News & guides · Release notes
FlightDesk 1.4.1: a security release
A thorough security review of FlightDesk, and the changes it led to — from sign-in protection to how dispatch handles meter readings.

Your members trust you with their medical dates, contact details and account balances. You trust us with the software that keeps them. So before adding new features, we put FlightDesk through a top-to-bottom security review — every page, every action, every permission.
Version 1.4.1 is the result. Here’s what changed, in plain English.
Signing in
- Repeated wrong passwords are slowed down per network and per account — but nobody gets locked out. A browser that has signed in to an account before keeps working, even if someone else is guessing.
- Sessions now end after a period of inactivity, and changing a password signs out every other device.
- Old password-reset links stop working as soon as the password changes.
- Common passwords are refused.
Who can do what
- Front-desk staff can only manage people whose access is within their own — they can’t reset an administrator’s password or change their sign-in email.
- Membership requests can’t ask for more access than the person approving them has.
Dispatch and billing
- Hobbs and tach readings at dispatch have to pick up where the last flight ended. A gap needs someone who can override dispatch, and it’s recorded on the flight.
- Check-ins can’t add more time than has passed since the flight started.
- The aircraft rate is locked when the flight is dispatched.
Around the edges
- Lobby TV screens use a read-only display link instead of a signed-in staff account.
- Spreadsheet exports neutralise formulas, and calendar feeds can’t be tampered with through booking notes.
- Two people booking the same airplane at the same moment can no longer both succeed.
Every FlightDesk school gets these changes automatically.

