← ClaudeAtlas

controller-advice-stylelisted

The house style for error responses of a Spring MVC REST application - `@RestControllerAdvice`, `@ExceptionHandler`, `ProblemDetail` (RFC 9457), `ResponseEntityExceptionHandler`, `AuthenticationEntryPoint`, `AccessDeniedHandler`. Load it before writing or changing any of them, when a new exception has to reach the client, when shaping validation `errors`, and when an endpoint returns 403 where 401 was expected, a `@PreAuthorize` denial comes back as 500, a status is lost to a catch-all handler, one module's exception is answered by another module's advice, or an error body has its fields nested under `properties`. Not for the controllers themselves (the separate `controller-style` skill) and not for documenting errors in Swagger (the separate `swagger-style` skill).
dmitriy-iliyov/java-agent-skills · ★ 0 · API & Backend · score 72
Install: claude install-skill dmitriy-iliyov/java-agent-skills
# Controller advice style House rules for how an exception leaves a REST application as an error response. An advice or handler that breaks one of them is either wrong, or a reason to change the rule here deliberately. The controllers that throw follow the `controller-style` skill ([../controller-style/SKILL.md](../controller-style/SKILL.md)): a controller never catches, so every failure arrives here as an exception. ## The advice **Every error response is a `ProblemDetail`** (RFC 9457) from an `@ExceptionHandler` of a `@RestControllerAdvice` - never a body of the project's own shape, never `ResponseEntity<String>`. Client libraries already read the standard one. **Who answers what:** | Exception | Answered by | |---|---| | standard Spring MVC - no handler, method not supported, `415`, `406`, a missing parameter, an unreadable body, a type mismatch, method validation | `ResponseEntityExceptionHandler`, which the advice extends. Only a `handle*` whose response is shaped differently is overridden - validation adding `errors`; a handler of one's own for each loses the statuses nobody remembered | | `AccessDeniedException`, `AuthenticationException` | Spring Security's `ExceptionTranslationFilter`: an `AuthenticationEntryPoint` `401`, an `AccessDeniedHandler` `403`, both through the same factory as the advice - which hands them back ([security failures](#security-failures)) | | a domain exception | its own handler. A condition the client can cause, such as a unique constrai