Hospitality engine

Rename a floor server

patch/api/servers/{id}

Name only. The section colour stays assigned by POST /api/servers, round-robin over a fixed palette: it exists to keep sections visually distinct on the map rather than to be chosen, and letting two servers land on the same hue would quietly break the thing it is for.

This endpoint did not exist until 2026-08-10, on the reasoning that "rename is delete-and-re-add, and nothing else references a server by id". The second half was wrong: book_server_assignments references it, and those are exactly what the DELETE below cascades. So fixing a typo in a name wiped every table that server held for that date, mid-service. Renaming in place keeps the assignments.

Authorization

sessionCookie
sb-qxrvgfkjyvbngipqvslu-auth-token<token>

The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.

Every request re-validates it against the Auth server (getUser()), never by decoding the cookie locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified app_metadata.company_id claim and enforced by row-level security; it is never read from request input, on any route, ever.

role (admin / staff) is deliberately not in RLS. It gates specific actions in route code, the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's own check is the enforcement.

In: cookie

Path Parameters

id*string

Server id.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X PATCH "https://example.com/api/servers/string" \  -H "Content-Type: application/json" \  -d '{    "name": "string"  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "name": "string",  "color": "string"}