<< All versions

Skill v1.0.0

currentAutomated scan100/100
jxoesneon/ciel/java-springboot-development
──Details
PublishedSeptember 27, 2026 at 09:35 PM
Content Hashsha256:f756a2daaa687cb8...
Git SHA
──Files
Files (1 file, 2.0 KB)
SKILL.md2.0 KBactive
SKILL.md · 47 lines · 2.0 KB

version: "1.0.0" name: java-springboot-development description: CIEL's framework for Java 17+ and Spring Boot 3+ development, security, and TDD. license: MIT metadata: ciel-version: 1.0.0 ciel-extension: ciel.yaml


CIEL ADAPTATION: Java & Spring Boot (The Enterprise Layer)

This skill formalizes the development of production-grade Java services using Spring Boot. It mandates immutability, fail-fast error handling, and security-first configuration.

Java Standards (17+)

  1. Immutability: Favor record and final fields. No setters.
  2. Null Safety: Accept @Nullable only when unavoidable. Use Optional for return types.
  3. Fail Fast: Use domain-specific unchecked exceptions (e.g., EntityNotFoundException).
  4. Streams: Keep pipelines short and readable. Favor List.of() and .toList().

Spring Boot Architecture

  • Layered Discipline: Controller (thin) -> Service (pure logic) -> Repository (abstract access).
  • Injection: Use constructor injection; prohibit @Autowired on fields.
  • Transactions: Use @Transactional(readOnly = true) for all GETs.
  • Validation: Enforce @Valid on all RequestBody DTOs via Bean Validation (Zod-like patterns).

Security Review

  • Auth: Default to stateless JWT. Use OncePerRequestFilter for validation.
  • CSRF: Disable for pure APIs; Enable for session-based browser apps.
  • SQLi: Prohibit string concatenation in @Query. Use :param bindings only.
  • PII: Never log full payloads or sensitive fields. Redact centrally.

TDD Workflow

  • Unit: JUnit 5 + AssertJ + Mockito. 100% logic coverage.
  • Web: MockMvc for controller boundary testing.
  • Persistence: DataJpaTest with Testcontainers (no H2 in CI).

Anti-Patterns

  • Lombok Over-use: Using @Data on immutable domain entities (use @Value or record).
  • Magic Numbers: Hardcoding timeouts or page sizes.
  • Silent Catch: Catching Exception without rethrowing or structured logging.
All versions