Part 03 · Spring Framework & Spring Boot · 3.3

Lab Spring Boot

Mỗi lab phải có failure case, command hoặc test tái hiện, expected result và artifact chứng minh. Không chấp nhận chỉ chạy happy path rồi chụp màn hình ứng dụng.


Chuẩn bị: Java 21 khuyến nghị, Maven/Gradle, Docker, PostgreSQL Testcontainers và công cụ load test. Lưu source, test reports, SQL/query count, metrics hoặc trace trong từng lab.

Lab 01 · REST API chuẩn

Xây Order API có DTO, Bean Validation, ControllerAdvice error contract, pagination và idempotency key. Không expose entity. Viết @WebMvcTest và OpenAPI examples.

Verify: invalid JSON/field trả stable 4xx; duplicate key không tạo side effect lần hai; entity/lazy fields không xuất hiện trong contract.

Lab 02 · Starter và auto-configuration detective

Tạo hai modules demo-spring-boot-autoconfiguredemo-spring-boot-starter, typed properties, conditional bean và AutoConfiguration.imports. Chạy condition report khi class thiếu, property tắt và user bean override; test bằng ApplicationContextRunner.

Verify: dependency tree chứng minh starter, BOM và transitive dependencies khác vai trò; custom bean làm default back off.

Lab 03 · Transaction proxy

Tạo lỗi self-invocation khiến inner method không mở transaction mới; chứng minh bằng integration test, sau đó tách bean và sửa. Thử REQUIRED và REQUIRES_NEW, quan sát transaction IDs hoặc connection pool.

Verify: outer rollback và inner outcome đúng theo propagation; test có case pool nhỏ để thấy cost của connection thứ hai.

Lab 04 · JPA N+1

Tạo quan hệ Order–Item, bật SQL statistics, chứng minh N+1; sửa lần lượt bằng fetch join, entity graph và projection. Test pagination và so sánh query count.

Verify: lưu SQL/query-count trước và sau; collection pagination không duplicate hoặc silently paginate in memory.

Lab 05 · Security filter chain

Bảo vệ API với hai roles, JSON 401/403, method security và CORS policy. Test anonymous, user, admin, object ownership, CSRF behavior với cookie/session và bearer API.

Verify: URL access không vượt qua object-level authorization; raw token không xuất hiện trong logs.

Lab 06 · Actuator và graceful operations

Expose health/metrics có kiểm soát, custom readiness indicator, correlation ID và graceful shutdown. Mô phỏng DB down: readiness fail nhưng liveness vẫn đúng theo policy.

Verify: management endpoints nhạy cảm bị chặn; instance drain inflight request trước shutdown trong timeout.

Lab 07 · Bean lifecycle inspector

Viết BeanFactoryPostProcessorBeanPostProcessor log thứ tự; tạo singleton, prototype, request scope, scoped proxy và SmartLifecycle.

Verify: chỉ ra object nào là proxy, callback nào chạy, prototype cleanup thuộc ai và start/stop phase theo thứ tự nào.

Lab 08 · Async/event/cache failure matrix

Tạo use case publish event BEFORE/AFTER_COMMIT, async listener và cache eviction. Mô phỏng listener fail, process crash và cache down; ghi state DB, event và cache để thấy abstraction nào không durable.

Verify: phân biệt committed DB state, event delivery và cache freshness; đề xuất Outbox hoặc retry/reconciliation đúng failure.

Lab 09 · MVC, virtual threads và WebFlux benchmark

Với cùng một blocking downstream giả lập, triển khai MVC platform threads, MVC virtual threads và WebClient/WebFlux. Đo throughput, p95/p99, thread count, pool saturation, memory và behavior khi vô tình block event loop.

Verify: workload, warm-up, concurrency và downstream capacity giống nhau; kết luận dựa trên signals thay vì chỉ requests/second.

Rubric

Nguồn đối chiếu