Appointments engine

Read one repeat series and its visits

get/api/booking-series/{id}

The series row plus every book_appointments row it generated, in date order, each with its OWN current status, not just the ones still upcoming. What the "End series" confirm step (BookingDetailDialog) reads to say how many visits are actually about to be cancelled, versus already past or already cancelled individually; that distinction needs the full list, not a second round trip filtered ahead of time.

Authorization

sessionCookie
sb-qxrvgfkjyvbngipqvslu-auth-token<token>

The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.

Every request re-validates it against the Auth server (getUser()), never by decoding the cookie locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified app_metadata.company_id claim and enforced by row-level security; it is never read from request input, on any route, ever.

role (admin / staff) is deliberately not in RLS. It gates specific actions in route code, the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's own check is the enforcement.

In: cookie

Path Parameters

id*string

book_booking_series id.

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/api/booking-series/string"
{  "series": {    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",    "status": "active"  },  "visits": [    {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "starts_at": "2019-08-24T14:15:22Z",      "status": "pending"    }  ]}