- New RefundBookingTableAction on the booking list row and detail page,
refunding a Confirmed booking directly via RefundBookingAction — no need
to hunt up its Payment on the Refunds resource first.
- Payment::refundableBalance() extracted from RefundBookingAction's private
balance check so both refund forms can display and cap against it.
- RefundBookingAction::resolveRefundablePayment() made public for the same
reason (round-trip leg resolution reused by the UI).
- Both refund forms (ProcessRefundAction and the new booking action) gain a
"Full refund" toggle, on by default, which refunds the payment's whole
remaining balance without requiring a manually typed amount. Turning it
off reveals an amount field capped at the refundable balance.
- T6.1: named rate limiters (api-read/api-write/api-auth/api-webhooks),
applied per module route group with tighter limits on booking/payment
writes and the KBZ webhook than read-only catalog/routing endpoints.
- T6.2: install spatie/laravel-activitylog; LogsActivity on Booking/
Payment/Refund status transitions and catalog/pricing admin CRUD
(EvCompany, Destination, DepartureTimeSlot, EvRoute, RoutePricing).
New IdentityPlugin with a read-only AuditLogResource gated by
view_audit_log.
- T6.3: JSON error envelope for api/* in bootstrap/app.php (401/403/404/
405/429/500 fallback), plus PaymentGatewayException (422 declined /
502 unavailable).
- T6.4: feature tests proving the FastAPI agent token gets 403 on
refund/cancel-not-owned and 405 (no write handler) on catalog/routing
writes.
- T6.5: install gboquizosanchez/filament-log-viewer with a custom
Filament admin theme (required for its views' Tailwind classes to
compile), LOG_CHANNEL/FILAMENT_LOG_VIEWER_DRIVER=daily, registered
under Operations in the sidebar.
252 tests passing.