Skip to content

Feature/p0 starters - #4

Merged
SaumilP merged 3 commits into
mainfrom
feature/p0-starters
Jul 5, 2026
Merged

SaumilP merged 3 commits into
mainfrom
feature/p0-starters

Conversation

@SaumilP

@SaumilP SaumilP commented Jul 5, 2026

Copy link
Copy Markdown
Owner

Summary

Changes

Type of change

  • Bug fix
  • New feature / starter
  • Breaking change
  • Documentation update
  • Dependency update

Checklist

  • Unit tests added or updated
  • Integration tests added (if touching infrastructure adapters)
  • JavaDoc added for all new public methods
  • ./gradlew spotlessCheck passes locally
  • ./gradlew javadoc compiles without warnings
  • README updated (if adding new configuration properties or starter)
  • CHANGELOG.md entry added under [Unreleased]

SaumilP added 3 commits July 5, 2026 15:43
…mentation plans

Researched public technical sources (Baeldung, spring.io, DZone, Java Code
Geeks, Medium, GitHub, vendor docs) for the Spring Boot cross-cutting concerns
teams most often reimplement, then mapped them against the eleven existing
starters to find the gaps.

Identifies ten candidate starters ranked by reinvention frequency, cross-cutting
reach, and gap-vs-built-ins, with detailed implementation plans (config prefix,
properties, beans/conditionals, dependencies, testing, effort, overlaps) for the
P0/P1 tier — observability (correlation ID/MDC/structured logging), RFC 7807
problem-details, resilient HTTP client, secrets, data-privacy (PII masking +
field encryption), and scheduler-lock — plus sketches for the rest and a
sequencing plan. Linked from the README documentation index.
…tarters to roadmap

Adds a "Third-party integration starters (requested)" section with detailed
plans (config prefix, properties, beans/conditionals, dependencies, testing,
effort) for five requested SaaS integrations:

- twilio     — SMS / WhatsApp / voice
- resend     — transactional email
- onesignal  — push / email / SMS / in-app (interpreted from "OpenSignal";
               OpenSignal is a different, network-analytics company with no
               notification API — flagged for confirmation)
- novu       — multi-channel notification workflow orchestration
- supabase   — BaaS: Auth (GoTrue), Storage, PostgREST data access

The four messaging providers are modeled as provider modules behind the
proposed `notifications` core SPI (same "common interface, swappable provider"
pattern used for StorageService across minio/aws-s3); Supabase is standalone.
Updated the candidates table, the notifications sketch, the delivery sequencing
(a parallel requested-integration track), and sources.
Implement the P0, P1, P2, and P3 tiers from ROADMAP.md as ten new Spring Boot
starters, each with auto-configuration, typed @ConfigurationProperties,
@ConditionalOnMissingBean overrides, unit tests, a module README, and a runnable
example app.

P0:
- spring-boot-starter-observability — request correlation IDs (CorrelationIdFilter),
  MDC log propagation, async context propagation (MdcTaskDecorator), a
  CorrelationContext accessor, and an opt-in outbound
  CorrelationIdClientHttpRequestInterceptor. Bound from spring.observability.*
- spring-boot-starter-problem-details — GlobalExceptionHandler rendering unhandled
  exceptions as RFC 7807 application/problem+json with a machine-readable code,
  per-field validation errors, request path, and optional correlation ID. Bound from
  spring.problem-details.*
- spring-boot-starter-resilient-client — ResilientClient façade with auto-configured
  Resilience4j Retry and CircuitBreaker plus a timeout-configured RestClient. Bound
  from spring.resilient-client.*

P1:
- spring-boot-starter-data-privacy — MaskingService (email/card/full) and JPA
  field-level AES-256-GCM encryption via EncryptedStringConverter / AesGcmEncryptor.
  Bound from spring.data-privacy.*
- spring-boot-starter-scheduler-lock — @SchedulerLock annotation and aspect so a
  @scheduled task runs on one instance only, with pluggable LockProvider
  (InMemoryLockProvider, Redis-backed RedisLockProvider). Bound from
  spring.scheduler-lock.*
- spring-boot-starter-secrets — unified SecretSource SPI with EnvironmentSecretSource
  (default) and AwsSecretsManagerSecretSource selected via spring.secrets.provider.

P2:
- spring-boot-starter-notifications — core notification SPI: NotificationSender,
  NotificationMessage/NotificationResult, Channel enum, CompositeNotificationSender
  (routes by channel), LoggingNotificationSender fallback, and a NotificationService
  façade with sync/async dispatch. Bound from spring.notifications.*
- spring-boot-starter-security-jwt — opinionated stateless JWT resource-server
  SecurityFilterChain with bearer auth, secure headers (HSTS, X-Content-Type-Options,
  X-Frame-Options), CORS, and a JwtDecoder from JWKS/issuer URI. Bound from
  spring.security-jwt.*
- spring-boot-starter-webhooks — outbound delivery via WebhookDeliveryService with
  HMAC signing (WebhookSigner), exponentittering, plus
  an InMemoryWebhookRegistry. Bound from spring.webhooks.*

P3:
- spring-boot-starter-api-keys — issue/vaService (only
  hashes stored), pluggable ApiKeyStore, and an ApiKeyAuthFilter enforcing X-Api-Key
  on protected paths. Bound from spring.a

Wire all modules and examples into settin(starter table
+ project tree), CHANGELOG (Unreleased/Added), and ARCHITECTURE (module topology
table). Full build passes: unit tests, Jaless.
@SaumilP
SaumilP merged commit 074af58 into main Jul 5, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant