The language switcher in barber/beauty headers reads
$currentPageUrlArray[2] unguarded after exploding REQUEST_URI on '/'.
On routes with no language prefix (e.g. POST /manage-booking-cancel
rendering the cancelled page inline), the array has only 2 elements,
triggering "Undefined array key 2" warnings and producing malformed
language links like https://studiobeve.no/en//.
Normalize the array with += [2 => '', 3 => ''] right after the explode
so indices 2 and 3 always exist.
The strftime() result was immediately overwritten by a hardcoded
Hungarian month-name array. Drop the dead line so PHP 8.1+ stops
emitting an E_DEPRECATED warning when prod loads the worker calendar.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Admin create/modify booking notifications now match the public
confirmation/modify emails. Admin-created bookings get a manage_token
generated; admin-modified bookings reuse the existing token (or
backfill one if missing).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- getAvailableTimes() takes optional exclude_booking_id so a guest's
own booking isn't counted as a conflict when editing — original time
now reappears when extending services
- Manage-booking AJAX passes manage_token; server resolves to booking_id
- manage_booking_process uses the new param instead of the date-swap
workaround (removes a small race-condition risk)
- Modify-booking emails (no/en/hu) now include Name/Email/Phone rows
and the 24h cancellation policy, matching the original booking email
The security hardening commit accidentally rendered every input value as
value=\"...\" (literal backslash-quote in HTML), which mangled all
submitted fields including the hidden worker_id/service_id, causing
UPDATE to match zero rows and silently no-op.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- New weekly calendar at /bookings/calendar with time blocks per booking
- Color-coded by worker, overlapping bookings shown side-by-side
- Click booking to see details, edit or delete
- Worker filter dropdown, week navigation (prev/next/today)
- AJAX week loading for smooth navigation
- Link between list view and calendar view
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add Europe/Oslo timezone to all DateTime constructors in getAvailableTimes() and
computeLunchBreak() to prevent UTC vs local time mismatch that allowed booking
slots 1 hour past the worker's end time on same-day bookings
- Remove fallback loop in computeLunchBreak() that pushed the lunch break outside
the configured window; lunch break is now strictly enforced within the interval
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Lunch slot no longer pre-blocked; a slot is only unavailable if
booking it would eliminate the last possible 30-min break window
- Added preferred lunch time per worker (closest-to-preferred slot wins)
- Lunch break only applies for shifts >= 6 hours
- Google Calendar: lunch event created/updated/deleted on every
booking create, modify, or cancel via _syncLunchCalendarEvent()
- New table worker_lunch_gcal_events tracks lunch event IDs per worker/date
- New model methods: getBookingsForWorkerDay, getLunchGcalEventId,
upsertLunchGcalEventId, deleteLunchGcalEventRecord, getBookingsForWorkerMonth,
computeLunchBreak
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Monthly calendar grid per worker with colour-coded day status
- Override types: vacation, sick, custom hours, other, day-off
- Date-range override support via modal
- Floating 30-min lunch break: finds slot closest to preferred time
within configurable window, adapts to existing bookings
- Lunch break only applies for shifts >= 6 hours
- Lunch slot shown in admin calendar; blocked in booking availability
- DB migrations: absence_type/note on worker_schedule_overrides,
lunch_window_start/end/preferred_time on workers
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Evelin receives all booking notifications via the shared ntfy topic in config.
Each worker also gets notified on their own personal ntfy topic (set per-worker
in the admin panel) — so workers only see their own booking events.
- _ntfy() now accepts optional $workerTopic and sends to both topics if different
- All three call sites (new/modify/cancel) pass $worker->ntfy_topic
- Admin worker form + worker_process() wired for ntfy_topic field
- DB: ALTER TABLE workers ADD COLUMN ntfy_topic VARCHAR(100) NULL DEFAULT NULL
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sends instant push notification on new booking, modification, and
cancellation. Set ntfy_topic in application/config/google_calendar.php
to activate. No-ops silently if topic is empty.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Service account can now impersonate a Workspace user (set gcal_impersonate_email
in config) to unlock attendee invitations with push notifications.
Falls back to silent event creation if impersonation is not configured.
Setup required in Google Admin Console:
Security → API Controls → Domain-wide delegation
→ Add service account client_id with scope:
https://www.googleapis.com/auth/calendar
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Google API forbids attendees on service account events without
Domain-Wide Delegation (requires Google Workspace). Reverts to
direct event creation which works with personal Gmail calendars.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Add attendees to calendar events with sendUpdates=all so workers and
Evelin receive an instant push notification + invitation email when a
booking is created or modified, instead of the event silently appearing.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- New GoogleCalendar library: createEvent/updateEvent/deleteEvent via service account, all wrapped in try/catch so failures never break booking flow
- booking_process: creates worker + owner calendar events on new booking
- manage_booking_process: deletes old events, creates new ones on modify
- manage_booking_cancel: deletes events before cancellation
- Service_model: updateBookingCalEvents() stores gcal event IDs
- Admin worker form: Google Calendar ID field added
- PHPMailer: enabled exceptions (was silently swallowing SMTP errors)
- Config: application/config/google_calendar.php for service account path + Evelin calendar ID
DB migration required:
ALTER TABLE workers ADD COLUMN google_calendar_id VARCHAR(255) NULL DEFAULT NULL;
ALTER TABLE bookings ADD COLUMN gcal_event_id_worker VARCHAR(255) NULL DEFAULT NULL;
ALTER TABLE bookings ADD COLUMN gcal_event_id_owner VARCHAR(255) NULL DEFAULT NULL;
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>