Commit Graph
172 Commits
Author SHA1 Message Date
Hendrik Belitz 3538d282ff Set preferred options so that yubikey works. 2026-02-16 10:43:40 +01:00
Karl Ludwig Weise fe9ea0703c Added dummy flow to add appointments using the calendar 2026-02-12 22:04:03 +01:00
Karl Ludwig Weise 68bfcfb609 Added staff member form fields to channels 2026-02-10 15:01:05 +01:00
Karl Ludwig Weise c1af53dc5b Fix appointment denial incl. email 2026-02-10 12:20:39 +01:00
Karl Ludwig Weise 168e2d5a6c Merge remote-tracking branch 'origin/main' into 160-book-appointment-confirm-appointment-requests-front-end 2026-02-10 12:05:52 +01:00
Karl Ludwig Weise 86294d4bba Send proper email on appointment request 2026-02-10 12:05:43 +01:00
Karl Ludwig WeiseandGitHub 60844d6e40 Merge pull request #186 from open-reception/feat_add_channel_staff
Optionally set staff channel associations when creating or updating a…
2026-02-08 11:46:36 +01:00
Hendrik Belitz a2fc4e4d34 Format und type fixes 2026-02-07 11:39:13 +01:00
Karl Ludwig WeiseandGitHub f34d24f7b6 Merge pull request #192 from open-reception/190-FIX-Add-locale-to-appointment-decryoted
Add locale to encrypted appointment data
2026-02-03 11:25:53 +01:00
Karl Ludwig WeiseandGitHub bcc2d78cdc Merge pull request #193 from open-reception/FIX_first_user_should_be_access_granted
First user of tenant gets access granted, regardless of role.
2026-02-03 10:58:32 +01:00
Hendrik Belitz 7d38db1ce1 Getters should also return staff id relations 2026-02-02 14:37:03 +01:00
Hendrik Belitz 97332c617a Added Cancellation Email template 2026-02-02 14:21:07 +01:00
Hendrik Belitz 1f34ea6f72 Add locale to encrypted appointment data 2026-02-02 13:50:33 +01:00
Hendrik Belitz 128ca9bfc7 First user of tenant gets access granted, regardless of role. 2026-02-02 13:44:24 +01:00
Karl Ludwig Weise 6124398696 Added appointment confirmation and prepared denial 2026-01-28 21:56:03 +01:00
Karl Ludwig WeiseandGitHub fe5309bfa0 Merge pull request #120 from open-reception/feat/custom-domains
Support Custom Domains
2026-01-28 21:38:06 +01:00
Karl Ludwig Weise 9a9abdcf46 Harden navigation for notifications on a all pages 2026-01-28 20:32:50 +01:00
Hendrik Belitz c5d8d174aa Optionally set staff channel associations when creating or updating a channel. 2026-01-28 17:23:46 +01:00
16eed3d03e Added missing files and notes to docker container. (#185)
* Added missing files and notes to docker container.

Dev compose adjusted accordingly (but untested, since it isn't used yet).

Checked release action

* Removed e2e tests from release (not used yet)

* Added missing env vars for unit test

* Missing env

* Display version number

---------

Co-authored-by: Karl Ludwig Weise <ludwig@ludwigweise.de>
2026-01-28 16:48:12 +01:00
Karl Ludwig Weise c5c86e6973 Notifications are closed initially 2026-01-27 22:12:30 +01:00
Karl Ludwig Weise bf9d642f0c Added notification front-end 2026-01-27 22:10:13 +01:00
Karl Ludwig Weise ffdd0ef20f Added automatic fallback link to emails 2026-01-27 17:17:45 +01:00
Karl Ludwig Weise 992b62a865 Disable channel and agent routes for staff role 2026-01-26 20:47:52 +01:00
Karl Ludwig Weise 3f550af281 Added custom domains for tenants 2026-01-23 21:38:06 +01:00
75cdccf5d0 149 allow creation of appointments through staff members (#174)
* Simplified locals.user
Checked routes for accessibilty

* Fixed tests

* Fixed import errors

* Fixed invite test

* PIN API implementation

* Tests for pin reset

* HOusekeeping

* Update src/routes/api/tenants/[id]/clients/pin-reset/request/+server.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Fixes for id and housekeeping

* End routes for staff appointment bookings and check whether client exists.

