skip to content

What is RepositoryRestConfigurer and what representation-level settings can you customise with it?

level: seniorimportance: should knowfreq 48%

answer

  1. implements RepositoryRestConfigurer @Component
  2. configureRepositoryRestConfiguration(config, cors)
  3. exposeIdsFor(Entity.class)
  4. setBasePath / setDefaultMediaType(HAL-FORMS)
  5. getExposureConfiguration() hide methods; configurers compose

basics

~10 s

RepositoryRestConfigurer is a callback interface you implement (as a @Component) to customise Spring Data REST: base path, default media type, whether entity ids are exposed, projections, Jackson mapper, CORS, and HTTP method exposure.

solid answer

~30 s

RepositoryRestConfigurer is the primary extension point for Spring Data REST. You implement it (usually as a @Component or via @Configuration) and override callbacks — chiefly configureRepositoryRestConfiguration(RepositoryRestConfiguration config, CorsRegistry cors). Through the RepositoryRestConfiguration you can: set the base path (setBasePath), expose entity ids (exposeIdsFor(Book.class)), change the default media type to HAL-FORMS (setDefaultMediaType), toggle setReturnBodyOnCreate/Update, tune default page size, register projections (getProjectionConfiguration().addProjection), and restrict exposed HTTP methods via getExposureConfiguration. Other callbacks include configureJacksonObjectMapper for custom serialisation, configureConversionService, and configureHttpMessageConverters. Because multiple configurers compose, you add cross-cutting representation policy without touching individual repositories.

code

java · 14 lines
java
@Component
class RestConfig implements RepositoryRestConfigurer {
    @Override
    public void configureRepositoryRestConfiguration(
            RepositoryRestConfiguration config, CorsRegistry cors) {
        config.setBasePath("/api");
        config.exposeIdsFor(Book.class);
        config.setDefaultMediaType(MediaTypes.HAL_FORMS_JSON);
        config.getProjectionConfiguration().addProjection(BookSummary.class);
        config.getExposureConfiguration()
              .forDomainType(Book.class)
              .withItemExposure((meta, methods) -> methods.disable(HttpMethod.DELETE));
    }
}

go deeper

for a junior

Knows it's the config hook for Spring Data REST.

for a middle

Names common settings like base path, exposeIdsFor, page size.

for a senior

Uses exposure DSL, projection registration, and default media-type switching knowingly; understands configurer composition.

for a principal

Chooses content negotiation vs global media-type override, layers configurers for separation of concerns, and governs API exposure policy centrally.

**`RepositoryRestConfigurer`** is the officially sanctioned interface for programmatically customising Spring Data REST behaviour. You provide an implementation as a Spring bean: ```java @Component class RestConfig implements RepositoryRestConfigurer { @Override public void configureRepositoryRestConfiguration( RepositoryRestConfiguration config, CorsRegistry cors) { config.setBasePath("/api"); config.exposeIdsFor(Book.class); // put numeric id in the JSON body config.setDefaultPageSize(25); config.setReturnBodyForPutAndPost(true); config.getProjectionConfiguration().addProjection(BookSummary.class); cors.addMapping("/**").allowedOrigins("https://app.example.com"); } } ``` **Key callbacks (all have no-op defaults, so override only what you need):** - `configureRepositoryRestConfiguration(RepositoryRestConfiguration, CorsRegistry)` — the main one; shapes exposure and representation. - `configureJacksonObjectMapper(ObjectMapper)` — register modules / custom serializers affecting how resources serialise. - `configureConversionService(ConfigurableConversionService)` — custom type conversions. - `configureHttpMessageConverters(List<HttpMessageConverter<?>>)` — add/adjust converters. - `configureValidatingRepositoryEventListener(...)` — wire Validators to lifecycle events. **Representation-relevant knobs on `RepositoryRestConfiguration`:** - **`setBasePath(String)`** — root path for all exported resources (default `/`). - **`exposeIdsFor(Class<?>...)`** — by default entity ids are hidden (identity comes from the self link); this forces them into the body. A very common interview point. - **`setDefaultMediaType(MediaType)`** — switch the default from `application/hal+json` to `application/prs.hal-forms+json` (HAL-FORMS). - **`setReturnBodyOnCreate/Update` / `setReturnBodyForPutAndPost`** — control whether write responses include the entity body. - **`setDefaultPageSize` / `setMaxPageSize`** — paging defaults. - **`getProjectionConfiguration().addProjection(...)`** — register projections not auto-discovered by package location. - **`getExposureConfiguration()`** — fluent DSL (`forDomainType(...).withItemExposure(...)`) to disable specific HTTP methods per resource, e.g. hide DELETE. **Composition:** Multiple `RepositoryRestConfigurer` beans are all invoked, in `@Order` sequence, so you can layer concerns (one for CORS, one for exposure, one for projections). The framework's own defaults run first; yours refine them. **Gotchas:** - Editing config here is the correct place — do NOT try to reconfigure via `application.properties` for these object-level settings (only a subset like base-path and page size have properties under `spring.data.rest.*`). - `exposeIdsFor` takes the *entity* class, not the repository. - Changing the default media type to HAL-FORMS affects *all* responses; you may prefer content negotiation (clients send `Accept: application/prs.hal-forms+json`) instead of globally overriding. - CORS configured here applies to the Spring Data REST endpoints specifically; it is distinct from a global WebMvc CORS setup. **When to use:** any time you need cross-cutting control over how repository resources are exposed and represented — base path, id visibility, projections, media type, method exposure, or serialisation — without polluting individual `@RepositoryRestResource` annotations.

  • By default entity ids are hidden from the JSON body — how do you expose them and why is it off by default?
    Call config.exposeIdsFor(Entity.class) in a RepositoryRestConfigurer. It's off by default because Spring Data REST models identity through the self link's href, keeping the representation hypermedia-driven rather than id-driven.
  • If two RepositoryRestConfigurer beans exist, do they conflict?
    No — all configurer beans are invoked in @Order sequence and compose, layering their customisations on top of the framework defaults.

saying these in an interview costs you the question

  • Passing the repository class (not the entity) to exposeIdsFor
  • Thinking all these settings are available as application.properties
  • Believing only one RepositoryRestConfigurer can exist
  • Confusing this CORS config with global WebMvc CORS

context