Chatelet is multi-tenant: any LNbits user can host rooms. What an operator
decides for all their rooms now lives in chatelet.operator_settings, keyed
by user id and created lazily (m003, which also indexes bookings by guest):
check-in/out times, cancellation policy, and accept_fiat.
Guests see it: the public room view (both doors) gains house_rules and
payment_methods, and the kind:30402 listing carries payment_methods,
checkin_time and checkout_time tags so a generic Nostr client can render
the right pay buttons and rules without our RPC. The check-in DM reads the
room owner's rules instead of the instance row.
Card is offered only when the operator opted in, the room is fiat-priced,
and LNbits core has a fiat provider for that user — resolved through
settings.get_fiat_providers_for_user(owner), the one seam lnbits#67's
per-user Stripe credentials will plug into; chatelet never sees creds.
Operator endpoints: GET/PUT /api/v1/operator (admin key → wallet user) and
RPC twins chatelet_operator_get/update (AUTH_WALLET); saving re-publishes
the owner's active listings. Admin UI moves the house-rule inputs into a
per-operator card with the card toggle and a provider hint. The old
house-rule columns on settings stay for old rows but are no longer read.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
GET /api/v1/public/rooms/{id}/unavailable?start=&end= and its RPC twin
chatelet_room_unavailable return the nights a guest cannot book over a
window (default today → +365 d, capped at 400 d): occupying bookings —
live holds included, so the feed always agrees with POST /availability —
and manual blocks, clipped, sorted and coalesced into anonymous half-open
spans. Adjacent spans merge on purpose so a guest cannot tell where one
occupant's dates end and the next begin, nor a block from a stay.
is_available now uses the OCCUPYING_STATUSES constant it was inlining.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
v0.4.0's merge of public_booking_dict landed inside AvailabilityQuery and
left the two date fields orphaned after the helper's return, so
POST /api/v1/availability raised AttributeError on q.check_in (500) on
every install of that version. The RPC door reads the raw body and was
unaffected, which is why nothing noticed.
Put the helper next to public_room_dict and add a regression test that
constructs the query model and drives the endpoint through the
services layer.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The guest cannot subscribe to the operator's wallet and the existing
booking read needs a wallet invoice key, so a client had no way to wait
for awaiting_payment -> confirmed over HTTP short of polling the invoice
on LNbits core. Add the HTTP twin of the RPC door's chatelet_booking_get:
the 10-char booking id from the quote is the capability, and the response
is public_booking_dict — lifecycle, dates and money only, with the guest's
pubkey/contact and the Lightning/Nostr plumbing stripped.
Closes#18
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The AUTH_NONE RPC room endpoints (chatelet_room_list/_get) stripped wallet
but NOT checkin_instructions — which was added in #5 after this code, so the
operator's private access details (address, gate code) were leaking to any
guest. Centralize a public_room_dict(room) helper (strips wallet +
checkin_instructions) and route both doors through it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019VUQCfdqiLSsFS2jcGnaFD
Private per-room access details (address, gate/door code). Sent to the
guest only in the encrypted check-in DM after payment — never in the
public listing. m002 adds the column (default '').
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019VUQCfdqiLSsFS2jcGnaFD
Booking requests now complete end-to-end over HTTP:
- _to_sats() converts fiat->sats via fiat_amount_as_satoshis (sat/sats
pass through). This is the single conversion point; the result is the
canonical amount_sat and is not recomputed downstream.
- api_request_booking creates a sats-denominated deposit invoice (locked
amount, immune to FX drift before payment), tagged {tag:chatelet,
booking_id} so tasks.on_invoice_paid matches the settle. On InvoiceError
the hold is released (status=declined) so dead holds don't block dates.
- New BookingQuote response returns the held booking + bolt11 + hash.
Settlement (tasks.on_invoice_paid: awaiting_payment -> confirmed, dates
hard-blocked, reservation republished) was already in place and now fires
on real payments. Testable on FakeWallet.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019VUQCfdqiLSsFS2jcGnaFD
Pydantic entities: ChateletSettings (operator/castle config), Room (a
rentable unit == one NIP-99 listing), Booking (a reservation), Block
(manual owner unavailability), plus availability query/result DTOs.
Two invariants encoded here: amount_sat is the canonical booking total
(never re-derived downstream), and availability is derived, never stored.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019VUQCfdqiLSsFS2jcGnaFD