HSC · Inventory ops

A rental system that treats after-hours returns as an untrusted event.

Gear Desk is the physical checkout record for chairs, masks, and fins at Suite 103. FareHarbor remains the payment rail. This system owns identity, due dates, quantities, sizes, replacement value, and the return state machine — including an after-hours path that cannot close itself.

Context

The shop sold rentals on the web and handed gear over the counter with no durable record of who held what. After 5pm, drop-offs were honor-system. Overdue chairs and missing masks could not be proven, so they could not be charged. Tagging every physical unit with a sticker would slow the counter and invent an inventory problem the shop does not have.

Architecture

The unit of work is a rental, not an asset tag. One checkout produces one rental code, one receipt QR, and one replacement total. Quantities and sizes live on line items. That matches how the counter actually works: two chairs, not Chair #17.

Two QR surfaces, both signed tokens (not guessable IDs). A station token on the laminated bin poster. A rental token on the printed receipt. Guest lookup still requires rental code + last name + last four of phone. Failed lookups share one error. Endpoints are rate-limited.

State is explicit: out, due today, overdue, after-hours pending, confirmed return, not-in-bin, charged. A guest POST only creates a pending return. Staff confirmation is a separate authenticated write. An append-only audit log records login, checkout, return, and charge events.

Implementation

Authenticated staff checkout

bcrypt credentials, 12-hour httpOnly session cookies, origin checks, security headers. Checkout captures guest, phone, due date (default seven days), gear, sizes, and replacement value in one pass.

Operational queues, not reports

The home view is currently-out, due-today, overdue, and the morning after-hours queue. That is the desk’s job list. There is no export step to find out what walked.

Untrusted guest return path

After hours the guest scans station or receipt QR, proves identity with three factors, and reports a drop-off. The rental stays open until someone looks in the bin — or marks it missing.

Charge path with a number already on the record

Replacement value is stored at checkout. Late or missing gear does not require a manager to reconstruct a price from memory.

Non-negotiables

No per-unit asset tags

QR codes are never applied to chairs or masks. Two printed codes cover the protocol. That was a product decision, not a backlog item.

FareHarbor is not replaced

Payment stays where the shop already sells. Gear Desk is designed to accept a later webhook without becoming the storefront.

Guest submissions never mutate a rental to returned. That write is reserved for an authenticated staff session after physical verification.

All systemsBook an audit