# Annuler une réservation (WP-admin confirm) `VERIFIED IN CODE` · `page=alya-hs-cancel-booking` · submenu **removed** from visible menu (`remove_submenu_page`) · `SCREENSHOT REQUIRED` ## 1. Purpose Dedicated confirmation screen before a **real** LiteAPI cancel: `PUT /bookings/{bookingId}` after POST + checkbox. Not a GET. No invented bookingId. Staff-only hotel cancel. ## 2. Screenshot `SCREENSHOT REQUIRED` — cancel was **not exercised** this audit. ## 3. Navigation Reached from CPT booking actions (`BookingAdmin` link with `alya_hs_cancel_prompt` nonce). Not listed in the Alya Hotels submenu (hidden after register). Not a cockpit hash. ## 4. Fields `post_id` of `alya_booking`. Eligibility from `BookingEligibility::can_cancel`. Environment hint sandbox/production without printing keys. ## 5. Buttons Confirm cancel (destructive). **Not clicked**. ## 6. Filters N/A ## 7. Actions If gate fails, page explains why. If ok, confirm sends cancel to Nuitee. ## 8. Workflow Open CPT reservation → Annuler → this screen → confirm → LiteAPI PUT booking (cancel). ## 9. REST/API Front/staff also: `POST /alya/v1/cancel` with `verify_cancel_permission`. This page is the wp-admin confirm UI for the same supplier cancel. ## 10. Database Updates CPT + status log on success. Not run this pass. ## 11. Permissions `edit_alya_bookings`. Agency Staff: **no**. Traveler hotel cancel: **NOT FOUND**. ## 12. Business meaning Prevent accidental supplier cancel from the post editor. ## 13. Limitations Not screenshot. Flight cancel is a different path (session quote + confirm). ## 14. Evidence status `VERIFIED IN CODE` · live cancel `REQUIRES ACCESS` / `NOT VERIFIED` ## Related [reservations.md](reservations.md) · [user-guide/index.html](../user-guide/index.html)#cancel