Merchant operations release candidate
- Added a role-aware merchant shell with Today, Calendar, booking detail, Customers, Services and Setup routes; links are rendered only for implemented surfaces.
- Added payment-free booking confirmation, completion, no-show and cancellation actions with optimistic conflict protection, history and audit rows. Payment-linked bookings stay locked until refunds are wired.
- Replaced server-time dashboard logic with venue-local dates and resource-specific availability with location-hours intersection, including split-shift and DST tests.
- Changed onboarding to invite-only sign-in with explicit multi-workspace recovery and a reviewed three-step initial setup in English and Arabic.
- Moved early-access and contact intake from the read-only web filesystem into least-privilege Postgres functions, with direct PII table access revoked from both runtime roles.
- Removed the unresolved permanent payment-fee promise from metadata, the share card and deposit copy; pricing remains unpublished.
StatusLocal release candidate. Unit, type and lint gates pass; production build, seeded portal browser acceptance, migration promotion and operator approval remain outstanding.