Skip to main content

Production Update 1.2.7

Environment:Production
Released:27 September 2026 at 11:22 UTC+7
Version:1.2.7
Status:Released
Deployment window:26 Sep 09:46 – 27 Sep 11:22
Verification:Pending Verification

Summary

Follow-up to the 23 September Open Defects retest. The role guide and the permission matrix now agree. A down provider is no longer listed as active. Unpaid expired deposits are no longer described as money that arrived.

Improved

  • Audit log and Notifications can be granted or revoked per role.Module: Role permissions · Portal: Admin
  • The public win ticker banner is hidden. Masked phone numbers and email addresses are not shown, and what remained was too little to keep the banner. The player credential email names Kiosk Gaming, and a shop that has the welcome bonus off no longer offers it.Module: Player · Portal: Player

Fixed

  • The public provider list no longer calls a provider active when deposits into that provider are closed.Module: Game providers · Portal: Player
  • An unpaid expired deposit reads Expired on the player activity page and on the admin detail. It is not called a refund, and it is not listed as money in.Module: Deposits · Portal: Player, Admin
  • A player deposit above the maximum is refused. The payout form shows the minimum, the daily maximum, the maturity window, and the manual approval threshold.Module: Deposits · Portal: Player
  • Admin Management shows which Super Admin is root, and states that Super Admin cannot delete or terminate that account.Module: Admin accounts · Portal: Admin
  • A rejected withdrawal’s audit trail shows who rejected it, when, and why.Module: Withdrawals · Portal: Admin
  • Payment transactions has the same Today / 7d / 30d / Custom range as the other money lists, and export follows that range.Module: Payments · Portal: Admin
  • A terminated agent’s own page shows Terminated, the same word as the agent list.Module: Agents · Portal: Admin

Changed

  • The role guide is the rule. View-only areas no longer grant writes, and Super Admin can list and terminate other Super Admins but cannot create admin accounts or mark root.Module: Role permissions · Portal: Admin
  • Terminating a super agent suspends its agents that are still active. Agents already terminated or already suspended stay as they are.Module: Agents · Portal: Admin

Known Issues

  • No. 15 Cashier device registration — no further change in this build. Still testing; the issue has not been found.Module: Cashier
  • No. 35 Super Agent, Agent, and Shop names differ because only Shop Management was updated. Alignment needs a more detailed requirement.Module: Navigation

Affected Modules

  • Admin accounts
  • Role permissions
  • Game providers
  • Withdrawals
  • Player ledger
  • Deposits
  • Payments
  • Notifications
  • Agents

Affected Portals

  • Admin Portal
  • Player Portal
Last updated on 27 September 2026 at 12:00 UTC+7 by Product Team

Issue status​

This pass covers the 23 September retest items that were still open or new. 18 Done, 1 still testing, 1 open.

#IssueStatus
8Owner (root) flag is visible on Admin ManagementDone
9A provider with deposits closed is not listed as activeDone
12A rejected withdrawal has an audit trailDone
15Cashier device registration on sign-inStill testing. No further change in this build. The issue has not been found
20Unpaid expired deposits are not inflow. Credit Wallets is a double-entry book, not a duplicate rowDone
21Win ticker banner is hidden. Masked phone and email are not shownDone
35Super Agent, Agent, and Shop use different namesOpen. Only Shop Management was updated. Alignment needs a more detailed requirement
36Deposit maximum, and payout limits on the formDone
41Role guide and permission matrix agreeDone
42Terminating a super agent suspends its active agentsDone
43An unpaid expired deposit has one statusDone
44No welcome bonus when the shop has it offDone
45Audit log and Notifications are on the permission matrixDone
46Root is explained on the account. No separate code changeDone
47Payment transactions can be limited to a periodDone
48Player credential email names Kiosk GamingDone
49A refused page and an unknown page are not the sameDone
50A terminated agent’s page uses the same status word as the listDone
51A terminated agent cannot be moved to a super agentDone
52Credit Wallets prints its heading onceDone

8 and 46. The owner account is visible​

Where: Admin → Admin Management, and Audit log

Previous issue: Deleting your own admin account was already blocked, and a delete of someone else already asked for a reason. The owner (root) flag existed only as Grant root and Revoke root in the audit log. No row showed who held it, so the protection could not be seen without trying to delete the owner.

