Bookable slot proposals for the appointment type bound to a booking code
Changed onUnauthenticated, code-gated read of bookable slots for an appointment type.
GET /public/booking/appointment-type-bookable-slots/ ports public_api.queries.Query.appointment_type_bookable_slots_with_code to REST. The appointment type comes from the resolved token (token.appointment_type, falling back to token.event.appointment_type); a single-calendar code is rejected via the same uniform 403 (its appointment_type resolves to None).
Request
- The document declares no server URL.
- Auth: none declared. Required headers: X-Booking-Code
Query parameters
Desired event duration, in seconds. ALWAYS REQUIRED to be present (a request omitting it is a 400 whether or not the resolved code's appointment type pins a duration -- presence alone must never disclose pin state). Duration pinning lives on the AppointmentType, not on the code: on the calendar-scoped endpoint this value always stands as given -- a calendar-scoped code carries no duration constraint at all. On the appointment-type-scoped endpoint, when the resolved code's appointment type pins a duration, the pin silently overrides this parameter's VALUE: a mismatched or malformed value produces the exact same response as the pinned value, so this endpoint cannot be used to probe whether an appointment type is pinned or what the pin is. When the appointment type pins no duration, the value must also be a valid positive integer.
End of the search window (ISO 8601).
Start of the search window (ISO 8601).
Search step, in seconds (default 900 = 15min).
Headers
Single-use booking code. Every failure -- invalid, expired, used, revoked, or wrong-scope -- returns the same 403 {"detail": "Invalid or expired code."}; this endpoint never discloses which one occurred. Repeatable: never consumed by a read.
Response
Changes
- ○
endpoint added
- ○