SkillAtlasSkill 详情

rest-api-conventions

Production-grade Spring Boot skills for Claude Code and Codex.

审核状态:已审核Quality 80Security 100

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年9月8日
spring-boot-skills — production-grade Claude Code and Codex skills for Spring Boot

Production-grade Spring Boot skills for Claude Code and Codex. Drop a skill into your project and your AI coding agent instantly understands your architecture, patterns, and conventions.


skills Spring Boot Java License

Claude Code Codex Spring AI MCP Java SDK GitHub Stars


Quick Start · Skills Catalog · Before / After · Skill Anatomy · Contributing


Why this exists

AI coding agents are great at Python. They hallucinate in Spring Boot.

They generate @Autowired field injection instead of constructor injection. They use ResponseEntity<?> where you have a standard response wrapper. They ignore your existing exception hierarchy and invent a new one. They don't know your project uses Flyway, so they generate schema SQL by hand. They emit pre-GA Spring AI artifact names that no longer exist in Maven Central.

Skills fix this. A skill is a markdown file your agent reads before touching your code. It tells the agent your conventions, your stack, your gotchas — not generic Spring Boot from 2020.

flowchart LR
    A["💬 You ask:<br/>&quot;add an orders endpoint&quot;"] --> B{Agent matches<br/>skill triggers}
    B -->|"REST code?"| C["📜 rest-api-conventions"]
    B -->|"persistence?"| D["📜 spring-data-jpa"]
    C --> E["🤖 Agent codes with<br/>YOUR envelope, YOUR<br/>status mapping, YOUR<br/>pagination contract"]
    D --> E
    E --> F["✅ Code that looks like<br/>your team wrote it"]

    style A fill:#0f172a,stroke:#38bdf8,color:#e2e8f0
    style B fill:#1e293b,stroke:#94a3b8,color:#e2e8f0
    style C fill:#10241a,stroke:#6DB33F,color:#a7f3d0
    style D fill:#10241a,stroke:#6DB33F,color:#a7f3d0
    style E fill:#0f172a,stroke:#d97757,color:#e2e8f0
    style F fill:#10241a,stroke:#6DB33F,color:#a7f3d0

This repo is a collection of battle-tested skills. Copy, adapt, drop in.


🧠 Concepts

ConceptDescription
SkillsMarkdown files loaded into Claude Code or Codex context — tell the agent how to work in your codebase
CLAUDE.md / AGENTS.mdProject-level persistent memory — your agent's onboarding doc
MCP Java SDKOfficial Java SDK for building MCP servers — connect your Spring Boot app to any AI agent
Marketplace pluginsVersioned Claude Code and Codex packages for all Boot 3 or Boot 4 skills
Project templatesReady-to-adapt CLAUDE.md and AGENTS.md guidance for Boot 3 and Boot 4 projects
Planned workflowsRepeatable commands such as /generate-endpoint, /write-test, and /db-migrate are listed in the roadmap

📦 Skills

The catalog ships in two version trees — pick the folder that matches your stack. Shared topics normally have both flavors; genuinely version-specific topics may live only in the relevant tree.

FolderTarget stackCompatibility baseline
skills/spring-boot-4/Spring Boot 4.x · Spring Framework 7 · Spring Security 7 · Spring Batch 6 · Jackson 3 · Spring AI 2.0Java 17+; examples use Java 21; Boot 4.0.x and 4.1.x
skills/spring-boot-3/Spring Boot 3.x · Spring Framework 6 · Spring Security 6 · Spring Batch 5 · Jackson 2 · Spring AI 1.xJava 17+; examples use Java 21

Drop any skill folder into your agent's skills directory. Claude Code users can copy them to .claude/skills/; Codex users can adapt the same SKILL.md folders for .codex/skills/. The catalog below links to the Spring Boot 4 versions — swap spring-boot-4 for spring-boot-3 in any path if you're still on Boot 3.

The version guidance follows the Spring Boot 4 system requirements, the Spring Boot 4 migration guide, and Spring AI's compatibility guidance. Check the official release notes before upgrading a project.

