コンテンツにスキップ

組織取得

メソッド

REST メソッドを採用しています。

HTTP メソッド

GET: ID による単一組織の取得

命名規則

クエリパラメータとノードの命名を統一し、可読性を向上させるため、リクエスト時の URI と JSON 内のノードには snake_case を使用します。

リクエストとレスポンス

ヘッダー

メタ情報はレスポンスボディではなく、HTTP ヘッダーに設定されます。

リクエストヘッダー

  • Authorization: Bearer <access_token>
  • Content-Type: application/json

レスポンスヘッダー

  • Content-Type: application/json

組織取得

URI

パスパラメータの型は integer です。

/api/v1/organizations/{organization_id}

パスパラメータ

名前 型 説明
organization_id integer 必須。組織を識別する正の整数。

レスポンス(200 OK)

レスポンスは JSON です。

{
  "id": 1,
  "name": "Example Organization",
  "createdAt": 1640995200000,
  "updatedAt": 1640995200000,
  "createdBy": "1111-aaaa-2222-bbbb",
  "updatedBy": "1111-aaaa-2222-bbbb",
  "deletedAt": null,
  "deletedBy": null
}

認証要件

Amazon Cognito が発行する JSON Web Token(JWT)を用いた認証です。Authorization ヘッダーに有効な Bearer トークンが必要です。

例外処理

例外時のステータスコードは次のとおりです。

説明 ステータスコード ステータス名
トークンが欠落または無効 401 Unauthorized
組織が見つからない 404 Not Found
サーバ内部エラー 500 Internal Server Error

処理フロー

シーケンス図

sequenceDiagram
    participant Client
    participant Middleware as Protected Route Middleware
    participant API as Hono Router
    participant Service as Organization Service
    participant Repository as Organization Repository
    participant DB as PostgreSQL Database

    Client->>Middleware: GET /api/v1/organizations/{organization_id}
    Middleware->>Middleware: Extract Bearer token
    Middleware->>Middleware: Verify JWT & session

    alt Token Valid
        Middleware-->>API: Auth info (sub, adminId)
        API->>Service: getById(id)
        Service->>Repository: findOneById(id)
        Repository->>DB: SELECT FROM organizations WHERE id = ?
        DB-->>Repository: Organization row

        alt Organization Found
            Repository-->>Service: Organization record
            Service-->>API: Organization data
            API-->>Client: 200 OK { id, name, ... }
        else Organization Not Found
            Repository-->>Service: null
            Service-->>API: throw NotFoundError
            API-->>Client: 404 Not Found
        end
    else Token Invalid
        Middleware-->>Client: 401 Unauthorized
    end

Routes 層

ルーティングはここで行います。protectedRoute ミドルウェアが JWT とセッションを検証してからハンドラが実行されます。ハンドラは organization_id パスパラメータを取り出し、正の整数として検証してから組織サービスに委譲します。

ソース: apps/admin/src/routes/v1/organization.ts

Services 層

ビジネスロジックの説明です。組織 ID を受け取りリポジトリでレコードを検索します。組織が見つからない場合は NotFoundError を送出します。

ソース: apps/admin/src/services/organization.ts

Repositories 層

データベースおよび外部サービスへのアクセスです。主キー ID で organizations テーブルを SELECT し、該当行または null を返します。

ソース: apps/admin/src/repositories/organization.ts

セキュリティ

  • ハンドラ実行前に protectedRoute ミドルウェアがトークンを検証します
  • verifySession によりセッションの存在を確認します
  • パスパラメータは正の整数として検証され、インジェクションを防ぎます