API designmedium0-2 years

Why shouldn't a Spring MVC controller return a JPA entity directly from a REST endpoint?

Jackson serialises every readable property it can find on the object it's handed — it has no concept of "internal". Return the entity and a passwordHash field, an internal flag, or a lazy @OneToMany collection all go out with it, and adding a field to the entity later silently changes the public response. A DTO is opt-in: the response is exactly the fields somebody wrote into that class, so a schema or entity change can't leak anything that wasn't deliberately exposed.

The lesson behind it →