Fast-moving integrations were last verified in August 2026 against Spring Boot 4.1, Spring AI 2.0, MCP Java SDK 2.0, Spring Cloud 2025.1, and Spring Cloud Gateway 5.0. Keep BOM-managed dependency versions together and recheck the linked official sources before adopting a newer release line.

Configuration

SkillDescriptionTags
configuration-propertiesTyped binding, startup validation, duration units and secret handling.configuration validation

🏗️ Architecture

SkillDescriptionTags
layered-architectureEnforces Controller → Service → Repository separation. Prevents business logic leaking into controllers or repositories.architecture
hexagonal-architecturePorts and adapters pattern for Spring Boot. Keeps domain clean of framework dependencies.architecture ddd
domain-driven-designAggregates, value objects, domain events with commit-safe publication. Includes JPA mapping conventions.ddd jpa
multi-module-mavenParent POM conventions, shared BOM, inter-module dependency rules. Prevents circular deps.maven architecture
spring-modulithModule boundaries, verification and durable event publication.architecture modulith
multi-tenancyTenant resolution, database/schema isolation, tenant-aware persistence, caches, jobs, and migrations.architecture security data

🔌 API Design

SkillDescriptionTags
rest-api-conventionsYour project's response envelope, error codes, pagination contract, versioning strategy. Fill in the template.rest api
openapi-firstGenerate controllers and DTOs from OpenAPI spec. Uses openapi-generator-maven-plugin.openapi codegen
problem-details-rfc9457RFC 9457 compliant error responses with Spring's ProblemDetail. Replaces ad-hoc error envelopes.error-handling rest
idempotency-patternsConcurrent retries, scoped request keys, replay and transaction boundaries.api transactions
hateoasSpring HATEOAS link building conventions. Teaches agent when and how to add hypermedia links.hateoas rest

🌐 Edge & Reactive

SkillDescriptionTags
spring-cloud-gatewaySecure route design, header hygiene, timeouts, rate limits, retries, and release-train compatibility.gateway spring-cloud security
webflux-reactive-patternsNon-blocking WebFlux, Reactor context, R2DBC, backpressure, cancellation, and reactive tests.webflux reactor r2dbc

🗄️ Data & Persistence

SkillDescriptionTags
spring-data-jpaBoot 4 JPA with Hibernate 7: entity modeling, Jakarta imports, relationships, projections, N+1 prevention, keyset pagination, and batch writes.jpa hibernate
flyway-migrationsMigration naming convention, safe multi-step schema changes, team workflow for concurrent migrations.flyway migrations
spring-data-redisCache-aside pattern, key naming, TTL strategy, stampede protection, serialization config.redis caching
transactional-patterns@Transactional propagation rules, self-invocation pitfall, after-commit side effects, saga pattern.transactions

📨 Messaging

SkillDescriptionTags
event-driven-messagingKafka/RabbitMQ/Pulsar/JMS contracts, idempotent consumers, outbox delivery, retries, and dead letters.messaging kafka rabbitmq

⚙️ Batch & Jobs

SkillDescriptionTags
spring-batchSpring Batch 6 chunk jobs, JDBC versus resourceless repositories, JobOperator, restartability, reader sort/thread-safety, and transaction boundaries.batch etl

🚀 Migration & Deployment

SkillDescriptionTags
spring-boot-migrationStaged Boot 3.5 → 4 migration covering modular starters, Jackson 3, tests, servers, and verification.migration spring-boot-4
container-native-deploymentBuildpacks, layered OCI images, JVM containers, GraalVM native images, AOT hints, and probes.containers graalvm aot

🧰 Framework 7 Core

SkillDescriptionTags
api-versioningSpring Framework 7 built-in API versioning: mapping versions, central request resolution, defaults, supported versions, and deprecation headers.rest api versioning
http-interface-clientsBoot 4 declarative HTTP clients with @ImportHttpServices, grouped base URLs/timeouts, and RestClient versus WebClient selection.http clients
null-safetyJSpecify nullability for Framework 7: @NullMarked, @Nullable, generic and array positions, Kotlin interop, and NullAway.null-safety jspecify
resilience-retryFramework 7 core @Retryable and @ConcurrencyLimit: enablement, backoff, no @Recover, proxy, and transaction pitfalls.resilience retry

