Update Project
Method
REST method is adopted.
HTTP Method
PUT: Update project details
Naming Convention
To unify naming of query parameters and nodes and improve readability, snake_case is used for URIs and nodes in JSON during requests.
Request and Response
Headers
Meta information is set in HTTP headers rather than in the response body.
Request Headers
Authorization:Bearer <access_token>Content-Type:application/json
Response Headers
Content-Type:application/json
Update Project
URI
Path parameter type is integer.
Request Body
Request body is JSON. All fields are optional โ only included fields will be updated.
Validation Rules
| Field | Rule |
|---|---|
| name | Optional. 1-255 characters. |
Response (200 OK)
Response is JSON.
{
"id": 1,
"organizationId": 1,
"name": "Updated Project Name",
"createdAt": 1640995200000,
"updatedAt": 1640995200000,
"createdBy": "1111-aaaa-2222-bbbb",
"updatedBy": "1111-aaaa-2222-bbbb",
"deletedAt": null,
"deletedBy": null
}
Authentication
Authentication is performed using JSON Web Tokens (JWT) issued by Amazon Cognito. A valid Bearer token is required in the Authorization header.
Exception Handling
Exception handling status codes are as follows.
| Description | Status Code | Status Name |
|---|---|---|
| Missing or invalid token | 401 | Unauthorized |
| Project not found | 404 | Not Found |
| Internal server error | 500 | Internal Server Error |
Process Flow
Sequence Diagram
sequenceDiagram
participant Client
participant Middleware as Protected Route Middleware
participant API as Hono Router
participant Service as Project Service
participant DB as PostgreSQL Database
Client->>Middleware: PUT /api/v1/projects/{project_id}
Middleware->>Middleware: Verify JWT & session
alt Token Valid
Middleware-->>API: Auth info (sub)
API->>Service: update(id, { name, actorSub })
Service->>DB: findOneByIdOnly(id)
DB-->>Service: Existing project
alt Project Found
Service->>DB: Update project record
DB-->>Service: Updated project
Service-->>API: Project
API-->>Client: 200 OK
else Project Not Found
Service-->>API: throw NotFoundError
API-->>Client: 404 Not Found
end
else Token Invalid
Middleware-->>Client: 401 Unauthorized
end
Routes Layer
API routing is performed here. The protectedRoute middleware validates the JWT token. The handler validates the request body and project_id path parameter via Zod schema, extracts the actor's Cognito sub, and delegates to the project service.
Source: apps/admin/src/routes/v1/project.ts
Services Layer
This section describes business logic. It verifies the project exists, then updates it with the provided fields. If name is not provided, the existing name is preserved. The actor's Cognito sub is recorded as the updater.
Source: apps/admin/src/services/project.ts
Repositories Layer
This section describes access to databases. It handles project lookup and updates.
Source: apps/admin/src/repositories/project.ts
Security
- Token validated by
protectedRoutemiddleware before handler execution - Actor's Cognito sub recorded as
updatedByfor audit trail