Files
UbuntuandClaude Opus 5 ce7400578a Apply the worker capability filter to the manage-booking flow
The per-worker service allow-list was only enforced on the new-booking form.
On the guest manage-booking page a worker could still be offered for services
they do not perform:

- manage_booking() branched on $firstService, which was never assigned - the
  resolve loop above it used $resolvedService - so the guarded branch was dead
  and the worker list fell through to getActiveWorkers(), filtered by vertical
  only. Assigning it activates both the category filter and the capability
  check, and with it the $isOtherCategory checkbox disabling in the view.
- The page's own getAvailableWorkersByServiceCategorySlug() never sent
  service_ids, so re-picking services asked for a category-only worker list.
  It now mirrors the booking form, including the empty-result message.
- setWorker() clears any time already chosen: changing worker or services left
  a stale selection with the submit button still enabled.

manage_booking_process() did re-check capability server-side, but every
rejection there answered with raw JSON, which this non-AJAX form renders as an
unstyled blob in the guest's browser. All eight rejections, plus the
cancellation cutoff, now go through _booking_error(), which takes an optional
back URL so the guest returns to their own manage page rather than an empty
booking form. Adds the cutoff_passed message in all three languages and makes
the error title and button label reflect which flow failed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TYGSbK1erKv7VG1pvdPEjG
2026-08-24 17:06:08 +00:00

44 lines
3.1 KiB
PHP
Executable File

<?php
$bookingErrorMessages = array(
'slot_taken' => 'Dette tidspunktet ble dessverre opptatt mens du fylte ut skjemaet. Vennligst velg et annet tidspunkt.',
'worker_unavailable' => 'Den valgte medarbeideren jobber ikke denne dagen. Vennligst velg en annen dag.',
'outside_schedule' => 'Det valgte tidspunktet er utenfor medarbeiderens arbeidstid. Vennligst velg et annet tidspunkt.',
'alternate_week' => 'Den valgte medarbeideren jobber kun annenhver uke. Vennligst velg en annen dag.',
'after_hours' => 'Behandlingen rekker ikke å bli ferdig innen stengetid. Vennligst velg et tidligere tidspunkt.',
'too_far' => 'Du kan kun bestille time inntil 3 måneder frem i tid.',
'category_mismatch' => 'Den valgte medarbeideren utfører ikke de valgte tjenestene. Vennligst velg på nytt.',
'service_not_offered' => 'Den valgte medarbeideren utfører ikke alle de valgte behandlingene. Vennligst velg en annen medarbeider eller endre behandlingene.',
'single_service_only' => 'Du kan kun bestille én behandling om gangen. Vennligst velg kun én.',
'invalid_email' => 'E-postadressen ser ikke ut til å være gyldig. Vennligst kontroller den - bekreftelsen og lenken for å endre bestillingen sendes dit.',
'cutoff_passed' => 'Bestillingen er innen 24 timer og kan ikke lenger endres eller avbestilles. Vennligst ta kontakt med salongen.',
'no_service' => 'Du har ikke valgt noen tjeneste. Vennligst velg minst én tjeneste.',
'default' => 'Noe gikk galt med bestillingen. Vennligst prøv igjen.',
);
$shownError = isset($bookingErrorCode) && isset($bookingErrorMessages[$bookingErrorCode])
? $bookingErrorMessages[$bookingErrorCode]
: $bookingErrorMessages['default'];
$backSubpage = isset($subpage) && $subpage != '' ? $subpage : 'barber';
// _booking_error() passes a back URL when the error came from the
// manage-booking flow; that guest must return to their own booking page
// rather than being dropped into an empty new-booking form.
$isManageError = isset($bookingBackUrl) && $bookingBackUrl !== '';
$backUrl = $isManageError ? $bookingBackUrl : SITEURL.'no/booking/'.$backSubpage;
$backLabel = $isManageError ? 'Tilbake til bestillingen din' : 'Tilbake til bestilling';
if(isset($bookingErrorCode) && $bookingErrorCode === 'slot_taken'){
$errorTitle = 'Tidspunktet er ikke lenger tilgjengelig';
} else {
$errorTitle = $isManageError ? 'Bestillingen kunne ikke endres' : 'Bestillingen kunne ikke fullføres';
}
?>
<div class="bookingContainer" style="min-height:500px;">
<div class="bookingThankYouTitle"><?php echo $errorTitle;?></div>
<div class="bookingThankYouMessageTitle"><?php echo $shownError;?></div>
<div style="text-align:center; margin-top:30px;">
<a href="<?php echo $backUrl;?>" style="display:inline-block; padding:12px 28px; background:#000; color:#fff; text-decoration:none; border-radius:5px; font-size:16px;"><?php echo $backLabel;?></a>
</div>
</div>