🔒 Security

SkillDescriptionTags
spring-security-jwtJWT auth filter chain, access and refresh token validation, RBAC with method security. Opinionated starting point.security jwt
oauth2-resource-serverOAuth2 resource server config, JWT claim extraction, scope-based authorization.security oauth2

🤖 AI & MCP

SkillDescriptionTags
spring-ai-integrationSpring AI ChatClient, chat memory, RAG pipeline, structured output. Real GA artifact names — no dead pre-GA coordinates.spring-ai llm
mcp-serverBuild MCP servers with the Java SDK 2.x and Spring AI 2.0 native annotations. Tool registration, Streamable HTTP, and stdio safety.mcp ai-agents
ai-observabilityToken usage tracking, latency monitoring, prompt/response logging for Spring AI apps.observability spring-ai

📊 Operations

SkillDescriptionTags
production-observabilityActuator, Micrometer, OpenTelemetry/OTLP, health probes, structured logging, and actionable alerts.actuator micrometer opentelemetry

🧪 Testing

SkillDescriptionTags
testing-pyramidUnit → Slice → Integration conventions. @WebMvcTest, @DataJpaTest, @MockitoBean, Testcontainers.testing

⚡ Quick Start

1. Prepare your coding agent

Install Claude Code if needed:

npm install -g @anthropic-ai/claude-code

If you use Codex, confirm the CLI or desktop app command is available:

codex --version

2. Drop a skill into your project

Claude Code:

PROJECT_DIR=/path/to/my-spring-app
mkdir -p "$PROJECT_DIR/.claude/skills"
# Spring Boot 4 project
cp -r skills/spring-boot-4/rest-api-conventions "$PROJECT_DIR/.claude/skills/"
cp -r skills/spring-boot-4/spring-data-jpa "$PROJECT_DIR/.claude/skills/"

# Spring Boot 3 project — same skills, Boot 3 flavor
cp -r skills/spring-boot-3/rest-api-conventions "$PROJECT_DIR/.claude/skills/"

Codex:

PROJECT_DIR=/path/to/my-spring-app
mkdir -p "$PROJECT_DIR/.codex/skills"
# Spring Boot 4 project
cp -r skills/spring-boot-4/rest-api-conventions "$PROJECT_DIR/.codex/skills/"
cp -r skills/spring-boot-4/spring-data-jpa "$PROJECT_DIR/.codex/skills/"

# Spring Boot 3 project — same skills, Boot 3 flavor
cp -r skills/spring-boot-3/rest-api-conventions "$PROJECT_DIR/.codex/skills/"

Run these commands from the root of this repository, or replace skills/ with the path to your local clone.

For persistent project guidance, start from the matching templates:

# Codex, Spring Boot 4
cp templates/spring-boot-4/AGENTS.md "$PROJECT_DIR/AGENTS.md"

# Claude Code, Spring Boot 4
cp templates/spring-boot-4/CLAUDE.md "$PROJECT_DIR/CLAUDE.md"

Boot 3 equivalents live under templates/spring-boot-3/. Adapt commands and conventions to the project rather than using the templates unchanged.

Install from the Claude Code marketplace

This repository also exposes two marketplace plugins without duplicating the skill files:

claude plugin marketplace add rrezartprebreza/spring-boot-skills
claude plugin install spring-boot-4-skills@spring-boot-skills
# or for a Boot 3 project:
claude plugin install spring-boot-3-skills@spring-boot-skills

The marketplace manifest is .claude-plugin/marketplace.json. Validate it locally with claude plugin validate .. The repository can be submitted to Anthropic's Claude Code community marketplace; approval is a separate review step. GitHub Marketplace is intended for GitHub Apps and Actions, so this skills repository should use GitHub releases and the Claude marketplace instead.

