fix(doctor): hide deactivated doctors from public site
The public list GET /api/v1/doctors only excluded inactive doctors when an explicit `active` filter was passed; with no param it returned everyone (deactivated doctors just ranked lower). Deactivated doctors (admin toggled active_doctor_appointment off) leaked onto nobat724. - DoctorRepository::findWithFilters: default (no `active` param) now filters activeDoctorAppointment = true. The active=1 (bookable) and active=0 (admin, inactive-only) escape hatches are unchanged. - Doctor::toDetailArray: expose raw `is_active` (= activeDoctorAppointment, independent of schedule) so public clients can 404 a deactivated doctor's profile page; distinct from `active` (flag && has_schedule). - Tests + docs/api/doctor.md updated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -108,6 +108,12 @@ class DoctorRepository extends ServiceEntityRepository
|
||||
// Legacy admin escape hatch: active=0 → flag explicitly off.
|
||||
$qb->andWhere('d.activeDoctorAppointment = false');
|
||||
}
|
||||
} else {
|
||||
// Public listing default: deactivated doctors (admin toggled the
|
||||
// active flag off) must never surface on the public site, even
|
||||
// without an explicit `active` filter. Bookability is a separate,
|
||||
// stricter concern handled by `active=1`.
|
||||
$qb->andWhere('d.activeDoctorAppointment = true');
|
||||
}
|
||||
|
||||
// Bookable doctors always rank above non-bookable ones.
|
||||
|
||||
Reference in New Issue
Block a user