Spring Data REST中如何反转实体类字段的默认暴露策略?
Absolutely! You can flip the exposure strategy to hide all fields by default and only explicitly expose the ones you want—this is a great practice to prevent accidental exposure of sensitive fields as your Account entity grows. Here are two robust approaches tailored to your tech stack:
Approach 1: Use Jackson Annotations for Entity-Level Control
This method leverages Jackson's core serialization rules to set a default "hide all" policy, then explicitly mark fields you want to expose.
Configure the entity to hide all fields by default
Add@JsonAutoDetectto yourAccountentity to disable visibility of all fields, getters, and setters by default. Then use@JsonPropertyon fields you want to expose:@Entity @JsonAutoDetect( fieldVisibility = JsonAutoDetect.Visibility.NONE, getterVisibility = JsonAutoDetect.Visibility.NONE, setterVisibility = JsonAutoDetect.Visibility.NONE ) public class Account { @Id @GeneratedValue(strategy = GenerationType.IDENTITY) @JsonProperty // Explicitly expose this field private Long id; @JsonProperty // Explicitly expose this field private String username; private String password; // Hidden by default private String email; // Hidden by default (no @JsonProperty) // Any future fields will be hidden unless you add @JsonProperty }Why this works: Jackson will only serialize fields marked with
@JsonProperty, ignoring all others automatically. This ensures any new fields you add later stay hidden until you explicitly opt-in to expose them.
Approach 2: Use Spring Data REST Projections (Recommended)
Spring Data REST has built-in support for projections, which let you define different "views" of your entity. This is more flexible than the Jackson approach because you can create multiple views (e.g., a public view, an admin view) and switch between them via request parameters.
Define a Projection interface
Create an interface that declares only the getters for fields you want to expose. Annotate it with@Projectionto link it to yourAccountentity:@Projection(name = "publicAccount", types = Account.class) public interface PublicAccountProjection { Long getId(); String getUsername(); // Only include getters for fields you want to expose }Set the projection as the default for your repository
Update yourAccountRepositoryto use this projection by default for all REST responses:@RepositoryRestResource(excerptProjection = PublicAccountProjection.class) public interface AccountRepository extends JpaRepository<Account, Long> { }Bonus: Switch projections dynamically
If you need to expose more fields for specific use cases, create another projection (e.g.,AdminAccountProjectionwith more getters) and access it via theprojectionquery parameter:GET /accounts?projection=adminAccount
Key Notes
- With projections, you don't need to modify the entity's Jackson annotations—Spring Data REST uses the projection interface to build the response, ignoring any fields not declared in the interface.
- Projections are fully compatible with Spring Data REST features like pagination, sorting, and nested entities.
内容的提问来源于stack exchange,提问作者Sebastiaan van den Broek