What we did: Admin Management shows the root flag on the list and on Manage. The rule is stated on the account, so it does not have to be proved by a delete.

After the update: The admin list has a Root column: Root or Not root. Root applies only to a Super Admin. New admins are created not root.

On Manage, a root account states that Super Admin cannot delete or terminate it. System Admin can still delete it, and can Mark as root or Remove root. Super Admin sees the same sentence and the status, and has no mark or remove control. Super Admin delete of a root account is refused. Nobody can delete their own account.

Grant root and Revoke root in the audit log are this flag. Each one records who changed it and the before/after value.


9. A provider with deposits closed is not listed as active​

Where: Player app → game lobby, and the public provider list

Previous issue: On 24 September the new player client already hid a deposit when a provider was down. The public provider list still reported those providers as active, so back office and reports did not match the lobby.

What we did: The public provider list now follows the same health check as the lobby. An enabled provider whose deposits are closed is not reported as active.

After the update: A provider with deposits closed shows as deposits closed, with its health and with deposits marked closed. A provider that is actually up stays active. The stored setup of the provider is unchanged; only the public reading of it changes.


12. A rejected withdrawal has an audit trail​

Where: Admin → a rejected withdrawal

Previous issue: The row already showed the review reason, and the detail already showed who rejected it and why. The panel’s own Audit trail still read “No audit events recorded.”

What we did: The audit trail is filled from the rejection on that withdrawal.

After the update: A rejected withdrawal’s audit trail shows the rejection: who rejected it, when, and the reason. It no longer reads as an empty gap when the rejection itself is on the record.


20. Money that never arrived is not inflow​

Where: Player → activity (Funds in), and Admin → Credit Wallets

Previous issue: The sign on a wallet deposit was already correct, and an unpaid deposit did not credit the wallet. After that deposit expired unpaid, Funds in still listed it, so money that never arrived counted as inflow. On Credit Wallets, one transfer appeared as two rows. That looked like a duplicate. The before/after balance did not say which wallet it belonged to.

What we did: Funds in leaves out unpaid expired deposits. Credit Wallets names the owner of each row, and the before/after balance is that wallet’s balance. The two rows stay. They are the ledger, not a duplicate.

After the update: An unpaid deposit that expires does not appear in the player’s Funds in list. Choosing the Expired status still finds that row. A deposit that really did return held credits stays visible and still says so.

Credit Wallets is a double-entry book. One transfer is written twice on purpose: one row for the payer (the wallet that sent) and one row for the payee (the wallet that received). Each row names its owner, for example Shop or Player, and shows that wallet’s balance before and after. The two rows are one transfer seen from both sides. They are not two copies of the same line.


21. The public win ticker is gone​

Where: Player app → lobby, signed out or signed in

Previous issue: When there were no real wins, the lobby still showed a ticker. The amounts stepped by 43 and the game names followed the lobby order. The rows also showed masked phone numbers and email addresses. Those contact details are not allowed on a public banner, masked or not.

What we did: With phone and email removed, the banner had too little left to show. The win ticker banner is hidden.

After the update: The lobby does not show a win ticker. There is no banner of amounts, game names, or masked phone numbers and email addresses.


36. Deposit maximum, and payout limits on the form​

Where: Player app → deposit, and payout

Previous issue: A deposit below the minimum was already refused. There was no maximum: a very large amount still reached Pay now. The payout form did not show the daily maximum, the maturity window, or the manual-approval threshold.

What we did: A per-transaction deposit maximum is applied and shown. The payout form prints the limits already configured for that player.

After the update: The deposit screen shows the minimum and the maximum. An amount above the maximum does not continue, and the deposit itself is refused. Unless Admin transaction limits set another positive maximum, the cap is $5,000 per transaction.