* Merged main, fixed tests

* Linting errors

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-01-22 11:48:11 +01:00
a64afbd297 160 book appointment confirm appointment requests (#179)
* Extension of tenant schema

* Notification service

* Notification endpoints

* Format errors

* Update src/lib/server/db/tenant-schema.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update src/lib/server/services/notification-service.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Explicit where clause in delete notification

* Update tenant-migrations/0008_neat_swarm.sql

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Sort notifivcations by creation date. Do not explicitly check for existance in mark as read.

* Fixed tests

* Mail templates appointment cancellation

* Appointment cancellation notification texts

* Delete appointment by staff

* Deletion endpoint for staff

* My Appointments endpoint for clients

* Delete appointment by client

* Copilot review fixes

* Fixes after notification changes and updates.

* Fixed limiting errors

* Rejection email template

* Send out request, confirmed notifications, send out confirmed, denied emails.

* Fix test

* MIgration files

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-01-22 11:39:12 +01:00
e9bd83bcd2 148 provide apis for cancelling appointments staff and client wise (#164)
* Extension of tenant schema

* Notification service

* Notification endpoints

* Format errors

* Update src/lib/server/db/tenant-schema.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update src/lib/server/services/notification-service.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Explicit where clause in delete notification

* Update tenant-migrations/0008_neat_swarm.sql

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Sort notifivcations by creation date. Do not explicitly check for existance in mark as read.

* Fixed tests

* Mail templates appointment cancellation

* Appointment cancellation notification texts

* Delete appointment by staff

* Deletion endpoint for staff

* My Appointments endpoint for clients

* Delete appointment by client

* Copilot review fixes

* Fixes after notification changes and updates.

* Fixed limiting errors

* Fix

* Refix fix

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-01-22 11:28:35 +01:00
25f10462da Added salutation field (#183)
* Added salutation field

* Handle honeypot in backend

---------

Co-authored-by: Karl Ludwig Weise <ludwig@ludwigweise.de>
Co-authored-by: Hendrik Belitz <hendrik@innovation-through-understanding.de>
2026-01-22 11:28:17 +01:00
Karl Ludwig Weise 85a0fed42b Fix check 2026-01-21 22:04:17 +01:00
Karl Ludwig Weise 214e201f21 Fix lint 2026-01-21 21:53:53 +01:00
Karl Ludwig Weise 9c86b28182 Undo svelte warnings 2026-01-21 21:22:07 +01:00
Karl Ludwig Weise 7504dd2ac1 Fix types 2026-01-21 19:50:15 +01:00
Hendrik Belitz 7435f8b6fb Allow client email to be optional 2026-01-21 17:30:13 +01:00
Hendrik Belitz 652380c08c Fixed formatting 2026-01-21 17:29:53 +01:00
Hendrik Belitz df50955d8c Merge branch 'main' of github.com:open-reception/appointment-booking-software into 153-book-appointment-allow-clients-to-select-if-they-want-email-notifications 2026-01-21 17:16:10 +01:00
Karl Ludwig Weise eb47814395 Redact user and password from databaseUrl logs 2026-01-16 16:03:23 +01:00
Karl Ludwig Weise 65a9807ad8 Fix: Show language switch again on dashboard 2026-01-16 15:34:45 +01:00
Karl Ludwig Weise 86a3f27bf6 Fix pin throttle check 2026-01-16 13:39:42 +01:00
Karl Ludwig Weise 082435c1fb Added Popover to explain why checkbox is there 2026-01-16 12:59:59 +01:00
Karl Ludwig Weise f663f305c5 Change opt separator back to dot 2026-01-14 17:23:02 +01:00
Karl Ludwig Weise 9c2254215e Added front-end flow to make email sending optional 2026-01-14 17:19:54 +01:00
fb3b880204 142 provide logic and apis to use more than one passkey with a staff member (#163)
* Basic implementation

* Syntax fixes

* Implemented PRF for passkey administration. Updated docs, renamed confusing endpoints.

* Update src/routes/api/auth/passkeys/[passkeyId]/crypto/+server.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Removed unused param

* Merge fixes, formatting fixes, database migrations

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-01-13 18:35:42 +01:00
c552945643 141 provide apis for pin reset (#162)
* Simplified locals.user
Checked routes for accessibilty

* Fixed tests

* Fixed import errors

* Fixed invite test

* PIN API implementation

* Tests for pin reset

* HOusekeeping

* Update src/routes/api/tenants/[id]/clients/pin-reset/request/+server.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Fixes for id and housekeeping

* DB migrations

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-01-13 18:17:42 +01:00
a6707ef081 151 bare minimum notification system (#161)
* Extension of tenant schema

* Notification service

* Notification endpoints

* Format errors

* Update src/lib/server/db/tenant-schema.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update src/lib/server/services/notification-service.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Explicit where clause in delete notification

* Update tenant-migrations/0008_neat_swarm.sql

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Sort notifivcations by creation date. Do not explicitly check for existance in mark as read.

