Add a floor server
/api/serversA server (0097) is a label with a section colour: a name on the floor map, bookable by nothing. The colour is assigned here, round-robin over a fixed palette chosen so the map's white initials stay readable in both themes; callers do not pick colours.
Front-of-house work, so no admin gate: the same trust level as moving a party between tables.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/api/servers" \ -H "Content-Type: application/json" \ -d '{ "name": "string" }'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "name": "string", "color": "string"}Create a reservation (staff side) POST
A sitting taken at the host stand or over the phone. Always inserted as `confirmed`, never `hold`; a hold is a guest's half-finished checkout with an expiry and has no meaning for something staff enter deliberately. `turnMinutes` is a free field here, unlike an appointment's duration: a reservation has no service to snapshot a length from, which is exactly why 0011 gave it its own tables. `ends_at` is derived from it. `tableId` may be null; a venue that caps covers without assigning tables works as-is.
Rename a floor server PATCH
Name only. The section colour stays assigned by `POST /api/servers`, round-robin over a fixed palette: it exists to keep sections visually distinct on the map rather than to be chosen, and letting two servers land on the same hue would quietly break the thing it is for. This endpoint did not exist until 2026-08-10, on the reasoning that "rename is delete-and-re-add, and nothing else references a server by id". The second half was wrong: `book_server_assignments` references it, and those are exactly what the DELETE below cascades. So fixing a typo in a name wiped every table that server held for that date, mid-service. Renaming in place keeps the assignments.