Install as a Codex plugin

Codex uses its own plugin manifest and marketplace catalog. Add this repository and install the version that matches your application:

codex plugin marketplace add rrezartprebreza/spring-boot-skills
codex plugin add spring-boot-4-skills@spring-boot-skills
# or for a Boot 3 project:
codex plugin add spring-boot-3-skills@spring-boot-skills

The Codex package metadata lives in .agents/plugins/marketplace.json and the two plugin manifests under plugins/. Direct copying into .codex/skills/ remains supported for projects that do not use plugins.

3. Tell your agent what you want

claude
> Generate a CRUD endpoint for the Order entity following our REST conventions

or:

codex
> Generate a CRUD endpoint for the Order entity following our REST conventions

That's it. Your agent reads the skill before writing a single line.


⚔️ Before / After

The value of these skills is not generic Spring Boot advice. The value is preventing the small mistakes AI agents make when they do not know your backend conventions.

❌ Without a skill✅ With layered-architecture + rest-api-conventions
@RestController
public class OrderController {
    @Autowired
    private OrderRepository repository;

    @PostMapping("/orders")
    public ResponseEntity<?> create(
            @RequestBody Order order) {
        return ResponseEntity.ok(
            repository.save(order));
    }
}
@RestController
@RequestMapping("/api/v1/orders")
@RequiredArgsConstructor
class OrderController {
    private final OrderService orderService;

    @PostMapping
    ResponseEntity<ApiResponse<OrderResponse>> create(
            @Valid @RequestBody CreateOrderRequest request) {
        OrderResponse response = orderService.create(request);
        return ResponseEntity.status(HttpStatus.CREATED)
            .body(ApiResponse.ok(response));
    }
}
  • Business logic leaks into the controller
  • No request DTO or validation boundary
  • Repository called directly from the web layer
  • Response shape ignores project conventions
  • Status codes left to framework defaults
  • Controller as a pure HTTP adapter
  • Service owns the business rules
  • DTO validation at the boundary
  • Consistent response envelope
  • Correct 201 Created semantics

📐 Skill Anatomy

Every skill in this repo follows the same structure:

skills/spring-boot-4/rest-api-conventions/
├── SKILL.md          ← the skill: trigger description + conventions + gotchas
├── agents/
│   └── openai.yaml   ← Codex skill-list metadata and default prompt
├── examples/         ← good and bad examples, side by side
│   ├── good-controller.java
│   └── bad-controller.java
└── templates/        ← copy-paste starting points
    ├── ApiResponse.java
    └── GlobalExceptionHandler.java

SKILL.md has two critical parts:

---
name: rest-api-conventions
description: >
  Use when generating REST controllers, response objects, DTOs, or error handlers.
  Defines the project's response envelope, HTTP status mapping, and error code conventions.
---

## Conventions
...

The description is a trigger — write it as "use when [condition]", not as a summary. This is what makes the agent actually load the skill.

The Gotchas section at the bottom of each skill is the secret weapon: a running list of the exact mistakes agents make in that domain, phrased as Agent does X — do Y instead.


💡 Tips from the trenches

The Gotchas section is the most valuable part — add to it every time the agent does something wrong. Your future self will thank you.

Don't describe what Spring Boot already knows. Skills should push your agent out of its default behavior, not repeat the docs.

Be opinionated about your project. Generic Spring Boot best practices belong in a blog post. Skills belong in your agent skills folder.

Fork this repo and customize. Every team's conventions are different. These are starting points, not gospel.

Combine with CLAUDE.md or AGENTS.md. Project guidance stores build commands, verification, and architecture decisions. Skills provide reusable domain-specific workflows.

Anti-patternFix
Giant SKILL.md with everythingSplit into focused skills, one concern each
"Always use constructor injection"Already a strong agent default — skip it
No examplesAdd a good.java and bad.java — the contrast is what teaches
Prescriptive step-by-step instructionsGive goals and constraints, let agent decide how
Never updatingAdd a Gotchas section, update it when agent fails

🔥 Hot: MCP Server Skill

The mcp-server skill is the most powerful one here.

It teaches your agent to build production-ready MCP servers on MCP Java SDK 2.x and the Spring AI 2.0 starters - the same protocol used by Claude, Codex, Cursor, VS Code, and other major AI coding tools.

