Skip to content

Scheduling edge cases: past-session attendance + edit-time unique-collision 500 #300

Description

@TusharW4ni

Part of #285 (Group D — robustness).

Problem

Two scheduling edge cases surfaced during the audit.

Evidence

  1. Attendance can be added to past sessions. server/api/session/attendance/index.post.ts enforces maxAttendance and prevents double-add (composite PK → 409), but has no time check — a patient can be added to a session in the past. May be intended (backfilling attendance) or not.
  2. Edit-time unique collision → 500. Session has @@unique([time, therapistId]) (prisma/schema.prisma:159). On create, a P2002 is translated by handlePrismaError. On edit, server/api/session/info.put.ts does not special-case P2002, so a same-start-time collision (that the overlap guard doesn't catch — e.g. identical start, different duration) falls through to a generic 500 instead of a clean 409.

Impact

P2. #1 is a possible data-correctness gap depending on intent; #2 is a poor error for a reachable edge.

Proposed approach

  • Decide whether past-session attendance is allowed; if not, add a time guard mirroring create.
  • In info.put.ts, catch P2002 and return a 409 with a clear "another session for this therapist starts at that time" message.

Acceptance criteria

  • Past-session attendance behavior is intentional and enforced.
  • Editing into a same-start-time collision returns a clean 409, not a 500.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2: mediumImprovements, non-blocking bugsarea: scheduleCalendar, appointments, sessionsbugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions