Public booking-status endpoint for guests #18

Closed
opened 2026-09-15 21:21:11 +00:00 by padreug · 0 comments
Owner

GET /api/v1/bookings/{id} requires a wallet invoice key, so a guest can't read back their own booking over HTTP. The webapp's booking dialog (aiolabs/webapp feat/chatelet-booking) works around it by polling LNbits core's anonymous GET /api/v1/payments/{hash}, which only says "paid", not "confirmed".

Proposal: GET /api/v1/public/bookings/{id} returning status, room_id, check_in, check_out, nights, deposit_sat and expires_at — no guest_contact or pubkey. The booking id is a 10-char short hash the guest received in the quote, which is the same trust level as the RPC door's chatelet_booking_get (there the sender_pubkey scopes it; over HTTP the id itself is the capability).

When it lands, the webapp swaps its poll target and can show hold-expired / declined states instead of inferring them.

GET /api/v1/bookings/{id} requires a wallet invoice key, so a guest can't read back their own booking over HTTP. The webapp's booking dialog (aiolabs/webapp feat/chatelet-booking) works around it by polling LNbits core's anonymous GET /api/v1/payments/{hash}, which only says "paid", not "confirmed". Proposal: GET /api/v1/public/bookings/{id} returning status, room_id, check_in, check_out, nights, deposit_sat and expires_at — no guest_contact or pubkey. The booking id is a 10-char short hash the guest received in the quote, which is the same trust level as the RPC door's chatelet_booking_get (there the sender_pubkey scopes it; over HTTP the id itself is the capability). When it lands, the webapp swaps its poll target and can show hold-expired / declined states instead of inferring them.
padreug referenced this issue from a commit 2026-09-15 21:53:19 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/chatelet#18
No description provided.