Skip to content

Update Organization

Method

REST method is adopted.

HTTP Method

PUT: Update an existing organization

Naming Convention

To unify naming of query parameters and nodes and improve readability, snake_case is used for URIs and nodes in JSON during requests.

Request and Response

Headers

Meta information is set in HTTP headers rather than in the response body.

Request Headers

  • Authorization: Bearer <access_token>
  • Content-Type: application/json

Response Headers

  • Content-Type: application/json

Update Organization

URI

Path parameter type is integer.

/api/v1/organizations/{organization_id}

Path Parameters

Name Type Description
organization_id integer Required. Must be a positive integer identifying the organization.

Request Body

Request body is JSON.

{
  "name": "Updated Organization Name"
}

Validation Rules

Field Rule
name Required. Must be a string between 1 and 255 characters.

Response (200 OK)

Response is JSON.

{
  "id": 1,
  "name": "Updated Organization Name",
  "createdAt": 1640995200000,
  "updatedAt": 1641081600000,
  "createdBy": "1111-aaaa-2222-bbbb",
  "updatedBy": "3333-cccc-4444-dddd",
  "deletedAt": null,
  "deletedBy": null
}

Authentication

Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito. A valid Bearer token is required in the Authorization header.

Exception Handling

Exception handling status codes are as follows.

Description Status Code Status Name
Missing or invalid token 401 Unauthorized
Organization not found 404 Not Found
Internal server error 500 Internal Server Error

Process Flow

Sequence Diagram

sequenceDiagram
    participant Client
    participant Middleware as Protected Route Middleware
    participant API as Hono Router
    participant Service as Organization Service
    participant Repository as Organization Repository
    participant DB as PostgreSQL Database

    Client->>Middleware: PUT /api/v1/organizations/{organization_id}
    Middleware->>Middleware: Extract Bearer token
    Middleware->>Middleware: Verify JWT & session

    alt Token Valid
        Middleware-->>API: Auth info (sub, adminId)
        API->>API: Validate request body (Zod)
        API->>Service: update(id, name, adminId)
        Service->>Repository: update(id, { name, updatedBy })
        Repository->>DB: UPDATE organizations SET name, updated_by WHERE id = ?
        DB-->>Repository: Updated row

        alt Organization Found
            Repository-->>Service: Updated organization
            Service-->>API: Organization data
            API-->>Client: 200 OK { id, name, ... }
        else Organization Not Found
            Repository-->>Service: null
            Service-->>API: throw NotFoundError
            API-->>Client: 404 Not Found
        end
    else Token Invalid
        Middleware-->>Client: 401 Unauthorized
    end

Routes Layer

API routing is performed here. The protectedRoute middleware validates the JWT token and session before the handler executes. The handler extracts the organization_id path parameter, validates the request body using a Zod schema, and delegates to the organization service.

Source: apps/admin/src/routes/v1/organization.ts

Services Layer

This section describes business logic. It receives the organization ID, validated name, and the authenticated admin's ID. It delegates to the repository to update the record, setting the updatedBy audit field. If the organization is not found, it throws a NotFoundError.

Source: apps/admin/src/services/organization.ts

Repositories Layer

This section describes access to databases and external services. It performs an UPDATE query on the organizations table, setting the name and updated_by fields for the matching ID. It returns the updated record or null if no row was affected.

Source: apps/admin/src/repositories/organization.ts

Security

  • Token validated by protectedRoute middleware before handler execution
  • Session existence verified via verifySession
  • Request body validated with Zod schema to prevent malformed input
  • Path parameter validated as positive integer to prevent injection