- Appointment detail (DetailLg/DetailSm) read the real response shape:
date/time from slot_start, specialty from doctor.specialties[0].name,
phone from address.telephone.
- Sidebar Head reads userInfo (cookie) after mount to avoid an SSR/client
hydration mismatch on the user's name.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- My-appointments tabs sent invalid status values (reserved/waiting_for_payment/
...) that don't exist in the backend, so every tab but "all" returned empty.
Map tabs to real statuses (pending/confirmed/completed/cancelled_by_user/
expired) so booked appointments show up.
- Booking form now validates required account fields before proceeding to
payment (national_code 10 digits, name, family, gender, basic_insurance),
in both self and other-person modes, surfacing per-field errors.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
These tabs have no backend endpoint yet (only per-doctor comments and
admin exist; user messages don't), so they read the always-empty
user.comments/user.messages. Guard against null and show a clear empty
state instead of a blank list.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The transactions list/card read mock fields (appointment_details,
row.amount, status 'received') and iterated user.turns.done. Pass the
real payments array and read order_id/type/created_at/amount_rials/status
from Payment.toArray(); map status to Persian labels, show rials→toman,
and render an empty state when there are no transactions.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The turns list/card read start_time, slot.time and doctor.specialty,
none of which exist on Appointment.toArray() (slot_start, doctor.name,
status). Use slot_start for the Jalali date/time, replace the specialty
column with a Persian status label, and show an empty state when there
are no appointments.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Login now overwrites the uuid cookie with the real user uuid (was the
OTP uuid), so server-side profile/dashboard fetches resolve.
- getMyAppointments → /api/v1/appointments/user (patient's own bookings;
/my/appointments is role-scoped and empty for plain users), read from
the double-nested data.data.
- getMyPayments → /api/v1/my/payments (new endpoint), read paginated
data + meta.totalPages.
- Drop the userId path param (both endpoints derive the user from token).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The routing modal shipped broken deep links: snapp.ir/route and
tapsi.ir/route paths don't exist (404), and balad used the wrong path
and params. Keep only apps with verified destination deep links and
fix their formats:
- Remove Snapp and Tapsi (no valid web destination route).
- Balad: balad.ir/location?latitude=&longitude= (was /map?lat=&lng=).
- Google Maps and Waze kept (already correct).
- Guard data.map destructuring against null.
- Dashboard turn detail: use maps/dir directions URL instead of a
plain q= pin to match the مسیریابی label.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Security:
- Disable SSL verification only in development (lib/req.js)
- Wrap all JSON.parse(cookie) calls in try-catch via safeJsonParse utility
- Sanitize dangerouslySetInnerHTML in blog/clinic with sanitizeHtml utility
- Fix open redirect in payment page — validate URL origin before redirect
- Fix cookie cleanup on 401 — use js-cookie with correct domain scope
Performance:
- Wrap ItemDoctor with React.memo to prevent unnecessary re-renders
- Replace <img> with Next.js <Image> in blog Caption component
Functionality:
- Fix memory leak in Recode.js — store intervals in refs, cleanup on unmount
- Add null guard on retryIcon.current before classList manipulation
- Fix getParsedUserInfo in helper to handle malformed cookie gracefully
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>