The MCP skill distinguishes native MCP annotations such as @McpTool from Spring AI model tool-calling annotations such as @Tool. Use the native MCP path when exposing server tools.

// What the agent generates with the skill loaded —
// real GA API: spring-ai-starter-mcp-server + annotation scanning
@Component
public class OrderMcpTools {

    private final OrderService orderService;

    @McpTool(name = "get_order",
             description = "Get a single order by ID including all line items and status history")
    public OrderResponse getOrder(
            @McpToolParam(description = "UUID of the order", required = true) String orderId) {
        return OrderResponse.from(orderService.findById(UUID.fromString(orderId)));
    }
}

Without the skill, the agent guesses: dead pre-GA artifact names, removed SDK constructors, @Tool instead of native @McpTool, or System.out logging that corrupts stdio transport.


🗺️ Roadmap

  • Skills for Spring Batch
  • Spring Boot 4 versions of all 33 skills (skills/spring-boot-4/)
  • Skills for Spring Cloud Gateway
  • Skills for Spring WebFlux / reactive patterns
  • Skills for multi-tenancy
  • Spring Boot 3 → 4 migration skill
  • Production observability skill
  • Event-driven messaging skill
  • Container and native deployment skill
  • CLAUDE.md and AGENTS.md templates for Boot 3 and Boot 4
  • /generate-endpoint command
  • /write-test command
  • /db-migrate command
  • Integration with Hatch background job library
  • Integration with SpringPulse observability

🤝 Contributing

Skills get better with real-world use. If you find a gap — the agent did something stupid in your Spring Boot project — open a PR and add it to the Gotchas section of the relevant skill.

Before opening a PR, install the validator dependency in a virtual environment and run:

python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -r scripts/requirements.txt
bash scripts/validate-skills.sh

The validator parses YAML safely, rejects duplicate keys, and checks both version trees, metadata, README links and marketplace packaging. There are 33 topics with Boot 3 and Boot 4 variants.

Executable verification

The behavior fixture compiles the shipped JWT, Problem Details, pagination and configuration templates. Its tests cover token/account rejection, HTTP error contracts, configuration startup validation, and JPA/Flyway against PostgreSQL. CI runs Boot 3.5 and Boot 4.1 with Java 17 and 21. The MCP compilation fixture remains separate. This is targeted coverage, not a claim that every example in the catalog has executable tests.

Agent evaluations provide repeatable prompts and review criteria for Claude Code and Codex. Transcript collection and human review are separate from CI validation; a successful model invocation is not a benchmark pass.

1. Fork the repo
2. Copy an existing skill as a template
3. Fill in conventions, examples, gotchas
4. PR with a one-line description of what problem it solves

🛠️ More from the same workbench

RepoDescription
HatchMulti-module background job library for Spring Boot — REST polling, retry, Redis/JDBC backends, SSE dashboard
SpringPulseRuntime observability for @Scheduled methods — AOP interception, WebSocket dashboard
rest-api-generatorCLI that scaffolds Spring Boot REST APIs from plain English prompts

If a skill saved your agent from writing @Autowired field injection today — ⭐ star the repo.


spring-boot · java · claude-code · codex · mcp · spring-ai · skills · developer-tools


Built by @rrezartprebreza · Pristina, Kosovo


LinkedIn

其他

低风险

  • 来源需自行核对维护者身份。
  • 未检测到明显脚本安装指令。
  • 未检测到明显外部权限要求。
  • 未检测到高风险命令。
  • 扫描发现:0 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/rrezartprebreza/spring-boot-skills.git
  3. 将 "skills/spring-boot-4/rest-api-conventions" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/rrezartprebreza/spring-boot-skills.git
  3. 将 "skills/spring-boot-4/rest-api-conventions" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/rrezartprebreza/spring-boot-skills.git
  3. 将 "skills/spring-boot-4/rest-api-conventions" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/rrezartprebreza/spring-boot-skills.git
  3. 将 "skills/spring-boot-4/rest-api-conventions" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/rrezartprebreza/spring-boot-skills.git
  3. 将 "skills/spring-boot-4/rest-api-conventions" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: rest-api-conventions
description: >
  Use when generating REST controllers, DTOs, success response contracts, pagination, HTTP status
  mapping, or API versioning. For RFC 9457 exception and error response formatting, use
  problem-details-rfc9457 unless the project explicitly requires a legacy error envelope.

