Case Study ยท Spring Boot ยท Java ยท REST

HealthApi & simpleShop REST APIs

Two production-grade Spring Boot 3.x APIs demonstrating enterprise patterns: JWT auth, generic response wrappers, global exception handling, and Jackson serialisation control โ€” the kind of code that survives a code review.

RoleBackend Engineer
FrameworkSpring Boot 3.x ยท Java 17
DomainHealthcare & E-Commerce
TypeBackend API Development

Reference implementations of enterprise Spring Boot patterns

HealthApi demonstrates full CRUD, JWT-secured endpoints, paginated list responses, file upload/delete, and a GlobalExceptionHandler returning consistent error shapes regardless of where exceptions occur.

simpleShop extends these patterns into e-commerce (products, orders, customers, inventory) with a generic ReturnSet<T> response wrapper and Jackson configuration suppressing null fields cleanly.

The engineering decisions that matter

1
Generic ReturnSet<T> response wrapperEvery endpoint returns ReturnSet<T> โ€” a typed wrapper with status, message, data payload, and pagination metadata. Consistent contract for all consumers across all entity types.
2
Spring Security 6 + JWT โ€” stateless authJWT filter validates every request. 15-minute access token with 7-day refresh rotation. Role-based access control via @PreAuthorize on controller methods.
3
GlobalExceptionHandler with @ControllerAdviceCatches ValidationException, EntityNotFoundException, AccessDeniedException โ€” returning structured error responses. No stack traces exposed to API consumers.
4
@JsonInclude(NON_NULL) on all DTOsJackson configured to suppress null fields globally. Optional fields simply absent from JSON when not populated.
5
Lombok + JPA โ€” clean entity definitions@Data, @Builder, @NoArgsConstructor on all entities. @EntityGraph used on complex joins instead of LAZY fetch with explicit join fetch in JPQL to avoid N+1 queries.
// Generic response wrapper @Data @Builder @JsonInclude(JsonInclude.Include.NON_NULL) public class ReturnSet<T> { private String status, message; private T data; private Integer totalRecords, page, pageSize; }

APIs ready to integrate โ€” not just demonstrate

100%
Consistent response shape across all endpoints
0
Stack traces exposed to consumers
JWT
Stateless auth with refresh rotation
RBAC
Role-based endpoint access control

Reusability: The ReturnSet wrapper, GlobalExceptionHandler, and JWT filter chain from HealthApi were extracted and reused directly in simpleShop โ€” demonstrating the value of designing for reuse from the start.


Back to all projects