skip to content

Repository REST Exposure

@RepositoryRestResource publishes a repository as a REST API automatically, with detection strategies and exported=false to control what is visible. Interviewers ask about the coupling this creates between your table structure and your public API.

part ofSpring Frameworkoverview, primer and where to startread it →
on this pageshow

questions

6

What does Spring Data REST do with your repositories, and what role does @RepositoryRestResource play?

level: juniorimportance: must knowfreq 55%

answer

  1. repositories -> REST for free, no controller
  2. HAL / application/hal+json, _links
  3. /people default = uncapitalized + pluralized
  4. @RepositoryRestResource = override, not opt-in
  5. path / collectionResourceRel / itemResourceRel / exported

basics

~10 s

Spring Data REST automatically turns each Spring Data repository into a REST API with hypermedia (HAL) links — CRUD endpoints appear with no controller code. @RepositoryRestResource customizes that exposure, e.g. changing the URL path.

solid answer

~30 s

Spring Data REST (starter spring-boot-starter-data-rest) scans Spring Data repositories (CrudRepository, JpaRepository, etc.) and auto-generates a hypermedia REST API for their aggregate roots — no @RestController needed. For a Person entity it exposes a collection resource (GET/POST /people), item resources (GET/PUT/PATCH/DELETE /people/{id}), association resources, and a /search resource for query methods. Responses use HAL (application/hal+json) with _links. The default path is the uncapitalized, pluralized entity name. @RepositoryRestResource on the repository interface overrides these defaults: path changes the URL segment, collectionResourceRel/itemResourceRel rename the link relations, and exported=false hides the whole repository. It is opt-in customization layered on top of the automatic behavior.

code

java · 16 lines
java
@Entity
public class Person {
    @Id @GeneratedValue Long id;
    String firstName;
    String lastName;
}

// No annotation needed — this alone yields GET/POST /people, GET/PUT/PATCH/DELETE /people/{id}
public interface PersonRepository extends JpaRepository<Person, Long> { }

// With customization: collection served at /members instead of /people
@RepositoryRestResource(
    path = "members",
    collectionResourceRel = "members",
    itemResourceRel = "member")
public interface MemberRepository extends JpaRepository<Person, Long> { }

go deeper

for a junior

Know that adding the Spring Data REST starter turns repositories into a working REST API automatically and that responses have _links (HAL).

for a middle

Know the concrete endpoints generated (collection/item/association/search) and the three main @RepositoryRestResource attributes.

for a senior

Understand default path derivation (uncapitalized+pluralized), base-path config, and that the annotation customizes rather than enables exposure.

for a principal

Weigh SDR's model-coupled contract against DTO controllers; know it fits admin/internal CRUD but risks leaking the persistence model as the public API.

**What Spring Data REST is.** Spring Data REST (SDR) is a Spring module (pulled in by `spring-boot-starter-data-rest`) that inspects the Spring Data repositories in your application context and, for each one, automatically publishes a fully working RESTful, hypermedia-driven HTTP API — without you writing a single controller. It builds on Spring HATEOAS and Spring MVC. **What gets exposed.** SDR only exports repositories whose domain type is an *aggregate root* (an `@Entity`/document with a repository). Given an entity `Person` and a `PersonRepository extends JpaRepository<Person, Long>`, SDR creates: - A **collection resource**: `GET /people` (list, paged/sorted) and `POST /people` (create). - **Item resources**: `GET /people/{id}`, `PUT/PATCH /people/{id}` (update), `DELETE /people/{id}`. - **Association resources**: e.g. `GET /people/{id}/address` for related entities, manipulable via `text/uri-list`. - A **search resource**: `GET /people/search` listing exported query methods (see the derived-search question). **Hypermedia / HAL.** By default responses use the HAL media type `application/hal+json`. Each resource carries a `_links` object (`self`, `profile`, and links to associations), and collections carry `_embedded` plus `page` metadata. This is what 'hypermedia-driven' means — clients navigate by following links rather than hardcoding URLs. **Default paths and rels.** The collection path defaults to the *uncapitalized, pluralized* simple entity name — SDR uses Evo Inflector for English pluralization (`Person` → `/people`, `Category` → `/categories`). The base path is `/` but is typically set with `spring.data.rest.base-path=/api`. **@RepositoryRestResource.** This annotation is placed on the *repository interface* to customize how that repository is exported. Its main attributes: - `path` — the URL segment for the collection resource (e.g. `path = "members"` → `/members`). - `collectionResourceRel` — the link relation used for the collection in HAL output. - `itemResourceRel` — the link relation for a single item. - `exported` — set `false` to suppress REST exposure entirely for this repository while keeping it as an injectable Spring bean. **Key point:** the API exists *even without* the annotation — SDR's `RepositoryDetectionStrategy` decides which repos are exported (DEFAULT = all public repos). `@RepositoryRestResource` is purely for overriding defaults, not for opting a repo in. The related annotation `@RestResource` is used on *query methods* and *properties/associations* for finer-grained control (path, rel, exported). **When to use.** SDR is excellent for admin panels, prototypes, internal tools, and CRUD-heavy microservices where the HTTP surface should mirror the persistence model. It is a poor fit when you need a stable, decoupled API contract, custom DTOs, or complex business rules on writes — because it couples your HTTP API tightly to your entity model. **Common gotchas.** (1) SDR endpoints coexist with your own `@RestController`s but a hand-written controller mapped to the same path *wins* and disables SDR for that path. (2) Everything is exposed by default — a real security risk if you forget to lock it down. (3) Projections and excerpts (`@Projection`) are needed to shape output without leaking every field.