The payout form shows the minimum payout, the daily maximum, how long funds must mature, and the amount above which a payout needs manual approval. Those figures follow the Admin configuration for that shop.


41. The role guide and the permission matrix agree​

Where: Admin → Admin Management role guide, and Role & Permission Management

Previous issue: The role guide told staff what each role may do. The live matrix granted more than the guide, always in the same direction: writes where the guide said view, and full Admin Management for Super Admin where the guide said Super Admin cannot manage admin accounts.

What we did: The guide is the rule. Default matrix cells that were still a full grant were narrowed to match it. A cell a System Admin has already edited is left as edited. A write on a view-only module is refused.

After the update:

RoleAreaAfter this update
Platform AdminTransactions, Wallet, Transaction limitsView only
Operation AdminWalletView only
Support AdminUsers / players, TransactionsView only
Super AdminAdmin accountsView, Edit, and Delete. Not Create

Super Admin can list other admins and can terminate or delete another Super Admin who is not root. Super Admin cannot create admin accounts, change roles, reset passwords, or mark root. Those stay with System Admin. Super Admin still cannot void a cash settlement.

The guide on Admin Management says the same thing: View means only View is checked, and Super Admin on admin accounts is View, Edit, and Delete.


42. Terminating a super agent suspends its active agents​

Where: Admin → Agents, terminate a super agent, then reactivate an agent under it

Previous issue: Terminating a super agent left its agents in two states. Some were terminated with the parent. Some were only suspended. Nothing on the agent said the parent was terminated, and the reactivate confirmation did not mention the parent.

What we did: One rule going forward: terminating a super agent suspends every managed agent that is still active. It does not terminate them. Agents already terminated stay terminated. Agents already suspended stay suspended. The parent and those suspends are saved together. The reactivate confirmation names the parent’s state.

After the update: A new termination suspends the active agents under that super agent. Older rows that were already terminated or suspended are not rewritten. Reactivating a suspended agent whose super agent is terminated asks, in substance: that super agent is terminated; do you still want to reactivate this agent. If the parent is suspended, the confirmation says that too.


43. One expired deposit, one status​

Where: Admin → Payment transactions (list and detail), and Player → activity

Previous issue: One unpaid deposit that expired on its own was read three ways at once. The admin list said Expired. The player page said Expired – Refunded. The admin detail still said Pending, with the action Credits received, which reads as if the money arrived.

What we did: The detail uses the same status as the list, and the wording says what happened. An expiry with no payment is not called a refund.

After the update: An unpaid deposit that expires says Expired on the admin list, the admin detail, and the player activity page. The detail says no payment was received and nothing was credited. It does not say Pending, and it does not say Credits received.

Expired – Refunded remains only when credits that had been held were actually returned to the wallet. The player detail says that in words: no payment was received, so nothing was added; or the held credits were returned.


44. No welcome bonus when the shop has it off​

Where: Player app → first sign-in

Previous issue: The welcome-bonus window opened for every new player, including a shop that has the bonus switched off. The warning sat above a button that was still enabled.

What we did: The offer is hidden when the shop has not opted in, or the bonus is switched off for the platform.

After the update: A player whose shop has the bonus off does not see the welcome-bonus window or the claim button. A bonus the player has already claimed stays visible. Other blocks (shop debt, daily budget, or a bonus that is no longer claimable) do not advertise a button that cannot succeed.


45. Audit log and Notifications are on the permission matrix​

Where: Admin → Role & Permission Management

Previous issue: The matrix did not include Audit log or Notifications. Audit log was hidden for Operation Admin by a fixed rule, so nobody could grant read access without promoting the account to Super Admin or System Admin.

What we did: Both areas are modules on the matrix, and the menus follow those cells.

After the update: Audit log and Notifications can be granted or revoked per role. By default, Audit log is view for Super Admin and System Admin. Notifications is view for Finance, Operation, Platform, and Support. Sending notifications stays with the roles that have that write. System Admin can change those cells; the change is what the menu and the page then follow.


