输入验证与错误处理
为传入请求实现数据验证,并创建全局异常处理器,以实现稳健的错误管理。
输入验证与错误处理 是 CoddyKit 上的免费 Spring Boot 4 Complete Guide 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Spring Boot 4 Complete Guide 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Spring Boot 4 Complete Guide 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Why Validate API Inputs?
When building RESTful APIs, receiving data from clients is common. But what if that data isn't quite right?
Input validation is the process of ensuring that the data your API receives conforms to expected rules and formats before it's processed. It's crucial for:
- Data Integrity: Ensuring only valid data enters your system.
- Security: Preventing malicious inputs (like SQL injection or XSS).
- Reliability: Avoiding unexpected errors and crashes in your application.
Bean Validation Basics
Spring Boot makes validation easy by integrating with the Jakarta Bean Validation API (JSR 380). This standard provides a set of annotations you can use to define validation rules directly on your data objects.
When Spring processes a request with a validated object, it automatically checks these rules. If any rule is violated, it flags an error.
Common Validation Annotations
Here are some essential Bean Validation annotations you'll often use:
@NotNull: Ensures the field is notnull.@NotBlank: For strings, ensures it's notnulland not just whitespace.@NotEmpty: For strings, collections, or arrays, ensures it's notnulland has at least one element/character.@Size(min=X, max=Y): Checks if a string or collection's size is within a range.@Min(value)/@Max(value): Checks if a numeric value is within a range.@Email: Validates if a string is a well-formed email address.@Pattern(regexp): Validates a string against a regular expression.
Creating a Validated DTO
Let's define a simple ProductRequest Data Transfer Object (DTO) that an API might receive. We'll add several validation annotations to its fields.
This DTO represents the expected structure and rules for creating a new product.
package com.coddykit.dto;
import jakarta.validation.constraints.DecimalMin;
import jakarta.validation.constraints.NotBlank;
import jakarta.validation.constraints.NotNull;
import jakarta.validation.constraints.Size;
public class ProductRequest {
@NotBlank(message = "Name cannot be empty")
@Size(min = 3, max = 50, message = "Name must be between 3 and 50 characters")
private String name;
@NotNull(message = "Price cannot be null")
@DecimalMin(value = "0.01", message = "Price must be greater than 0")
private Double price;
@NotBlank(message = "Description cannot be empty")
@Size(max = 200, message = "Description cannot exceed 200 characters")
private String description;
// Getters and Setters (omitted for brevity in snippet)
public String getName() { return name; }
public void setName(String name) { this.name = name; }
public Double getPrice() { return price; }
public void setPrice(Double price) { this.price = price; }
public String getDescription() { return description; }
public void setDescription(String description) { this.description = description; }
}Seeing Validation in Action
While Spring handles validation automatically in controllers, you can manually test the Bean Validation API. This program creates a ProductRequest and uses a Validator to check its rules.
Notice how violations are collected!
import com.coddykit.dto.ProductRequest;
import jakarta.validation.ConstraintViolation;
import jakarta.validation.Validation;
import jakarta.validation.Validator;
import jakarta.validation.ValidatorFactory;
import java.util.Set;
public class Main {
public static void main(String[] args) {
ValidatorFactory factory = Validation.buildDefaultValidatorFactory();
Validator validator = factory.getValidator();
ProductRequest invalidProduct = new ProductRequest();
invalidProduct.setName(" "); // Too short, blank
invalidProduct.setPrice(-5.0); // Less than 0.01
invalidProduct.setDescription("Short");
Set<ConstraintViolation<ProductRequest>> violations =
validator.validate(invalidProduct);
if (!violations.isEmpty()) {
System.out.println("Validation Errors:");
for (ConstraintViolation<ProductRequest> violation : violations) {
System.out.println("- " + violation.getMessage());
}
} else {
System.out.println("Product is valid!");
}
}
}Spring Boot's @Valid Integration
In a Spring Boot controller, you activate validation by simply adding the @Valid (or @Validated) annotation to the request body parameter. Spring automatically applies the rules defined in your DTO.
