Skip to content
Back to skills

Springboot Best Practices

ASecurity

Spring Boot 4.0 patterns for enterprise Java 25 applications

  • 43 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 9, 2026
securitygojavaspringtestingapidatabasesecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 10 files and shows the line behind each finding

Scanned September 9, 2026

npx -y skills add baekenough/oh-my-customcode --skill springboot-best-practices --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Springboot Best Practices?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Springboot Best Practices
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/baekenough-springboot-best-practices/badge)](https://www.skillsdirectory.com/skills/baekenough-springboot-best-practices)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: springboot-best-practices
description: Spring Boot 4.0 patterns for enterprise Java 25 applications
scope: core
user-invocable: false
---

## Rules

### 1. Project Structure
Layered architecture: controller (REST), service (business logic), repository (data access), model/entity, dto, config, exception.

### 2. Dependency Injection
Constructor injection preferred. Use @RequiredArgsConstructor with final fields. Avoid field injection with @Autowired.

```java
// GOOD: Constructor injection
@Service
@RequiredArgsConstructor
public class UserService {
    private final UserRepository userRepository;
    private final EmailService emailService;
}
```

### 3. REST API Design
@RestController + @RequestMapping. Use @Validated for input, ResponseEntity for responses, proper HTTP status codes.

See `examples/controller-example.java` for reference implementation.

### 4. Service Layer
Business logic in services. @Transactional boundaries at service level. Interface + implementation pattern.

See `examples/service-example.java` for reference implementation.

### 5. Data Access
Spring Data JPA. @Query or method naming for custom queries. @Entity with proper JPA annotations.

See `examples/repository-example.java` and `examples/entity-example.java` for reference implementations.

### 6. Exception Handling
@RestControllerAdvice for global handling. Domain-specific exceptions with proper HTTP status mapping.

See `examples/exception-handler-example.java` for reference implementation.

### 7. Configuration
Profile-based: application-{profile}.yml. @ConfigurationProperties for type-safe config. Externalize sensitive values.

```yaml
# application.yml
spring:
  profiles:
    active: ${SPRING_PROFILES_ACTIVE:local}
  datasource:
    url: ${DATABASE_URL}
    username: ${DATABASE_USERNAME}
    password: ${DATABASE_PASSWORD}
```

See `examples/config-properties-example.java` for type-safe configuration properties.

### 8. Security
Spring Security with SecurityFilterChain. Externalize secrets. Proper authentication/authorization patterns.

See `examples/security-config-example.java` for reference implementation.

### 9. Testing
@WebMvcTest (controller), @DataJpaTest (repository), @SpringBootTest (integration), @MockBean for mocking.

See `examples/controller-test-example.java` and `examples/repository-test-example.java` for reference implementations.

## Application

Always: constructor injection, layered architecture, DTOs, global exception handling, externalized config, proper security, layer-appropriate tests.

Files in this skill

  • SKILL.md2.5 KB
  • examples/config-properties-example.java565 B
  • examples/controller-example.java881 B
  • examples/controller-test-example.java1.2 KB
  • examples/entity-example.java481 B
  • examples/exception-handler-example.java1.1 KB
  • examples/repository-example.java584 B
  • examples/repository-test-example.java681 B
  • examples/security-config-example.java1.1 KB
  • examples/service-example.java1.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…