Reorder service groups
/api/service-groupsThe body is the full shelf in its new order, and position in the array IS the new sort_order. Idempotent; an id that is not this org's simply matches zero rows under RLS. One request and one cache bust per drag session, rather than one per step.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/api/service-groups" \ -H "Content-Type: application/json" \ -d '{ "ids": [ "6e0346a3-e54d-40e3-9779-4ba1e707e35b" ] }'{ "ok": true}Create a service group POST
A named shelf services hang off on the public page (migration 0054); "Hair Colouring", "Mens Cuts"; with an optional photo and colour. New groups land at the end of the order (`sort_order = max+1`). Busts the cached public booking config.
Update a service group PATCH
Full replacement of the group's editable fields, same PATCH-in-name-only semantics as PATCH /api/services/{id}. RLS scopes the update, so an id from another org matches zero rows and returns 404.