feat(api): keyless GET /api/v1/public/bookings/{id} for guests

The guest cannot subscribe to the operator's wallet and the existing
booking read needs a wallet invoice key, so a client had no way to wait
for awaiting_payment -> confirmed over HTTP short of polling the invoice
on LNbits core. Add the HTTP twin of the RPC door's chatelet_booking_get:
the 10-char booking id from the quote is the capability, and the response
is public_booking_dict — lifecycle, dates and money only, with the guest's
pubkey/contact and the Lightning/Nostr plumbing stripped.

Closes #18

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-09-15 23:43:21 +02:00
commit 94542ad0f9
4 changed files with 106 additions and 2 deletions

View file

@ -208,6 +208,25 @@ def public_room_dict(room: Room) -> dict:
class AvailabilityQuery(BaseModel):
room_id: str
def public_booking_dict(booking: "Booking") -> dict:
"""A Booking as public JSON for the guest who holds its id — lifecycle +
money + dates only. Strips the guest's own identity/contact (so the id
alone can't be turned into PII) and the internal Lightning/Nostr
plumbing. The 10-char id from the quote is the capability here, the same
trust level as the RPC door's chatelet_booking_get; chatelet_booking_get
additionally scopes by sender_pubkey, which HTTP can't."""
d = json.loads(booking.json())
for k in (
"guest_pubkey",
"guest_contact",
"payment_hash",
"request_event_id",
"reservation_event_id",
):
d.pop(k, None)
return d
check_in: str # YYYY-MM-DD inclusive
check_out: str # YYYY-MM-DD exclusive