Part 13 · Applications

MVC request flow, DTO validation and errors

Prerequisites: 01-ecosystem

Where do request responsibilities belong?

DispatcherServlet: route request; Controller + DTO: validate / translate; Service: business rules; Repository: persistence; Exception handling: ProblemDetail. Connections: DispatcherServlet to Controller + DTO (invoke handler); Controller + DTO to Service (use case); Service to Repository (data access); Controller + DTO to Exception handling (invalid input); Service to Exception handling (failure)
Request-side responsibilities; responses return through MVC. Authentication filters normally run before this view. [S23] [S24] [S25]

Goal & mental model verified

DispatcherServlet delegates request mapping and invocation to MVC components. Validation checks request constraints. Error handling can produce ProblemDetail responses rather than leaking internal exception representations.

[S23] [S24]

Worked example · design exercise synthesis

POST /quotes accepts a validated request DTO. The service enforces business eligibility; the repository persists. A validation failure returns a stable client error, while an internal failure gets a traceable sanitized response.

[S23] [S24] [S25]

Engineering decision synthesis

Keep controllers focused on transport and services on use-case policy. DTOs decouple API shapes from persistence; the additional mapping is an intentional boundary cost.

[S23] [S24] [S25]

Pitfall & diagnosis synthesis

Bean Validation cannot prove business eligibility or authorization. Returning persistence entities can expose fields and trigger unexpected serialization-time loads.

[S23] [S24] [S25]

Improve & validate synthesis

Exercise malformed input, missing access and failure responses with HTTP tests. Keep stable problem types and correlate internal diagnostics without returning stack traces.

[S23] [S24] [S25]
Keep this: Validate syntax at transport boundaries and invariants in the domain.
Check yourself: Can @Valid prove an agent owns a policy?

No. Ownership is an authorization/domain rule, not just a field constraint.

Sources & further reading

  1. [S23] DispatcherServlet

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: Front controller delegates MVC request processing

    Read the linked section to validate the mechanism and its version-specific constraints.

  2. [S24] MVC validation

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: Request and method validation

    Read the linked section to validate the mechanism and its version-specific constraints.

  3. [S25] HTTP error responses

    Spring project maintainers · documentation · accessed 2026-10-09 · Documentation retrieved 2026-10-09

    Supports: ProblemDetail; Central exception handling

    Read the linked section to validate the mechanism and its version-specific constraints.