https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=43763 Bug ID: 43763 Summary: Hold cancellation request via API does not respect waiting hold cancellation policy Initiative type: --- Sponsorship --- status: Product: Koha Version: Main Hardware: All OS: All Status: NEW Severity: normal Priority: P5 - low Component: REST API Assignee: koha-bugs@lists.koha-community.org Reporter: andrew@bywatersolutions.com QA Contact: tomascohen@gmail.com CC: tomascohen@gmail.com Target Milestone: --- Koha's API is able to cancel holds and create a hold cancellation requests when the hold policies say such a request is not allowed. To recreate: - have a waiting hold - set waiting hold cancellation policy to No - attempt to cancel via API without x-koha-override value - your holds is cancelled - create a new waiting hold - waiting hold cancellation policy still at No - attempt to cancel via API with x-koha-override value "cancellation-request-flow" - hold cancellation request is created If the API is meant to be equivalent to a user in the staff interface, then it should be allowed to cancel a waiting hold but not allowed to create a cancellation request regardless of the hold cancellation policy. If the API is meant to be equivalent to a user in the OPAC, then it should not be allowed to cancel a waiting hold and should only be allowed to create a cancellation request if the waiting hold cancellation policy is set to Yes. -- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug.