Skip to content

Permissions ​

FluentBooking does not use WordPress roles for its own authorization. It stores a list of permission sets per user (in fcal_meta under _access_permissions) and checks those; a user with manage_options is treated as having all of them.

Permission sets ​

SetGrants
manage_own_calendarManage only own Calendar, Events, Bookings & Availability
read_all_bookingsRead Access to All Bookings
manage_all_bookingsRead & Write Access to All Bookings
read_other_calendarsRead Access of Other Users Calendars
manage_other_calendarsManage Other Users Calendars
read_and_use_other_availabilitiesRead & Use Access of All Availabilities
manage_other_availabilitiesManage All Availabilities
manage_all_dataManage All Data and Settings
php
use FluentBooking\App\Services\PermissionManager;

if (PermissionManager::userCan(['manage_all_bookings', 'manage_all_data'])) {
    // Any one of the listed sets is enough.
}

REST policies ​

Every route group declares a policy; the policy's verifyRequest() runs before any of its per-method checks. The sets and capabilities below are the ones each policy class actually references.

A policy with no routes is not attached to any route group — it exists for a surface that does not use it (yet). A set marked with * is referenced by a policy but is not one of the sets above, so nothing ever grants it.

PolicyEditionRoutesPermission setsWordPress capsChecks used
AdminPolicyCore3——canManageOtherHosts()
AvailabilityPolicyCore9manage_all_data, manage_other_availabilities, manage_own_calendar, read_and_use_other_availabilities——
CalendarEventPolicyCore7manage_all_bookings, manage_all_data, manage_other_calendars, read_other_calendars——
CalendarPolicyCore49invite_team_members*, manage_all_data, manage_own_calendarmanage_optionscanReadCalendar(), canUpdateCalendarEvent(), canWriteCalendar(), currentUserHasAnyPermission()
MeetingPolicyCore20manage_all_bookings, manage_all_data, manage_own_calendar, read_all_bookingsmanage_optionsuserCanSeeAllBookings()
PublicPolicyCore0———
SettingsPolicyCore25manage_all_data——
SuperAdminPolicyPRO5—manage_options—
UserPolicyCore3——currentUserHasAnyPermission()

MCP gates ​

The MCP server authorizes through PermissionGate instead of a policy. Read abilities need only a working transport (MCP enabled, application-password auth); write abilities additionally need one of the listed sets.

GateRequires one ofAbilities
bookingWriteGate()manage_own_calendar, manage_all_bookings, manage_all_datacreate-booking, manage-booking
readGate()transport onlydaily-briefing, diagnose-availability, get-availability, get-available-slots, get-booking, get-booking-context, get-event-types, get-payments, list-bookings, list-reference-data, query-bookings, troubleshoot-event, weekly-report
scheduleWriteGate()manage_own_calendar, manage_other_calendars, manage_other_availabilities, manage_all_datamanage-availability, manage-event-type

Parsed from fluent-booking/app/Services/PermissionManager.php and app/Http/Policies/.