Delete a link group (admin)
/api/link-groups/{id}Never 409s, for the same reason deleting a level does not: book_tables.link_group_id is ON DELETE SET NULL (migration 0035), so this un-links its tables and deletes nothing else. Past bookings are unaffected; a reservation holds TABLES (book_reservation_tables), never the group they were combined through.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Path Parameters
Link group id.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/api/link-groups/string"{ "ok": true}Rename a link group PATCH
A group carries nothing but a name, so this is the whole of it. Membership is changed by editing the tables.
List a combine group's staff-drawn adjacency edges GET
Every book_table_link_adjacencies edge for one book_table_link_groups id (2026-09-11): which of the group's own tables actually sit next to each other, drawn on the floor-plan canvas' connect tool. Combining that group's members now requires a connected chain of these edges (see reservation-slots.ts's own comment); an empty list means every member is bookable only on its own or with a single-table fit.