The API and React components were already parameterized by doctor uuid, but 14 copy-pasted identity checks limited every endpoint to "the doctor themselves or an admin", so a clinic owner could not touch a member doctor's booking setup. - Replaces those 14 checks with one denyDoctorAccess() that also admits the owner of a clinic the doctor belongs to, and a member doctor holding the clinic's appointment_settings permission (view for GET, update for writes). A doctor's own settings short-circuit before any permission lookup. - Moves ScheduleSection and its tabs out of DoctorDetailPage into components/schedule/ScheduleSection.tsx so the doctor panel and the new clinic page render the same module instead of one page importing another. Pure relocation — no logic changed. - Adds ClinicAppointmentSettingsPage: one tab per clinic doctor, each rendering that same section. The tab wrapper is keyed by doctor uuid so in-progress schedule edits cannot leak onto the wrong doctor. - insurance-pricing accepts an optional doctor_uuid (query on GET, body on PUT) under the same access rule, so the visit-price card works inside the clinic tabs. Fixes saveInsurancePricing calling getInsurancePricing with the wrong argument by extracting the shared pricingPayload(). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
37 lines
1.3 KiB
TypeScript
37 lines
1.3 KiB
TypeScript
import { useAuthStore } from '../stores/authStore';
|
|
import SettingsLayout from '../components/layout/SettingsLayout';
|
|
import FreeVisitPrice from '../components/FreeVisitPrice';
|
|
import { ScheduleSection } from '../components/schedule/ScheduleSection';
|
|
|
|
/**
|
|
* مدیریت نوبت دهی — the doctor's appointment settings: visit price and the full
|
|
* weekly/overrides/holidays schedule (moved here from the doctor profile). The
|
|
* schedule is now managed exclusively from this page.
|
|
*/
|
|
export default function AppointmentSettingsPage() {
|
|
const doctorUuid = useAuthStore((s) => s.doctorUuid);
|
|
const dbUuid = useAuthStore((s) => s.dbUuid);
|
|
const uuid = doctorUuid ?? dbUuid ?? undefined;
|
|
|
|
return (
|
|
<SettingsLayout active="appointment">
|
|
<div
|
|
style={{ background: 'var(--surface)', minWidth: 0 }}
|
|
className="px-4 py-4 md:px-6 md:py-6 rounded-[var(--r-lg)]"
|
|
>
|
|
<h1 className="section-title" style={{ marginBottom: 16 }}>مدیریت نوبت دهی</h1>
|
|
|
|
<FreeVisitPrice />
|
|
|
|
{!uuid ? (
|
|
<div className="card" style={{ padding: 32, textAlign: 'center', color: 'var(--text-3)', fontSize: 14 }}>
|
|
این بخش فقط برای پزشک در دسترس است.
|
|
</div>
|
|
) : (
|
|
<ScheduleSection doctorUuid={uuid} />
|
|
)}
|
|
</div>
|
|
</SettingsLayout>
|
|
);
|
|
}
|