REST API Conventions

Project Contract

Inspect existing controllers, tests and OpenAPI before choosing a response contract. Preserve the project's IDs, response shape and versioning strategy. Do not migrate unrelated endpoints while adding one route. The envelope below is an optional convention for a project that uses it; plain success DTOs are equally valid. A 204 response has no body.

Success and error formats are independent: an existing success envelope can coexist with RFC 9457 errors. Use one consistent error policy; choose the legacy error examples below only when the project already requires that format.

Example success envelope:

{
  "success": true,
  "data": { },
  "error": null,
  "timestamp": "2026-04-13T10:00:00Z"
}

Error response:

{
  "success": false,
  "data": null,
  "error": {
    "code": "ORDER_NOT_FOUND",
    "message": "Order with id 123 not found",
    "details": []
  },
  "timestamp": "2026-04-13T10:00:00Z"
}

ApiResponse Wrapper

@JsonInclude(JsonInclude.Include.NON_NULL)
public record ApiResponse<T>(
    boolean success,
    T data,
    ApiError error,
    Instant timestamp
) {
    public static <T> ApiResponse<T> ok(T data) {
        return new ApiResponse<>(true, data, null, Instant.now());
    }

    public static <T> ApiResponse<T> error(String code, String message) {
        return new ApiResponse<>(false, null, new ApiError(code, message, List.of()), Instant.now());
    }
}

public record ApiError(String code, String message, List<String> details) {}

HTTP Status Mapping

ScenarioStatus
GET — found200
POST — created resource201
PUT/PATCH — updated200
DELETE — deleted204 (no body)
Validation failure400
Unauthenticated401
Forbidden403
Not found404
Conflict (duplicate)409
Unhandled server error500

URL Conventions

  • Plural nouns for resources: /orders, /users, /products
  • Kebab-case for multi-word: /order-items, not /orderItems
  • Versioning in path: /api/v1/orders — route with native API versioning (below), don't duplicate controllers per version
  • Nested resources max 2 levels: /orders/{id}/items ✅, /orders/{id}/items/{itemId}/notes ❌ — flatten to /order-item-notes/{id}
  • IDs: preserve the existing ID type. UUIDs are an option, not an authorization mechanism.
GET    /api/v1/orders              → list (paginated)
POST   /api/v1/orders              → create
GET    /api/v1/orders/{id}         → get one
PUT    /api/v1/orders/{id}         → full update
PATCH  /api/v1/orders/{id}         → partial update
DELETE /api/v1/orders/{id}         → delete
GET    /api/v1/orders/{id}/items   → nested resource

API Versioning (Native in Boot 4)

Spring Boot 4 / Framework 7 route requests by API version natively — never hand-roll it with duplicated V1/V2 controllers, custom RequestConditions, or header if checks.

Pick ONE resolution strategy per API (path segment, header, query param, or media-type param):

spring:
  mvc:                        # WebFlux: same keys under spring.webflux.apiversion.*
    apiversion:
      use:
        path-segment: 1       # index of the path segment holding the version: /api/v1.1/orders
        # header: X-API-Version
        # query-parameter: version
      supported: [1.0, 1.1, 2.0]
      default: 1.0

Route with the version attribute on any mapping annotation:

@GetMapping("/{id}")                            // no version — matches any
public OrderResponse getById(@PathVariable UUID id) { ... }

@GetMapping(value = "/{id}", version = "1.1")   // fixed: matches 1.1 only
public OrderResponseV1_1 getByIdV1_1(@PathVariable UUID id) { ... }

@GetMapping(value = "/{id}", version = "1.2+")  // baseline: 1.2 and supported versions above
public OrderResponseV2 getByIdV2(@PathVariable UUID id) { ... }

The most specific matching version wins. Unsupported version → 400 (InvalidApiVersionException); missing required version → 400 (MissingApiVersionException).

