## What changed - validate every normalized order-booking item against active customer product rules before reservation and persistence - return a structured HTTP 400 response containing the rejected product and matching rule metadata - document the rejection response in both OpenAPI specifications - add API coverage for restricted base products, restricted add-ons, and allowed neighboring products ## Why Frontend rule guidance alone cannot prevent stale or crafted requests from persisting restricted booking products. The booking write boundary must enforce the same customer rules. ## Validation - full backend API suite - focused order-booking API coverage - PHP syntax checks - OpenAPI and diff checks ## Related frontend PR The coordinated frontend PR provides fail-closed selection, recovery, and responsive booking-page behavior.
661 KiB
661 KiB