/api/packing/orders/{id}/lockTake the order [Packaging]
One packer per order at the confirm step (PK-10). Taking is a single conditional write, so two packers pressing the button at the same moment cannot both win.
Re-entrant: taking a lock you already hold succeeds, because a page refresh must not lock you out of your own order. A lock past lockTtlMinutes can be taken by anyone.
Advisory, not a database constraint — which is why confirm re-checks it rather than trusting that this was called.
- IdempotentThe SDK sends
Idempotency-Key, so a retried request is only applied once.
A 400 is returned: Invalid input — the error string says what was wrong. A 401 is returned: Not authenticated. Sign in first (see the Auth tag). A 403 is returned: Authenticated, but not allowed — this endpoint requires a department membership or a role you do not have. A 404 is returned: Not found. A 409 is returned: Someone else is holding it — the body names them. A 500 is returned: Unexpected server error.