You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Data REST中如何反转实体类字段的默认暴露策略?

How to Reverse Field Exposure Strategy in Spring Data REST + JPA

Absolutely! You can flip the exposure strategy to hide all fields by default and only explicitly expose the ones you want—this is a great practice to prevent accidental exposure of sensitive fields as your Account entity grows. Here are two robust approaches tailored to your tech stack:

Approach 1: Use Jackson Annotations for Entity-Level Control

This method leverages Jackson's core serialization rules to set a default "hide all" policy, then explicitly mark fields you want to expose.

  1. Configure the entity to hide all fields by default
    Add @JsonAutoDetect to your Account entity to disable visibility of all fields, getters, and setters by default. Then use @JsonProperty on fields you want to expose:

    @Entity
    @JsonAutoDetect(
        fieldVisibility = JsonAutoDetect.Visibility.NONE,
        getterVisibility = JsonAutoDetect.Visibility.NONE,
        setterVisibility = JsonAutoDetect.Visibility.NONE
    )
    public class Account {
        @Id
        @GeneratedValue(strategy = GenerationType.IDENTITY)
        @JsonProperty // Explicitly expose this field
        private Long id;
    
        @JsonProperty // Explicitly expose this field
        private String username;
    
        private String password; // Hidden by default
        private String email; // Hidden by default (no @JsonProperty)
        // Any future fields will be hidden unless you add @JsonProperty
    }
    
  2. Why this works: Jackson will only serialize fields marked with @JsonProperty, ignoring all others automatically. This ensures any new fields you add later stay hidden until you explicitly opt-in to expose them.

Spring Data REST has built-in support for projections, which let you define different "views" of your entity. This is more flexible than the Jackson approach because you can create multiple views (e.g., a public view, an admin view) and switch between them via request parameters.

  1. Define a Projection interface
    Create an interface that declares only the getters for fields you want to expose. Annotate it with @Projection to link it to your Account entity:

    @Projection(name = "publicAccount", types = Account.class)
    public interface PublicAccountProjection {
        Long getId();
        String getUsername();
        // Only include getters for fields you want to expose
    }
    
  2. Set the projection as the default for your repository
    Update your AccountRepository to use this projection by default for all REST responses:

    @RepositoryRestResource(excerptProjection = PublicAccountProjection.class)
    public interface AccountRepository extends JpaRepository<Account, Long> {
    }
    
  3. Bonus: Switch projections dynamically
    If you need to expose more fields for specific use cases, create another projection (e.g., AdminAccountProjection with more getters) and access it via the projection query parameter:

    GET /accounts?projection=adminAccount
    

Key Notes

  • With projections, you don't need to modify the entity's Jackson annotations—Spring Data REST uses the projection interface to build the response, ignoring any fields not declared in the interface.
  • Projections are fully compatible with Spring Data REST features like pagination, sorting, and nested entities.

内容的提问来源于stack exchange,提问作者Sebastiaan van den Broek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:07:02