fix(doctor): hide deactivated doctors from public site

The public list GET /api/v1/doctors only excluded inactive doctors
when an explicit `active` filter was passed; with no param it returned
everyone (deactivated doctors just ranked lower). Deactivated doctors
(admin toggled active_doctor_appointment off) leaked onto nobat724.

- DoctorRepository::findWithFilters: default (no `active` param) now
  filters activeDoctorAppointment = true. The active=1 (bookable) and
  active=0 (admin, inactive-only) escape hatches are unchanged.
- Doctor::toDetailArray: expose raw `is_active` (= activeDoctorAppointment,
  independent of schedule) so public clients can 404 a deactivated
  doctor's profile page; distinct from `active` (flag && has_schedule).
- Tests + docs/api/doctor.md updated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
hamed
2026-07-23 19:38:01 +03:30
co-authored by Claude Opus 4.8
parent ccbd028fee
commit 1986356c91
+5 -1
View File
@@ -22,7 +22,11 @@ const getDoctor = cache(async (slug) => {
if (res.status === 404 || res.status === 400) return null;
if (!res.ok) throw new Error(`Failed to fetch doctor: ${res.status}`);
const json = await res.json();
return json?.data?.data ?? null;
const doctor = json?.data?.data ?? null;
// پزشک غیرفعال (ادمین فلگ فعال را خاموش کرده) نباید در سایت نمایش داده شود؛
// صفحهٔ تکی هم مثل لیست عمومی 404 می‌شود.
if (doctor?.is_active === false) return null;
return doctor;
});
const getDoctorAddresses = cache(async (doctorId) => {