 1.2.4. After the permission work (nos. 5 / 7) this was an ops staffing question. Admin Management occupancy is in 1.2.5.
38. Agent, Super Agent and Cashier panels need a redesign
Not in 1.2.4. Redesign is still not signed off. See 1.2.5.
39. Agent portal Players tab — status unresolved
Not closed in 1.2.4. Still needs a live-data re-check. See 1.2.5.
40. Balance metrics under the period filter — not fully verified
Not closed in 1.2.4. Period filter exists (no. 17); the numbers still need a controlled money-movement test. See 1.2.5.