Public booking-status endpoint for guests #18
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
GET /api/v1/bookings/{id} requires a wallet invoice key, so a guest can't read back their own booking over HTTP. The webapp's booking dialog (aiolabs/webapp feat/chatelet-booking) works around it by polling LNbits core's anonymous GET /api/v1/payments/{hash}, which only says "paid", not "confirmed".
Proposal: GET /api/v1/public/bookings/{id} returning status, room_id, check_in, check_out, nights, deposit_sat and expires_at — no guest_contact or pubkey. The booking id is a 10-char short hash the guest received in the quote, which is the same trust level as the RPC door's chatelet_booking_get (there the sender_pubkey scopes it; over HTTP the id itself is the capability).
When it lands, the webapp swaps its poll target and can show hold-expired / declined states instead of inferring them.