Developer blog ·
Booking a meeting is easy. Clearing up after it is the work.
SimpleScrumTools now books the Sprint Review and the Daily Scrum when a sprint starts. Most of the work went into the sessions nobody uses, and into what our testing found before release.
This week SimpleScrumTools started booking Scrum Events on its own. When a sprint becomes Active, the product puts the Sprint Review on the final Friday. If the team asks, it also puts a 15-minute Daily Scrum on every weekday. The booking was the small part. Most of the follow-up work went into what happens to a booked session that nobody uses.
Book once, at activation
We considered two designs. One was an hourly job that keeps each sprint’s calendar full. The other books everything in the same database transaction that activates the sprint. The job looked friendlier, because a setting changed mid-sprint would apply at once. But a job cannot tell a session that someone cancelled on purpose from one that was never booked. A tool that books a meeting you just cancelled is worse than a setting that waits a sprint. We chose activation.
Every time is the team’s wall clock. A Daily Scrum at 09:15 stays at 09:15 across a daylight-saving change in the middle of the sprint. We test that rule in Los Angeles in November and in Sydney in October, because UTC never changes its clocks.
A row you book is a row you must retire
Adding rows was easy. Then we followed one booked Daily Scrum through a sprint that ended early. The board shows only the Active sprint, and the board is the only place a Daily Scrum opens. So Thursday’s and Friday’s sessions could never open, and they would read “scheduled” forever.
We now cancel a sprint’s unopened Daily Scrums when someone ends, closes or cancels it. We do not cancel Reviews or Retrospectives at that point, because a team can hold either one after the sprint is over. A Review leaves the calendar in two cases instead: when the team opens a different Review for the same sprint, or when the next sprint starts. Every cancellation writes a line in the activity feed with its reason, so nothing disappears without a record.
The test run that found three more problems
Before release we run a 288-check function test against the hosted development copy. It uses throwaway accounts and the real HTTP routes, then deletes everything it made. The suite had passed: 3,398 tests, with the integration tests running against a real Postgres. The function test still found three problems that only show up in a running app. The first was a booked Review that stayed “scheduled” after the team ran its own. The second was a Review screen that opened on the wrong sprint. The third was a set of controls that were too small to tap on a phone. A green suite tells you that the code does what the tests ask. It does not tell you that the product does what a team needs.
The security review
We paired the function test with a security review of everything not yet in production. It found one real problem, and it was older than this week’s work: a pre-account takeover. That is a known class of defect for any site that lets you sign in either with a password or through a provider such as Google.
It came to light now because this release adds GitHub as a sign-in option. The review went through the step that links a provider sign-in to an existing account, and the defect was in that step. Google sign-in uses the same step, and has since SimpleScrumTools went live, so the defect was in production until this release. GitHub sign-in reaches production with the fix already in place. We tested the fix through the real sign-in routes, with and without the change.
That is all we will say about how the defect worked. If you have a question about your account, contact us.
How we test the tests
For each change this week we broke the code on purpose, one line at a time, and checked that a test failed. The security fixes took 18 such breaks, and in the end a test caught all 18. The first run let one through. In that test the second account had nothing to lose, so a change that reached every account instead of one still passed. We gave it something to lose, and the test caught the change.
Two other breaks this week got through because another check already covered the line we broke. We removed one redundant line, and wrote down why the other one stays. When a break gets through, we record it with the reason, so nobody assumes it was covered.
SimpleScrumTools is free for teams of up to 5 members, with no card required. Create a free account.
Release notes for October 2, 2026
Scrum Events now book themselves, the product has a new look, and this release includes a sign-in security fix. Your data does not change, and you do not have to set anything up.
Scrum Events book themselves
- The Sprint Review is booked when a sprint starts. It goes on the final Friday of the sprint at 13:00 in the team’s timezone, and it runs one hour for each week of the sprint. You can change the time with the new Sprint Review time setting. To turn it off, clear Book the Sprint Review automatically.
- The Daily Scrum can be booked too. Turn on Book the Daily Scrum automatically. Each weekday of the sprint then gets a 15-minute Daily Scrum at your Daily Scrum time.
- The board knows the Daily Scrum for today. It says “Booked for 09:15 today”, and Start Daily Scrum opens that session.
- Open and close the Sprint Review on its own screen. Before this release, only the Daily Scrum had a screen to start it from.
- Sessions that will not happen are cleared away. When you end, close or cancel a sprint, its Daily Scrums that never opened are cancelled. A booked Review is cancelled when the team opens a Review of its own, or when the next sprint starts.
- The Sprint Review and Retrospective screens open on the current sprint.
Booking happens one time, when the sprint becomes Active. If you change a setting during a sprint, the change applies from the next sprint.
A new look
- The SimpleScrumTools mark and typeface across the product, with navigation that starts from your projects.
- Project cards show the running sprint, how many points are done, and whether the sprint is on track.
- Board: every card has a Move button, and on a phone you can press and hold a card. Phones show one column at a time. A new setting, Show Drafts on the board, adds a Draft column.
- Sprint Planning: pick the sprint one time, then add each item with one button. A bar shows planned points against the cap of the sprint.
- Product Backlog: only High and Critical items get a priority pill. Sizes read as you wrote them, for example 3 or 0.5.
- Every button and link is at least 44 pixels tall on a phone.
- Sign up on its own page. GitHub joins Google as a sign-in option.
- This developer blog, linked from the footer of every public page.
Fixes
- Sign-in security. Our security review before this release found a pre-account takeover defect in the step that links Google sign-in to an existing account. This release fixes it. GitHub sign-in is new in this release, and the fix was in place before it reached you. If you had not yet confirmed your email address, your password stops working the first time you sign in with Google or GitHub. Use Forgot password to set a new one. Your projects and settings do not change.
- Staying signed in. With several tabs open, waking the computer could sign you out on every device. Now only the one out-of-date request is refused.
- Board cards show item sizes as numbers, so “5.00” now reads “5”.