* Fixed tests

* No longer store texts in notifications

* Single source of truth for notification types

* Formatting

* Fixed linting errors

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-01-13 18:05:32 +01:00
8c0343b1ec Feat/email renderer (#172)
* Added poc of new email renderer

* Completed email renderer poc for appointment confirmation

* Changed phone description in add-personal-data-form

* Added used email types to new email system

* Switched email templates to the new template engine.

---------

Co-authored-by: Karl Ludwig Weise <ludwig@ludwigweise.de>
Co-authored-by: Hendrik Belitz <hendrik@innovation-through-understanding.de>
2026-01-12 10:03:22 +01:00
HendrikGitHubhbelcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Copilot
b81706a8d9 Security hotfix prf (#146)
* Use PRF extension for deterministic Zero Knowledge Shards

* Webauthn validation lib

* Use attestation and validate passkeys

* Use attestation objects and cose-format keys in frontend. Added additional checks so that we don't create orphaned users when validation fails.

* Fixed type check error

* Fix PRF salt documentation to match implementation (#147)

* Initial plan

* Fix PRF salt documentation to match implementation

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Use dev instead of node env

* Migration fixes

---------

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>
2026-01-02 15:08:23 +01:00
CopilotGitHubhbelcopilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>Hendrik Belitz
337fc2e70b Add throttling to challenge APIs for brute force protection (#145)
* Initial plan

* Add throttling implementation for challenge APIs

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Add tests for throttling and fix linting issues

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Address code review feedback - improve error handling and documentation

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Consolidate throttle storage to central DB per review feedback

Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>

* Fixed errors in challenge-throlle.

* Add throttling to frontend.

* incorporated Reviewer comments

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: hbel <7416029+hbel@users.noreply.github.com>
Co-authored-by: Hendrik Belitz <hendrik@innovation-through-understanding.de>
2026-01-02 13:14:40 +01:00
Karl Ludwig WeiseandGitHub 56b7d4a9b2 Feat/calendar (#129) 2025-11-19 14:42:45 +01:00
HendrikandGitHub 6a610b96b1 When client selects an appointment that does not need to be confirmed… (#133)
* When client selects an appointment that does not need to be confirmed, send out an email. Also prepared the appointment confirmation call to send out an email.

* Removed old client table. Fixed tests.

* MIgration for removed table
2025-11-17 17:04:57 +01:00
316d7ef25b Feat/book appointment (#121)
* Adding book appointment workflow -wip

* Load channels

* Added channel and agent selection

* Provide optional filter criteria for agents and channels in schedule endpoint.

Return agent info for free schedule slots.

* Select slot

* Added personal data form

* Added login and register step

* Empty PIN input when crypto fails

* Added summary and complete steps

* Format errors in otp component

* Format error in otp component

* Store staff keypairs for appointment encryption

* storeStaffKeyPair during passkey setup

* Fix lint

* Allow access to tenants for tenant admins

* Removed centralised route-based authorization.

* Use setupState from back-end

* First tenant admin is ACCESS_GRANTED.

* load local argon2 directly in central html file

* Make sure cookie is deleted on logout

* Allow WASM execution

* Staff key is base64 encoded, not hex encoded

* Fix proceeding to summary

* Fix TunnelId. Fix Appointment Date. Fix missing AgentId for Tunnel Creation call.

* Fix book appoint flow for new users

* Fix design issues

* Show only slots that have not passed

* Reimplemented ShamirsSecretSharing with Laplacian Interpolation

* Check for existing users before creating new client tunnels. Corrected base64 decoding of challenge.

* Properly deal with existing client errors (422)

* Use new shamir implementation for shard construction and key reconstruction.

* Fix lint and check

* Fix csp header test

* Fixed tests

---------

Co-authored-by: Karl Ludwig Weise <ludwig@ludwigweise.de>
Co-authored-by: Hendrik Belitz <hendrik@innovation-through-understanding.de>
2025-11-13 14:55:11 +01:00