47. Payment transactions can be limited to a period​

Where: Admin → Payment transactions

Previous issue: USD Wallets, Credit Wallets, Cash Transactions, and the dashboards already had a date range. Payment transactions, the largest list, had type, status, gateway, search, and export, and no period. An export could not be limited to a window.

What we did: The same period control was added, and the list and the export both use it.

After the update: Payment transactions has Today, 7d, 30d, and Custom. The page opens on 30 days. Export follows the period on the screen. A custom end date that is a calendar day includes that whole day.


48. The player credential email names the player site​

Where: Admin → re-issue a player’s login. The password is emailed, not shown on screen.

Previous issue: The email told the player they could sign in to Kiosk Shop. The recipient signs in on the player site. The shop name is the shop the account belongs to, not the sign-in destination.

What we did: The email names Kiosk Gaming as the place to sign in, and names the shop as the account’s shop. English and Spanish both say that.

After the update: The email says the player can sign in to Kiosk Gaming, and that the account is with that shop. The shop name is no longer the sign-in destination.


49. A refused page and an unknown page are not the same​

Where: Admin, and the player app

Previous issue: In Admin, a page the role cannot open sometimes showed Access Denied, and sometimes landed on Player management with no message. On the player app, an unknown finance address sent the player home instead of a not-found page.

What we did: A known page the role cannot open goes to Access Denied. An address that is not a page goes to not found.

After the update: In Admin, opening a page outside the role (including by typing the address) shows Access Denied, with the path that was requested, and a way back. It does not open Player management. On the player app, an unknown address stays on a not-found page. It does not redirect home.


50. A terminated agent’s page uses the same status word​

Where: Admin → Agents, the agent’s own page

Previous issue: The agent list shows Terminated. The header on that agent’s page shows Inactive.

What we did: The header uses the agent’s status, the same word as the list.

After the update: A terminated agent’s page reads Terminated. A suspended agent reads Suspended. An active agent still reads Active.


51. A terminated agent cannot be moved​

Where: Admin → Agents, row menu on a terminated agent

Previous issue: Suspend, Terminate, and reactivate were already gone from a terminated agent. Move to super agent was still offered. Moving an account that has been ended has no meaning.

What we did: The action is hidden, and the move is refused if it is sent anyway.

After the update: A terminated agent’s row menu does not offer Move to super agent. View remains. An active or suspended agent can still be moved when a super agent exists to move them to.


52. Credit Wallets prints its heading once​

Where: Admin → Credit Wallets

Previous issue: Cash Transactions had already stopped printing its title twice. Credit Wallets still printed “Credit transactions” as both the section title and the card title.

What we did: The second heading was removed.

After the update: Credit Wallets shows the heading once.


Not in this build​

These two are still open. They are not closed by 1.2.7.

15. A cashier still cannot be given a shift​

Where: Shop → Cashiers → Devices, and Create Shift

Previous issue: On 23 September, Create Shift still needed an approved device, and cashier sign-in did not register one. Devices stayed at zero, so no shift could be created.

What we did: No further change in this area in 1.2.7. We are still testing it, and we have not found the issue.

After the update: The Shift Schedule screen is the same as in 1.2.5. This item stays open while that testing continues.

35. The same list still has a different name in each portal​

Where: Admin, Agent, and Shop sidebars

Previous issue: The old role nicknames (Finance Manager, and the rest) no longer appear. What remains is the section names: the payment list is “Payment transactions” in Admin, “Transactions” in Agent, and “Money Transactions” in Shop. The landing page is “Dashboard” in Admin and “Home” in Agent and Shop. Inside Agent, the super-agent role is written three ways.

What we did: No label change in this build. The inconsistency between Super Agent, Agent, and Shop is due to a recent enhancement that was applied to Shop Management only.

After the update: Super Agent, Agent, and Shop still use their current names. To align them, a more detailed requirement is needed.