AMA: guests hold a time and pay
CaliCastle/cali.so
Description
## Parent #79 ## What to build Complete the booking journey from selected slot to verified Stripe payment. A guest receives a 15-minute Slot Hold, enters Stripe-hosted Checkout, and returns to a truthful paid, expired, cancelled, or still-processing state. ## Acceptance criteria - [ ] Selecting an available start time creates one server-authoritative 15-minute Slot Hold. - [ ] The browser shows an accessible tabular countdown and refreshes authority after visibility changes or reconnects. - [ ] Expired and abandoned holds release availability automatically. - [ ] Database concurrency guarantees prevent overlapping effective holds or Bookings from succeeding. - [ ] Checkout metadata references opaque internal identifiers and contains no Booking Brief or other sensitive content. - [ ] Stripe-hosted Checkout charges exactly US$99 and is idempotent for a Slot Hold. - [ ] A signed Stripe webhook, not the return URL, is authoritative for payment completion. - [ ] Provider event IDs are persisted before side effects; duplicate and out-of-order events are safe. - [ ] Verified payment converts the hold into one paid Booking and invalidates competing claims. - [ ] A late successful payment after hold expiry follows an explicit recoverable conflict path rather than double-booking. - [ ] Confirmation pages distinguish processing, paid, expired, cancelled, failed, and unavailable states without claiming false success. - [ ] Tests cover signature tampering, replay, concurrency, duplicate Checkout creation, abandoned Checkout, late payment, and exactly-once Booking creation. ## Blocked by Public intake and availability journey.