リクエストとレスポンスの検証
受信リクエストのデータ検証を実装し、一貫性のあるエラーレスポンスを返します。
「リクエストとレスポンスの検証」はCoddyKit上の無料Spring Boot 4 Microservices & REST APIsレッスンです。 これはレッスン1/3です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSpring Boot 4 Microservices & REST APIs学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Spring Boot 4 Microservices & REST APIsコースには全3レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Why Validate Requests?
When building REST APIs, clients send data to your server. This data often needs to meet certain rules, like a field not being empty, or a number being within a specific range.
- Data Integrity: Ensures your database stores only valid information.
- Security: Prevents malicious or malformed data from causing issues.
- User Experience: Provides clear, immediate feedback to clients when their input is incorrect.
Validation is crucial for robust and reliable APIs.
Spring's Validation Tools
Spring Boot makes data validation easy by integrating with the Jakarta Bean Validation API (JSR 380). You'll primarily use the @Valid annotation in your controller methods.
Common validation annotations include:
@NotNull: Field must not be null.@NotBlank: String must not be null and must contain at least one non-whitespace character.@Size(min=X, max=Y): String or collection size must be within range.@Min(X),@Max(Y): Numeric value must be within range.@Email: String must be a valid email format.
Data Transfer Objects (DTOs)
For incoming request bodies, it's best practice to use a Data Transfer Object (DTO). A DTO is a simple Java class that mirrors the structure of the data you expect from the client.
You apply validation annotations directly to the fields within your DTO. This keeps your controller clean and separates validation logic from business logic.
Implementing Basic Validation
Let's create a ProductRequest DTO with some validation rules and use it in a Spring Boot controller. The @Valid annotation triggers the validation.
Try sending a request with an empty name or a price less than 1.
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.web.bind.annotation.*;
import jakarta.validation.Valid;
import jakarta.validation.constraints.NotBlank;
import jakarta.validation.constraints.Min;
// DTO for product creation request
class ProductRequest {
@NotBlank
private String name;
@Min(1)
private double price;
// Getters and Setters
public String getName() { return name; }
public void setName(String name) { this.name = name; }
public double getPrice() { return price; }
public void setPrice(double price) { this.price = price; }
}
@RestController
@RequestMapping("/api/products")
class ProductController {
@PostMapping
public String createProduct(@Valid @RequestBody ProductRequest productRequest) {
// If validation passes, process the product request
return "Product '" + productRequest.getName() +
"' with price " + productRequest.getPrice() +
" created successfully!";
}
}
@SpringBootApplication
public class Main {
public static void main(String[] args) {
SpringApplication.run(Main.class, args);
}
}Customizing Error Messages
The default validation error messages can sometimes be generic. You can provide your own custom messages for each annotation to make them more user-friendly and specific to your application.
Just add the message attribute to the validation annotation, like this: @NotBlank(message="Product name is required").
Custom Message Example
Let's update our ProductRequest DTO to include custom error messages. This helps clients understand exactly what went wrong with their input.
Run this and try the previous invalid inputs again. You should see your custom messages.
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.web.bind.annotation.*;
import jakarta.validation.Valid;
import jakarta.validation.constraints.NotBlank;
import jakarta.validation.constraints.Min;
// DTO for product creation request with custom messages
class ProductRequest {
@NotBlank(message = "Product name cannot be empty")
private String name;
@Min(value = 1, message = "Product price must be at least 1")
private double price;
// Getters and Setters
public String getName() { return name; }
public void setName(String name) { this.name = name; }
public double getPrice() { return price; }
public void setPrice(double price) { this.price = price; }
}
@RestController
@RequestMapping("/api/products")
class ProductController {
@PostMapping
public String createProduct(@Valid @RequestBody ProductRequest productRequest) {
return "Product '" + productRequest.getName() +
"' with price " + productRequest.getPrice() +
" created successfully!";
}
}
@SpringBootApplication
public class Main {
public static void main(String[] args) {
SpringApplication.run(Main.class, args);
}
}Handling Validation Exceptions
When validation fails, Spring automatically throws a MethodArgumentNotValidException. By default, Spring handles this by returning an HTTP 400 Bad Request status with a simple error body.
However, for a consistent API, you'll want to customize this error response. This means catching the exception and formatting the response in a structured way, often with specific error codes or details.
