package routes import ( "github.com/gofiber/fiber/v2" "nearle/facade" ) /* Delivery windows. ── The web half is guarded, the app half is read-only ────────────────────── Setting a branch's hours is a tenant-wide decision with money behind it, so it sits on /v1/web where WebAuth checks the session and the tenant scope. Reading what is on offer is what a shopper's app does before it has any identity at all, so that one endpoint — and only that one — lives on the unauthenticated /v1/mob group. There is deliberately NO write route on the mob group. The /v1/mob/* group has no session at all, and a shop's trading hours are not something an anonymous caller gets to set. */ func RegisterDeliverySlotRoutes(api fiber.Router, f *facade.Facade) { // ── Console: read and edit a branch's windows ─────────────────────────── web := api.Group("/v1/web/deliveryslots") web.Get("/", f.DeliverySlotController.ListDeliverySlots) web.Put("/", f.DeliverySlotController.SaveDeliverySlots) // ── App: what a shopper may pick, already filtered ────────────────────── mob := api.Group("/v1/mob/deliveryslots") mob.Get("/available", f.DeliverySlotController.AvailableDeliverySlots) }