Hospitality engine

Remove a furniture-set combo

delete/api/furniture-set-combos/{id}

Deletes the combo (its book_furniture_set_combo_members rows cascade). The piece's own real member rows are untouched: this only withdraws staff's permission for the allocator to combine that particular subset, and each member goes back to being bookable only on its own unless another configured combo still covers it.

Authorization

sessionCookie
sb-qxrvgfkjyvbngipqvslu-auth-token<token>

The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.

Every request re-validates it against the Auth server (getUser()), never by decoding the cookie locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified app_metadata.company_id claim and enforced by row-level security; it is never read from request input, on any route, ever.

role (admin / staff) is deliberately not in RLS. It gates specific actions in route code, the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's own check is the enforcement.

In: cookie

Path Parameters

id*string

Combo id.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X DELETE "https://example.com/api/furniture-set-combos/string"
{  "ok": true}

Configure a combo for a furniture-set piece POST

Names a subset of one furniture-set piece's real member rows (at least 2) that the allocator may combine into one reservation: the explicit, staff-driven replacement for the automatic uncapped combining this feature used to do (removed 2026-09-11, no adjacency awareness, could combine stool 2 with stool 7). Deliberately its own route, not a branch inside POST /api/link-groups: that route gates on the Venue Pro `table_combining` feature, which furniture-set pieces were built to avoid, and repointing a member's single `link_group_id` into an ordinary combine group would strip its furniture-set identity. Every `tableId` is verified server-side to actually belong to `linkGroupId`, and that group's own `kind` must be `furniture_set`.

Save one floor's decor elements PATCH

Replaces the decor (walls, doors, stairs, bar, stools, plants, text labels; migration 0092) for one canvas wholesale: `levelId` null means the venue's single implicit floor. Element geometry is in the same grid units as table geometry. Strict on write; the read side re-parses leniently and drops junk, so a malformed element here is a 400 naming the problem rather than a silent shrink. The backdrop image (0094) is positioned and faded through the `background*` fields here, but its URL deliberately is NOT settable: `background_url` is written only by `POST /api/floor-plan/background`, from a file that route just placed in this app's own bucket, so no request can aim a venue's canvas at an arbitrary external image.