Skip to content
Back to skills

Spring Controller

ASecurity

Add a Spring Boot REST controller backed by a service and DTOs

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentsgospringapi

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill spring-controller --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Spring Controller?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Spring Controller
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-spring-controller/badge)](https://www.skillsdirectory.com/skills/black141312-spring-controller)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: spring-controller
description: Add a Spring Boot REST controller backed by a service and DTOs
category: frameworks
---

# Spring Controller

Use to expose a new REST endpoint in a Spring Boot app, layering controller → service → repository with proper DTOs and status codes.

1. Define request/response DTOs (records work well) and validation annotations (`@NotNull`, `@Size`, …) — don't expose entities directly.
2. Create a `@RestController` with a class-level `@RequestMapping("/api/...")`; inject the service via constructor.
3. Add handler methods with `@GetMapping`/`@PostMapping`/etc., binding `@RequestBody`/`@PathVariable`/`@RequestParam` and `@Valid` on bodies.
4. Put business logic in a `@Service` bean; keep the controller to mapping, validation, and response shaping.
5. Return `ResponseEntity<T>` with correct status codes; handle errors centrally via `@ControllerAdvice`/`@ExceptionHandler`.
6. Run the app (`./mvnw spring-boot:run` or `./gradlew bootRun`) and exercise the endpoint with curl/HTTP client.

## Rules
- Never serialize JPA entities over the wire — map to DTOs to avoid lazy-loading and over-exposure bugs.
- Use constructor injection (final fields), not field `@Autowired`.
- Validate input with `@Valid` and surface failures as 400s via a global exception handler, not stack traces.
- Keep controllers free of persistence/transaction logic; `@Transactional` belongs in the service layer.
- Choose accurate status codes (201 + `Location` on create, 404 on missing, 204 on delete).

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…