ViewSet for managing BookingPolicy objects.
Provides full CRUD for booking policies scoped to the authenticated user's organization. Write operations (create, update, delete) delegate to BookingPolicyService so validation, uniqueness checking, and audit emission live in a single place.
Exactly-one-target rule: create requests must supply exactly one of calendar, membership_user_id, appointment_type, or is_organization_default=true. Any other combination returns 400.
Duplicate target → 400: creating a second policy for the same target is a validation error (not a 409) so the serializer can name the conflict.
Idempotent destroy: DELETE /booking-policies/{id}/ returns 204 even when the policy does not exist for the bound organization.
Request
- The document declares no server URL.
- Auth: one of:
- HTTP bearer
- API key in cookie sessionid
Query parameters
Number of results to return per page.
The initial index from which to return the results.
Headers
Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.
Response
Example response
{
"count": 123,
"next": "http://api.example.org/accounts/?offset=400&limit=100",
"previous": "http://api.example.org/accounts/?offset=200&limit=100"
}Changes
- ●
removed the optional property
//from the response with the status - ○
added the optional property
//to the response with the status
- ●
- ○
endpoint added
- ○