spring-projects / spring-projects/spring-data-rest

Overriding Repository methods exposed them under /search endpoint [DATAREST-920]

Open
#1,172 0 comments 0 reactions 1 assignee View on GitHub

@odrotbohm is already working on this.

Since Dec 31, 2020.

type: bug
Dominant language
Java
Stars
958
Forks
568
PR merge metrics
No merged PRs in 30d

Description

Marc Zampetti opened DATAREST-920 and commented

When one overrides methods provided by an inherited Repository interface, such as CrudRepository in order to do things like add @Query parameters or @PreAuthorize information, Spring Data Rest exposes the overridden method under the /search/ endpoint.

This seems like an issue since that changes the signature of the API in an unintendded way. Using @RestResource(exported = false) won't work, as that will deny access to the method.

For example, when overring the findAll() method to add a @Query adjustment, the <repository>/search/findAll method now appears in the output. And calls to <repository>/search/findAll now also work.

It seems like this is unintended behavior, and should be resolved in some manner. I see a couple of ways to do so:

  • If the @Override annotation is on the method, don't expose in the /search endpoint. That might not work if the method is coming from another custom interface however.
  • Filter out methods that are overrides of known Repository interfaces, maybe by using the package name or some other marker interface.
  • Add a hide option to @RestResource that would hide the method from generated metadata, but wouldn't restrict access like exported = false does

No further details from DATAREST-920

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.