Hospitality engine

Configure a combo for a furniture-set piece

post/api/furniture-set-combos

Names a subset of one furniture-set piece's real member rows (at least 2) that the allocator may combine into one reservation: the explicit, staff-driven replacement for the automatic uncapped combining this feature used to do (removed 2026-09-11, no adjacency awareness, could combine stool 2 with stool 7). Deliberately its own route, not a branch inside POST /api/link-groups: that route gates on the Venue Pro table_combining feature, which furniture-set pieces were built to avoid, and repointing a member's single link_group_id into an ordinary combine group would strip its furniture-set identity. Every tableId is verified server-side to actually belong to linkGroupId, and that group's own kind must be furniture_set.

Authorization

sessionCookie
sb-qxrvgfkjyvbngipqvslu-auth-token<token>

The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.

Every request re-validates it against the Auth server (getUser()), never by decoding the cookie locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified app_metadata.company_id claim and enforced by row-level security; it is never read from request input, on any route, ever.

role (admin / staff) is deliberately not in RLS. It gates specific actions in route code, the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's own check is the enforcement.

In: cookie

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/furniture-set-combos" \  -H "Content-Type: application/json" \  -d '{    "linkGroupId": "856ba7c8-3373-4364-b044-8aea0515333c",    "tableIds": [      "0f15e971-bb89-4712-9d06-bc444ed39ebe",      "0f15e971-bb89-4712-9d06-bc444ed39ebe"    ]  }'
{  "ok": true,  "comboId": "1fa22bdf-8ea5-4d3f-a6cf-3abb16e9aa74"}