# Changelog

Every version of API v1 and of the TypeScript SDK, newest first.

## API v1

### 1.9.1 (2026-10-01)

- **Changed:** The served OpenAPI document gains an operationId per operation (the SDK method names), six tags, English descriptions for every operation, parameter, response and property, recorded examples for every response, and `x-pp-since` on operations, schemas and newer fields. No endpoint, field or type changed.
- **Fixed:** `MediaItem.createdAt` is documented: GET /media has sent it since 1.2.0. (listMedia)
- **Deprecated:** `MediaItem.r2Key` is an internal storage key. It stays in the response; build addresses from `url`. (listMedia, uploadMedia)

### 1.9.0 (2026-09-30)

- **Added:** Request a time: an optional `timeRequest` (1 to 3 preferred windows, a treatment and optionally a doctor) on POST /leads, echoed as `LeadCreated.timeRequest`. An invalid one keeps the lead and adds the warning `invalid_time_request`; with `?strict=1` it is a 400 with that code. (createLead)

### 1.8.1 (2026-09-30)

- **Behaviour change:** `BookingCatalogService.priceLabel` is the booking service's own price first, then the linked treatment's `priceFromLabel`. Before, the treatment's price won, so a consultation linked to orthodontics showed the orthodontics price instead of its own. (getBookingCatalog)

### 1.8.0 (2026-09-30)

- **Added:** `BookingCatalogService.nfz`: services under the public health fund (NFZ) are listed for information and booked by phone only. (getBookingCatalog)
- **Behaviour change:** A service the clinic marks as NFZ answers 400 with the code `nfz_phone_only` on GET /booking/slots and POST /booking/appointments; nothing is stored. (getSlots, createAppointment)

### 1.7.0 (2026-09-30)

- **Added:** GET /privacy: the clinic's privacy policy and the information clause for its forms, with a version to send back. (getPrivacy)
- **Added:** Optional `privacyNoticeVersion` and `marketingConsent` on POST /leads and POST /booking/appointments; `SiteProfile.privacy`. (createLead, createAppointment, getSite)

### 1.6.3 (2026-09-30)

- **Changed:** Every booking sends reception a "Nowa wizyta" e-mail with an .ics file; a lead created by a booking no longer sends a second e-mail of its own. The response is unchanged. (createAppointment)

### 1.6.2 (2026-09-30)

- **Fixed:** `Site.noindex`: keep robots.txt open (`Allow: /`, no Sitemap line) so crawlers can see the noindex and drop pages they indexed before. The description used to recommend `Disallow: /`. (getSite, getContent)

### 1.6.1 (2026-09-30)

- **Behaviour change:** POST /media refuses SVG files with 415. SVG files uploaded before are still served, with a sandboxing Content-Security-Policy header. (uploadMedia)

### 1.6.0 (2026-09-30)

- **Added:** POST /feedback: remarks about the clinic's site or the API for the platform team, with personal data removed before storing and 20 remarks per hour per clinic and source. (sendFeedback)

### 1.5.0 (2026-09-29)

- **Added:** `Site.noindex`: the clinic keeps its site out of search engines, and your frontend follows. (getSite, getContent)

### 1.4.0 (2026-09-29)

- **Added:** GET /site and `Site.profile`: contact, address, map point, opening hours, NFZ, payments, social links, logos and registry numbers. (getSite, getContent)
- **Added:** Image variants of library files (`?w=` on a fixed width ladder, `f=` auto, avif or webp) and `width`, `height`, `aiGenerated` and `caption` on MediaRef and MediaItem; `caption` and `aiGenerated` on POST /media. (uploadMedia, listMedia)

### 1.3.0 (2026-09-29)

- **Added:** GET /booking/catalog, and `bookingServiceId` on treatments and `bookingResourceId` on team members to link pages to booking. (getBookingCatalog, listServices, getService, listDoctors, getDoctor)
- **Added:** RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset on every response to a valid key; `code` on errors that have one.
- **Added:** POST /leads answers `warnings: ["missing_contact"]` for a lead without a phone or e-mail, and rejects it with `?strict=1`. (createLead)
- **Fixed:** POST /leads answers 400 `invalid_json` or `invalid_body` for a body that is not a JSON object, instead of failing. (createLead)

### 1.2.0 (2026-07-16)

- **Added:** Booking: free slots, booking an appointment (409 with fresh slots when it was taken) and the appointment list. (getSlots, createAppointment, listAppointments)
- **Added:** The media library: upload an image and list the files. (uploadMedia, listMedia)

### 1.1.0 (2026-07-12)

- **Added:** Treatments, team members, case studies and posts, each with a list and a detail endpoint; the page of GET /content told apart by `kind`; a schema for every response. (listServices, getService, listDoctors, getDoctor, listCaseStudies, getCaseStudy, listPosts, getPost, getContent)

### 1.0.0 (2026-07-02)

- **Added:** The first public API: a page with its site, the published paths and creating a lead, with a secret Bearer key and 120 requests per minute. (getContent, listPages, createLead)

## SDK

### 0.8.1 (2026-10-01, for API 1.9.1)

- **Added:** `MediaItem.createdAt` is typed.

### 0.8.0 (2026-09-30, for API 1.9.0)

- **Added:** `createLead({ …, timeRequest })` and `LeadCreated.timeRequest`; `TIME_OF_DAY` and `windowFromPart` build windows from the parts of the day the clinic's form offers.

### 0.7.2 (2026-09-30, for API 1.8.1)

- **Changed:** Documents the new `priceLabel` order; types unchanged.

### 0.7.1 (2026-09-30, for API 1.8.0)

- **Added:** `BookingCatalogService.nfz`; `getSlots` and `createAppointment` throw ApiError with `code: "nfz_phone_only"` for an NFZ service.

### 0.7.0 (2026-09-30, for API 1.7.0)

- **Added:** `getPrivacy()`; `privacyNoticeVersion` and `marketingConsent` on `createLead` and `createAppointment`; `SiteProfile.privacy`.

### 0.6.0 (2026-09-30, for API 1.6.0)

- **Added:** `sendFeedback()`.

### 0.5.1 (2026-09-29, for API 1.5.0)

- **Added:** `Site.noindex`.

### 0.5.0 (2026-09-29, for API 1.4.0)

- **Added:** `getSite()` and `Site.profile`; media fields; `uploadMedia(file, { caption, aiGenerated })`; `mediaVariantUrl`, `mediaSrcSet`, `phoneHref`, `WEEKDAYS` and `SCHEMA_ORG_DAYS`.

### 0.4.1 (2026-09-29, for API 1.3.0)

- **Fixed:** The tarball installs on its own (types inlined, no dependency outside the public registry).
- **Added:** `createLead(lead, { strict })` and `LeadCreated.warnings`.

### 0.4.0 (2026-09-29, for API 1.3.0)

- **Behaviour change:** `baseUrl` is required: there is no default, so a test frontend never talks to production by accident.
- **Added:** Non-2xx answers throw `ApiError` (`SlotTakenError` for a taken slot, with fresh `slots`); booking and media methods; ESM and CommonJS builds.

### 0.3.0 (2026-09-29, for API 1.3.0)

- **Added:** `getBookingCatalog()`, `bookingServiceId` and `bookingResourceId`.

### 0.2.0 (2026-07-12, for API 1.1.0)

- **Added:** The eight entity methods; `SiteContent.page` is the `ContentPage` union.

### 0.1.0 (2026-07-02, for API 1.0.0)

- **Added:** `getContent`, `listPages` and `createLead`.
