Two production-grade Spring Boot 3.x APIs demonstrating enterprise patterns: JWT auth, generic response wrappers, global exception handling, and Jackson serialisation control โ the kind of code that survives a code review.
RoleBackend Engineer
FrameworkSpring Boot 3.x ยท Java 17
DomainHealthcare & E-Commerce
TypeBackend API Development
The Goal
Reference implementations of enterprise Spring Boot patterns
HealthApi demonstrates full CRUD, JWT-secured endpoints, paginated list responses, file upload/delete, and a GlobalExceptionHandler returning consistent error shapes regardless of where exceptions occur.
simpleShop extends these patterns into e-commerce (products, orders, customers, inventory) with a generic ReturnSet<T> response wrapper and Jackson configuration suppressing null fields cleanly.
Key Patterns
The engineering decisions that matter
1
Generic ReturnSet<T> response wrapperEvery endpoint returns ReturnSet<T> โ a typed wrapper with status, message, data payload, and pagination metadata. Consistent contract for all consumers across all entity types.
2
Spring Security 6 + JWT โ stateless authJWT filter validates every request. 15-minute access token with 7-day refresh rotation. Role-based access control via @PreAuthorize on controller methods.
3
GlobalExceptionHandler with @ControllerAdviceCatches ValidationException, EntityNotFoundException, AccessDeniedException โ returning structured error responses. No stack traces exposed to API consumers.
4
@JsonInclude(NON_NULL) on all DTOsJackson configured to suppress null fields globally. Optional fields simply absent from JSON when not populated.
5
Lombok + JPA โ clean entity definitions@Data, @Builder, @NoArgsConstructor on all entities. @EntityGraph used on complex joins instead of LAZY fetch with explicit join fetch in JPQL to avoid N+1 queries.
// Generic response wrapper@Data @Builder @JsonInclude(JsonInclude.Include.NON_NULL)
public class ReturnSet<T> {
private String status, message;
private T data;
private Integer totalRecords, page, pageSize;
}
Outcomes
APIs ready to integrate โ not just demonstrate
100%
Consistent response shape across all endpoints
0
Stack traces exposed to consumers
JWT
Stateless auth with refresh rotation
RBAC
Role-based endpoint access control
Reusability: The ReturnSet wrapper, GlobalExceptionHandler, and JWT filter chain from HealthApi were extracted and reused directly in simpleShop โ demonstrating the value of designing for reuse from the start.