  • Deprecate old versions with StandardApiVersionDeprecationHandler (register via WebMvcConfigurer#configureApiVersioning(ApiVersionConfigurer)) — it emits RFC 9745 Deprecation/Sunset and Link response headers
  • Clients: RestClient/WebClient and HTTP interface clients send versions too — configure .apiVersionInserter(ApiVersionInserter.fromHeader("X-API-Version").build()) and .defaultVersion("1.2") on the builder, matching the server's strategy

Pagination

{
  "success": true,
  "data": {
    "content": [...],
    "page": 0,
    "size": 20,
    "totalElements": 150,
    "totalPages": 8,
    "last": false
  }
}

Query params: ?page=0&size=20&sort=createdAt,desc

Use Spring Data Pageable in controllers:

@GetMapping
public ApiResponse<PageResponse<OrderResponse>> list(Pageable pageable) {
    return ApiResponse.ok(PageResponse.from(orderService.findAll(pageable).map(OrderResponse::from)));
}

Cap the page size. A bare Pageable accepts ?size=100000 from any client — one request can drag your whole table into memory. Spring's default cap is 2000, still too high for most APIs:

spring:
  data:
    web:
      pageable:
        default-page-size: 20
        max-page-size: 100   # requests above this are silently clamped

The compiled PageResponse fixes the JSON pagination contract. Mapping entities to DTOs alone does not stabilize Spring Data PageImpl serialization. Spring Data's org.springframework.data.web.PagedModel is another option when its shape fits the API. Validate sort fields against an allowlist and add an ID tie-breaker to non-unique sorts.

Legacy Envelope Exception Handler

@RestControllerAdvice
@RequiredArgsConstructor
public class GlobalExceptionHandler {

    @ExceptionHandler(EntityNotFoundException.class)
    public ResponseEntity<ApiResponse<Void>> handleNotFound(EntityNotFoundException ex) {
        return ResponseEntity.status(404).body(ApiResponse.error("NOT_FOUND", ex.getMessage()));
    }

    @ExceptionHandler(MethodArgumentNotValidException.class)
    public ResponseEntity<ApiResponse<Void>> handleValidation(MethodArgumentNotValidException ex) {
        List<String> details = ex.getBindingResult().getFieldErrors().stream()
            .map(e -> e.getField() + ": " + e.getDefaultMessage()).toList();
        return ResponseEntity.status(400)
            .body(new ApiResponse<>(false, null, new ApiError("VALIDATION_FAILED", "Invalid input", details), Instant.now()));
    }

    @ExceptionHandler(Exception.class)
    public ResponseEntity<ApiResponse<Void>> handleGeneric(Exception ex) {
        return ResponseEntity.status(500).body(ApiResponse.error("INTERNAL_ERROR", "An unexpected error occurred"));
    }
}

Gotchas

  • Agent imposes a new envelope - preserve the existing success contract.
  • Agent invents competing error handlers - use the project's established error contract.
  • Agent puts exception handlers in controllers — always use @RestControllerAdvice
  • Agent changes ID types while adding an endpoint - retain the existing ID scheme.
  • Agent accepts unbounded Pageable — set spring.data.web.pageable.max-page-size or one request can pull the whole table
  • Agent serializes PageImpl directly - map entities to DTOs, then wrap in PageResponse.
  • Agent hand-rolls versioning with duplicated /v1//v2 controllers — Boot 4 has native API versioning: version attribute on mappings + spring.mvc.apiversion.*
  • Agent adds spring-boot-starter-web — renamed spring-boot-starter-webmvc in Boot 4 (MockMvc tests: spring-boot-starter-webmvc-test)
  • Agent uses @JsonComponent or Jackson2ObjectMapperBuilderCustomizer to tune serialization — Jackson 3 renames: @JacksonComponent, JsonMapperBuilderCustomizer; declare JsonMapper beans, not generic ObjectMapper
  • Agent tests controllers with bare @SpringBootTest expecting MockMvc — Boot 4 no longer auto-provides it; add @AutoConfigureMockMvc (or the new RestTestClient via @AutoConfigureRestTestClient)

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!