Medium15 minSpring Boot Fundamentals
UpdatedAug 5, 2026
Edit

Spring Boot REST Validation

Question Variations

  • "Where should request validation run in a Spring controller?"
  • "Why not accept an entity directly in a REST endpoint?"
  • "How do you return validation errors consistently?"

Why This Is Asked

This question assesses API boundary design: typed request DTOs, validation, status codes, and separation from persistence models.

Key Concepts

  • Controllers bind requests to dedicated DTOs.
  • Jakarta Bean Validation validates untrusted inputs with @Valid.
  • Validation, domain conflicts, and authorization are separate concerns.
  • Response contracts should not expose JPA entities directly by default.

Question Variations

  • “Where should request validation run in a Spring controller?”
  • “Why not accept an entity directly in a REST endpoint?”
  • “How do you return validation errors consistently?”

Answers by Technology

+ Add Variant
Spring BootImprove this answer ✏️

Expected Answer (Spring Boot 4.1.0 / Java 17+)

Bind request data to a dedicated DTO and validate it with Jakarta Bean Validation using @Valid. Controllers should translate an HTTP request into a valid application command, while services own domain rules and persistence. Do not expose JPA entities as public contracts by default because lazy fields, persistence concerns, and future schema changes leak through the API.

Why It Matters

Boundary validation gives clients clear errors and protects domain and database code from malformed input.

Code Example

record CreateUserRequest(@NotBlank @Email String email) {}
@RestController
class UserController {
  @PostMapping("/users")
  ResponseEntity<Void> create(@Valid @RequestBody CreateUserRequest request) {
    return ResponseEntity.status(HttpStatus.CREATED).build();
  }
}

Common Mistakes

  • Binding a persistence entity directly: Client fields can affect persistence state unexpectedly.
  • Skipping @Valid: Constraints are never invoked for the request body.

Follow-up Questions

  • Where should a duplicate-email rule live? (Answer: In domain/service logic, typically producing a conflict.)
  • What status fits malformed input? (Answer: 400 Bad Request.)