  • If you don't annotate the repository at all, is it still exposed?
    Yes. The default RepositoryDetectionStrategy exports every public Spring Data repository automatically. @RepositoryRestResource only customizes or (via exported=false) suppresses it — it is not required to opt in.
  • How do you change the API base path from / to /api?
    Set the property spring.data.rest.base-path=/api (or configure RepositoryRestConfiguration.setBasePath in a RepositoryRestConfigurer). This prefixes all SDR endpoints.
  • What media type do responses use by default and why does it matter?
    application/hal+json (HAL). It matters because clients are expected to discover related resources through the _links section rather than constructing URLs, making the API hypermedia-driven.

saying these in an interview costs you the question

  • Thinking you must annotate a repository for it to be exposed (it's exposed by default)
  • Believing you must write an @RestController for CRUD endpoints under Spring Data REST
  • Assuming the default path is the raw singular class name like /person

context

open as a page

What does exported=false do at the repository, query-method, and association level, and what is the gotcha when you hide a repository that backs an association?

level: middleimportance: should knowfreq 42%

basics

~20 s

exported=false stops Spring Data REST from publishing something over HTTP while keeping it as a normal Spring bean. On a repository it hides all its endpoints; on a query method it hides that finder; on an association it drops the association resource. Gotcha: hiding a repository can break linking to its entities.

open as a page

How do @RepositoryRestResource and @RestResource change the URL path and HAL link relation of an exposed resource, and how do path and rel differ?

level: middleimportance: should knowfreq 40%

basics

~20 s

path sets the URL segment (e.g. /members); rel sets the name of the link in the HAL _links output that clients follow. @RepositoryRestResource customizes the whole collection; @RestResource customizes a single query method or association.

open as a page

What is RepositoryDetectionStrategy in Spring Data REST, what are its modes, and how do you configure it?

level: seniorimportance: should knowfreq 33%

basics

~20 s

RepositoryDetectionStrategy decides which repositories Spring Data REST exposes. Modes: DEFAULT (all public repos, respecting exported=false), ALL (every repo, ignoring visibility and annotations), ANNOTATED (only repos annotated for export), and VISIBILITY (only public repos). Set it via the spring.data.rest.detection-strategy property or a RepositoryRestConfigurer.

open as a page

How does Spring Data REST expose derived query (search) methods, and how do you control their paths and parameters?

level: seniorimportance: should knowfreq 35%

basics

~20 s

Derived finder methods like findByLastName are exposed under /{repo}/search. Each method becomes /{repo}/search/{name} with its parameters as query params. Use @Param to name the query parameters, @RestResource(path/rel) to rename the endpoint, and exported=false to hide a finder.

open as a page

What are the architectural and security trade-offs of auto-exposing repositories with Spring Data REST, and when would you choose it over hand-written controllers?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Auto-exposure is fast but tightly couples your HTTP API to your persistence model and exposes everything by default, which is a security and contract risk. Use it for internal/admin CRUD; prefer DTO-based controllers when you need a stable public contract, custom validation, or business logic.

open as a page