H
HykeCal

Bookings & cancellation

Booking, without an account

A visitor picks a time on /book/[slug] and submits their name, email, and an optional note — no account, no password. You get a notification email, they get a confirmation with a cancellation link.

Double-booking is a database guarantee

A Postgres EXCLUDE constraint (via btree_gist) spans every confirmed booking's time range — deliberately not partitioned by event type, since there's one owner and one calendar. Two concurrent requests for overlapping times will have one fail at the database level regardless of timing. The API's own pre-check exists only to give a visitor a normal "that time's gone" message instead of a raw constraint error — the constraint is what actually holds.

Cancelling

The confirmation email includes a link to /cancel/[token] — a confirm step, not an instant cancel, since mail clients and link scanners sometimes pre-fetch links. The token is single-use proof that whoever holds it made the original booking; you, the owner, can also cancel any booking directly from the dashboard without one.