All packages
Opening Hours for Laravel
Security notes
- Ids in a sync payload must belong to the calendar being written; foreign ids are rejected (unknown_id).
- OpeningHours::exceptions($owner)->remove($id) only touches that calendar’s rules — any other id returns false.
- Labels are returned raw — escape them in your templates.
- meta is hidden from API resources by default (api.expose_meta); php artisan about shows the cache store only as default or custom.
- Column names given to EloquentBusyPeriodProvider are allow-list validated; values are bound.
- The limits.* keys cap definition size, busy periods read and slots returned, guarding against oversized input.
- Mass deletes of owners (Clinic::query()->delete()) fire no model events and leave their calendars behind — polymorphic owners cannot carry a foreign key.
- Availability is a read — guard bookings with your own lock or unique constraint.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.