Update Organization
Method
REST method is adopted.
HTTP Method
PUT: Update an existing organization
Naming Convention
To unify naming of query parameters and nodes and improve readability, snake_case is used for URIs and nodes in JSON during requests.
Request and Response
Headers
Meta information is set in HTTP headers rather than in the response body.
Request Headers
Authorization:Bearer <access_token>Content-Type:application/json
Response Headers
Content-Type:application/json
Update Organization
URI
Path parameter type is integer.
Path Parameters
| Name | Type | Description |
|---|---|---|
| organization_id | integer | Required. Must be a positive integer identifying the organization. |
Request Body
Request body is JSON.
Validation Rules
| Field | Rule |
|---|---|
| name | Required. Must be a string between 1 and 255 characters. |
Response (200 OK)
Response is JSON.
{
"id": 1,
"name": "Updated Organization Name",
"createdAt": 1640995200000,
"updatedAt": 1641081600000,
"createdBy": "1111-aaaa-2222-bbbb",
"updatedBy": "3333-cccc-4444-dddd",
"deletedAt": null,
"deletedBy": null
}
Authentication
Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito. A valid Bearer token is required in the Authorization header.
Exception Handling
Exception handling status codes are as follows.
| Description | Status Code | Status Name |
|---|---|---|
| Missing or invalid token | 401 | Unauthorized |
| Organization not found | 404 | Not Found |
| Internal server error | 500 | Internal Server Error |
Process Flow
Sequence Diagram
sequenceDiagram
participant Client
participant Middleware as Protected Route Middleware
participant API as Hono Router
participant Service as Organization Service
participant Repository as Organization Repository
participant DB as PostgreSQL Database
Client->>Middleware: PUT /api/v1/organizations/{organization_id}
Middleware->>Middleware: Extract Bearer token
Middleware->>Middleware: Verify JWT & session
alt Token Valid
Middleware-->>API: Auth info (sub, adminId)
API->>API: Validate request body (Zod)
API->>Service: update(id, name, adminId)
Service->>Repository: update(id, { name, updatedBy })
Repository->>DB: UPDATE organizations SET name, updated_by WHERE id = ?
DB-->>Repository: Updated row
alt Organization Found
Repository-->>Service: Updated organization
Service-->>API: Organization data
API-->>Client: 200 OK { id, name, ... }
else Organization Not Found
Repository-->>Service: null
Service-->>API: throw NotFoundError
API-->>Client: 404 Not Found
end
else Token Invalid
Middleware-->>Client: 401 Unauthorized
end
Routes Layer
API routing is performed here. The protectedRoute middleware validates the JWT token and session before the handler executes. The handler extracts the organization_id path parameter, validates the request body using a Zod schema, and delegates to the organization service.
Source: apps/admin/src/routes/v1/organization.ts
Services Layer
This section describes business logic. It receives the organization ID, validated name, and the authenticated admin's ID. It delegates to the repository to update the record, setting the updatedBy audit field. If the organization is not found, it throws a NotFoundError.
Source: apps/admin/src/services/organization.ts
Repositories Layer
This section describes access to databases and external services. It performs an UPDATE query on the organizations table, setting the name and updated_by fields for the matching ID. It returns the updated record or null if no row was affected.
Source: apps/admin/src/repositories/organization.ts
Security
- Token validated by
protectedRoutemiddleware before handler execution - Session existence verified via
verifySession - Request body validated with Zod schema to prevent malformed input
- Path parameter validated as positive integer to prevent injection