List availability-override requests
/api/availability-overridesStaff sees only their own linked provider's rows (server-forced, ignoring any client filter; there is none to send); admin sees every row across every status, so this one endpoint powers both a "needs attention" view (filter client-side on status: pending, or approved with conflictAcknowledged and conflictCount > 0) and a full history view.
conflictCount is recomputed live on every call for an admin caller (always 0 for staff); migration 0052 deliberately does not persist which appointments conflicted, so a later cancellation or reassignment through the ordinary calendar screen makes a row stop needing attention with no write required.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Response Body
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/api/availability-overrides"{ "overrides": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "providerId": "4834bcdc-4a64-444d-966b-1a6fe381da24", "providerName": "string", "overrideDate": "2019-08-24", "windows": [ { "startTime": "string", "endTime": "string" } ], "reason": "string", "status": "pending", "requiresApproval": true, "autoApplyReason": "trusted_tier", "createdByRole": "admin", "createdAt": "2019-08-24T14:15:22Z", "reviewedAt": "2019-08-24T14:15:22Z", "decisionNote": "string", "conflictAcknowledged": true, "conflictCount": 0 } ]}Remove a time-away entry (admin, or manage_staff) DELETE
The provider's ordinary hours (and any approved date-specific override) apply again over that range immediately. Scoped to both `id` and this provider: a bare id match would let a caller delete a whole-venue closure or another provider's entry by reusing a uuid from the same table.
Cancel or reject an availability-override request PATCH
Two plain status transitions on a `pending` row: `cancelled` (the staff member who owns the linked provider, on their own row, or any admin) and `rejected` (admin only). `approved` is deliberately refused here even though the request shape alone would not stop it; it is a special action (POST .../approve), same rule PATCH /api/waitlist/{id} enforces for `notified`. `superseded` is never client-settable at all. Both transitions call a SECURITY INVOKER database function (`book_cancel_availability_override` / `book_decide_availability_override`, migration 0052) rather than writing the row directly; this table has no update policy for `authenticated` at all, so a raw PostgREST update would be refused the same way from anywhere else. The functions re-check role/ownership themselves from the database; this route's own gates are the ordinary UX path, not the enforcement.