Rock Tech Bulletin

Your go-to source for key updates, alerts, and notes on Rock releases—covering features, fixes, and critical changes that may impact your system.

Alert

Server Model Validation

Summary

Starting with Rock 17.9, 18.5, 19.5, and 20.0, Server Model Validation is a powerful new security feature for Rock, and we're excited about what it does for you. Instead of adding a patchwork of protections in every place data is entered, we've created a single point that ensures the data entered is safe, a genuine win for your data's security.

While this is a great, powerful feature, it does come with some risk of breaking existing customizations you might have, so we're shipping it turned off initially. That gives you a window to review and validate first, then flip the switch yourself once you're confident it's clean. Heads up though: we'll be turning it on for you soon in an upcoming release, so we'd encourage you to take this seriously and get ahead of it now: this closes real, identified security gaps, not just hypothetical ones.

This protection is controlled by a single setting, Enable Server Model Validation. While it is off, Rock still performs every check, but instead of blocking the save it writes an entry to the Exception Log and lets the save go through. That gives you a safe window to find and fix problems before anything is enforced.

Our recommendation: review your Exception Log, resolve what you find, and then turn the setting on. In the near future, this setting will be removed and validation will always be on, so doing the work now means the change is a non-event when it arrives.

Why It Matters

Information entered into Rock gets shown in many places: staff pages, your website, emails, and the mobile app. Most fields are meant to hold simple text, like a name or a title. When a field ends up holding something other than what it was designed for, it can cause problems, and in some cases it can be misused by people with bad intentions.

Turning validation on gives you:

  • Stronger security. Rock makes sure each field only accepts the kind of content it was designed for. This closes off a category of risks that would otherwise depend on every screen and every process being perfect.
  • Cleaner data. Names, titles, and other simple fields stay simple, so they look right wherever they appear.
  • Protection everywhere. The check happens at the moment information is saved, so it applies no matter how the information came in: a staff member, a website visitor, a workflow, an integration, or an import.

What Changes When You Turn It On

Setting off (today)Setting on
Invalid content is savedYesNo
An Exception Log entry is createdYesUsually
The person saving sees an errorNoYes, the save fails

In short: anything showing up in your Exception Log today will become a failed save once the setting is on. Fixing those entries first is what makes the switch painless.

How to Get Ready

  1. Confirm your version. You need Rock 17.9, 18.5, 19.5, 20.0, or a later release in the same version line.
  2. Review and fix. Over a few weeks, check your Exception Log for validation entries and resolve them. Most are quick settings changes.
  3. Turn it on. Check Enable Server Model Validation on the Security Settings page, then restart Rock.

For the full walkthrough, including exactly what to look for and how to fix each entry, check out Server Model Validation: Fixing Exception Log Entries, a blog post on the Rock community site. It's a great resource for understanding this in depth and knowing exactly what to do next.

If Something Goes Wrong

If an important process starts failing after the setting is turned on, uncheck the setting and restart Rock to return to log-only mode. Fix the underlying issue, then turn it back on. This is a temporary safety valve: in the near future, this setting will be removed and validation will always be on.