Global Error Handler
To provide a uniform error response across your entire API, you can use a Global Error Handler. This is typically a class annotated with @ControllerAdvice.
Inside this class, you define methods annotated with @ExceptionHandler to catch specific exception types, like MethodArgumentNotValidException, and return a custom ResponseEntity.
Error Handling in Action
Here's how to create a global error handler that catches validation exceptions and returns a structured JSON error response. This improves API consistency and makes error handling easier for clients.
Run this code and try sending an invalid product request. Observe the structured error response.
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.MethodArgumentNotValidException;
import org.springframework.web.bind.annotation.*;
import jakarta.validation.Valid;
import jakarta.validation.constraints.NotBlank;
import jakarta.validation.constraints.Min;
import org.springframework.validation.FieldError;
import java.util.HashMap;
import java.util.Map;
// DTO for product creation request
class ProductRequest {
@NotBlank(message = "Product name cannot be empty")
private String name;
@Min(value = 1, message = "Product price must be at least 1")
private double price;
// Getters and Setters
public String getName() { return name; }
public void setName(String name) { this.name = name; }
public double getPrice() { return price; }
public void setPrice(double price) { this.price = price; }
}
// Custom Error Response DTO
class ErrorResponse {
private int status;
private String message;
private Map<String, String> errors;
public ErrorResponse(int status, String message, Map<String, String> errors) {
this.status = status;
this.message = message;
this.errors = errors;
}
// Getters
public int getStatus() { return status; }
public String getMessage() { return message; }
public Map<String, String> getErrors() { return errors; }
}
@RestController
@RequestMapping("/api/products")
class ProductController {
@PostMapping
public String createProduct(@Valid @RequestBody ProductRequest productRequest) {
return "Product '" + productRequest.getName() +
"' with price " + productRequest.getPrice() +
" created successfully!";
}
}
@ControllerAdvice
class GlobalExceptionHandler {
@ExceptionHandler(MethodArgumentNotValidException.class)
@ResponseStatus(HttpStatus.BAD_REQUEST)
public ResponseEntity<ErrorResponse> handleValidationExceptions(
MethodArgumentNotValidException ex) {
Map<String, String> errors = new HashMap<>();
ex.getBindingResult().getAllErrors().forEach((error) -> {
String fieldName = ((FieldError) error).getField();
String errorMessage = error.getDefaultMessage();
errors.put(fieldName, errorMessage);
});
ErrorResponse errorResponse = new ErrorResponse(
HttpStatus.BAD_REQUEST.value(),
"Validation failed",
errors
);
return new ResponseEntity<>(errorResponse, HttpStatus.BAD_REQUEST);
}
}
@SpringBootApplication
public class Main {
public static void main(String[] args) {
SpringApplication.run(Main.class, args);
}
}Validation Quick Check
Consider a DTO field: @Size(min = 5, max = 10, message = "Length must be between 5 and 10") String code;
Which input for code would cause a validation error?
Recap: Validation & Errors
In this lesson, you learned how to implement robust request validation in Spring Boot and provide consistent error responses.
- We used
@Validand standard bean validation annotations like@NotBlankand@Minwith DTOs. - You saw how to customize validation error messages.
- We implemented a
@ControllerAdviceglobal error handler to catchMethodArgumentNotValidExceptionand return structured, user-friendly error responses.
Well done! Consistent validation and error handling are key for a professional API.
よくある質問
「リクエストとレスポンスの検証」レッスンは無料ですか?
はい。「リクエストとレスポンスの検証」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Spring Boot 4 Microservices & REST APIsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Spring Boot 4 Microservices & REST APIsコースには全3レッスンが含まれています。
「リクエストとレスポンスの検証」で何を学びますか?
受信リクエストのデータ検証を実装し、一貫性のあるエラーレスポンスを返します。 ブラウザで直接実行するハンズオンコードでSpring Boot 4 Microservices & REST APIsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Spring Boot 4 Microservices & REST APIsを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのSpring Boot 4 Microservices & REST APIsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/3です。
「リクエストとレスポンスの検証」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このSpring Boot 4 Microservices & REST APIsレッスンでコードを書いて実行できますか?
はい。すべてのSpring Boot 4 Microservices & REST APIsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。
このコースのすべてのレッスン
- リクエストとレスポンスの検証
- ページネーションとソート
- RESTにおけるHATEOASの原則