Skip to content

Update Project

Method

REST method is adopted.

HTTP Method

PUT: Update project details

Naming Convention

To unify naming of query parameters and nodes and improve readability, snake_case is used for URIs and nodes in JSON during requests.

Request and Response

Headers

Meta information is set in HTTP headers rather than in the response body.

Request Headers

  • Authorization: Bearer <access_token>
  • Content-Type: application/json

Response Headers

  • Content-Type: application/json

Update Project

URI

Path parameter type is integer.

/api/v1/projects/{project_id}

Request Body

Request body is JSON. All fields are optional โ€” only included fields will be updated.

{
  "name": "Updated Project Name"
}

Validation Rules

Field Rule
name Optional. 1-255 characters.

Response (200 OK)

Response is JSON.

{
  "id": 1,
  "organizationId": 1,
  "name": "Updated Project Name",
  "createdAt": 1640995200000,
  "updatedAt": 1640995200000,
  "createdBy": "1111-aaaa-2222-bbbb",
  "updatedBy": "1111-aaaa-2222-bbbb",
  "deletedAt": null,
  "deletedBy": null
}

Authentication

Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito. A valid Bearer token is required in the Authorization header.

Exception Handling

Exception handling status codes are as follows.

Description Status Code Status Name
Missing or invalid token 401 Unauthorized
Project not found 404 Not Found
Internal server error 500 Internal Server Error

Process Flow

Sequence Diagram

sequenceDiagram
    participant Client
    participant Middleware as Protected Route Middleware
    participant API as Hono Router
    participant Service as Project Service
    participant DB as PostgreSQL Database

    Client->>Middleware: PUT /api/v1/projects/{project_id}
    Middleware->>Middleware: Verify JWT & session

    alt Token Valid
        Middleware-->>API: Auth info (sub)
        API->>Service: update(id, { name, actorSub })
        Service->>DB: findOneByIdOnly(id)
        DB-->>Service: Existing project

        alt Project Found
            Service->>DB: Update project record
            DB-->>Service: Updated project
            Service-->>API: Project
            API-->>Client: 200 OK
        else Project Not Found
            Service-->>API: throw NotFoundError
            API-->>Client: 404 Not Found
        end
    else Token Invalid
        Middleware-->>Client: 401 Unauthorized
    end

Routes Layer

API routing is performed here. The protectedRoute middleware validates the JWT token. The handler validates the request body and project_id path parameter via Zod schema, extracts the actor's Cognito sub, and delegates to the project service.

Source: apps/admin/src/routes/v1/project.ts

Services Layer

This section describes business logic. It verifies the project exists, then updates it with the provided fields. If name is not provided, the existing name is preserved. The actor's Cognito sub is recorded as the updater.

Source: apps/admin/src/services/project.ts

Repositories Layer

This section describes access to databases. It handles project lookup and updates.

Source: apps/admin/src/repositories/project.ts

Security

  • Token validated by protectedRoute middleware before handler execution
  • Actor's Cognito sub recorded as updatedBy for audit trail