If validation fails, Spring throws a MethodArgumentNotValidException.
package com.coddykit.controller;
import com.coddykit.dto.ProductRequest;
import jakarta.validation.Valid;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RestController;
@RestController
public class ProductController {
@PostMapping("/products")
public ResponseEntity<String> createProduct(@Valid @RequestBody ProductRequest productRequest) {
// If validation passes, this code executes
System.out.println("Received valid product: " + productRequest.getName());
return new ResponseEntity<>("Product created successfully!", HttpStatus.CREATED);
}
}Understanding Default Error Handling
When @Valid fails in a controller, Spring Boot's default error handling kicks in. It catches the MethodArgumentNotValidException and returns a 400 Bad Request HTTP status.
The default error response typically includes a detailed (and often verbose) JSON object with error messages, field names, and other technical details. While functional, it might not be the most user-friendly or consistent for your API consumers.
Customizing Error Responses
For a better API experience, you'll want to customize error responses. This means:
- Consistent Format: All errors look similar.
- Clear Messages: Easy for clients to understand.
- Relevant Details: Only provide necessary information.
Spring provides the @ControllerAdvice and @ExceptionHandler annotations to centralize and customize error handling across your entire application.
Building a Global Error Handler
The @ControllerAdvice annotation marks a class that can handle exceptions from any controller. Inside it, @ExceptionHandler methods specify which exceptions to catch and how to respond.
Here's how to create a simple global handler for validation errors, returning a list of specific field errors.
package com.coddykit.exception;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.validation.FieldError;
import org.springframework.web.bind.MethodArgumentNotValidException;
import org.springframework.web.bind.annotation.ControllerAdvice;
import org.springframework.web.bind.annotation.ExceptionHandler;
import java.util.HashMap;
import java.util.Map;
@ControllerAdvice
public class GlobalExceptionHandler {
@ExceptionHandler(MethodArgumentNotValidException.class)
public ResponseEntity<Map<String, String>> handleValidationExceptions(
MethodArgumentNotValidException ex) {
Map<String, String> errors = new HashMap<>();
ex.getBindingResult().getAllErrors().forEach(error -> {
String fieldName = ((FieldError) error).getField();
String errorMessage = error.getDefaultMessage();
errors.put(fieldName, errorMessage);
});
return new ResponseEntity<>(errors, HttpStatus.BAD_REQUEST);
}
}Quick Check: Validation & Errors
Which of the following annotations are used to define validation rules for a string field in a DTO, ensuring it's not null, not empty, and has a minimum length?
Recap: Validation & Error Handling
You've learned how to make your Spring Boot APIs robust!
- Input Validation: Essential for data integrity and security, using the Jakarta Bean Validation API.
- Validation Annotations: Use
@NotBlank,@Size,@Min,@Max, etc., to define rules on your DTOs. @Valid: Triggers validation automatically in your controller methods.- Custom Error Handling: Use
@ControllerAdviceand@ExceptionHandlerto create consistent, user-friendly error responses, especially forMethodArgumentNotValidException.
Next, explore how to handle other types of exceptions in your API!
常见问题解答
「输入验证与错误处理」课时是免费的吗?
是的 — 「输入验证与错误处理」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Spring Boot 4 Complete Guide 课程的其余内容,请升级到 CoddyKit PRO。 Spring Boot 4 Complete Guide 课程共包含 4 节课。
「输入验证与错误处理」这节课中我会学到什么?
为传入请求实现数据验证,并创建全局异常处理器,以实现稳健的错误管理。 你通过在浏览器中直接运行的动手代码来练习 Spring Boot 4 Complete Guide,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Spring Boot 4 Complete Guide 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Spring Boot 4 Complete Guide 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。
「输入验证与错误处理」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Spring Boot 4 Complete Guide 课中编写并运行代码吗?
能。每节 Spring Boot 4 Complete Guide 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。