# Flight booking — complete visual guide **Product:** Alya Hotel System `1.1.16-dev` **Site:** https://alyatrip.com/flights/ **Shortcode:** `[alya_flight_booking]` **Date:** 30 August 2026 **Production changes:** NONE ## Honest status | Step | Status | |------|--------| | Search UI | `VERIFIED LIVE` | | Search submit ALG–CDG | `VERIFIED LIVE` **error** — expired REST nonce | | Results / verify / extras | **NOT VERIFIED IN THIS AUDIT** | | Prebook / payment / book | **NOT VERIFIED IN THIS AUDIT** | | Confirmation / cancel | `VERIFIED IN CODE` only | Do **not** claim a successful flight booking for this audit. --- # Search ## Screenshot ![Flight search](../screenshots/live/05-flights-01-search.png) ## Visible Réserver un vol. Aller simple / **Aller-retour**. Départ / Arrivée (IATA). Dates. 1 passager. **Rechercher**. Stepper: Recherche → Offres → Passagers → Options → Paiement → Confirmation. Trust: “Paiement Stripe sécurisé”, sandbox 4242. ## Who Traveler. Public nonce. ## API (code) `POST /alya/v1/flights/search` — 10/600s. Airports: `GET /flights/airports` 30/600s. --- # Search error (this pass) ## Screenshot ![Nonce expired](../screenshots/live/05-flights-02-search-error.png) Input: ALG → CDG, 2026-09-20 → 2026-09-27. **Result:** “Session de page expirée. Rechargez la page puis réessayez.” This is a **real live error**. Typical cause: `wp_rest` nonce on a long-lived tab. Reload then search again. `SCREENSHOT REQUIRED` for a successful offers list **after reload**. A file `05-flights-02-results-prior.png` exists from **28 Aug 2026**. It is **not** this pass and is not used as proof of success here. --- # Results → Verify → Extras → Prebook → Payment → Book `VERIFIED IN CODE` — `alya-flights.js` + `FlightRoutes.php` | Step | REST | LiteAPI | Live this pass | |------|--------|---------|----------------| | Verify | `POST /flights/verify` 15/600s | `/flights/verify` | `SCREENSHOT REQUIRED` | | Accept price | `POST /flights/verify/accept` | | `SCREENSHOT REQUIRED` | | Extras | `GET/POST /flights/prebook/{id}/services` | prebook services | extras **before** book only | | Post-book extras | — | — | `NOT FOUND` | | Prebook | `POST /flights/prebook` **8/600s** | `usePaymentSdk: true` | `SCREENSHOT REQUIRED` | | Payment | Stripe Elements `secretKey` | front **never** sends `transactionId` | `SCREENSHOT REQUIRED` | | Book | `POST /flights/book` | server injects TRANSACTION_ID | `SCREENSHOT REQUIRED` | | Confirmation | confirmation / itinerary endpoints | ICS `CalendarLinks` | `SCREENSHOT REQUIRED` | --- # Cancellation `VERIFIED IN CODE`: traveler can quote then cancel with session (`FlightCancel.php`). Staff ops cancel-quote exists. Live cancel: **NOT VERIFIED IN THIS AUDIT**. `SCREENSHOT REQUIRED`. PUT on booking in this plugin = **cancel**, not amend. `VERIFIED IN CODE`. --- ## Related [flight-booking-journey.md](../live-site/flight-booking-journey.md) · [nuitee-liteapi-audit.md](../technical/nuitee-liteapi-audit.md) · [payment-architecture.md](../business/payment-architecture.md)