error-model-validation-architect

作成者: kotlin

KotlinとSpringサービス向けに一貫したAPIバリデーションとエラーハンドリングの動作を設計・実装します。エラーペイロードの定義やフレームワークのマッピングを行う際に使用します。

npx skills add https://github.com/kotlin/kotlin-backend-agent-skills --skill error-model-validation-architect

Error Model Validation Architect

Source mapping: Tier 2 high-value skill derived from Kotlin_Spring_Developer_Pipeline.md (SK-07).

Mission

Turn ad-hoc exception handling into a deliberate public contract. Treat validation and error mapping as part of API design, not a post-processing afterthought.

Inputs To Read

  • Endpoint contracts and sample payloads.
  • Existing exception classes and error payloads.
  • Validation annotations, custom validators, and business rule failures.
  • Current @ControllerAdvice, security exception handling, and framework defaults.
  • Logging and observability conventions, especially correlation ids and PII policy.

Design The Error Taxonomy

Separate at least these categories:

  • malformed request or unreadable JSON
  • transport-level validation failure
  • not found
  • conflict or concurrency failure
  • business rule rejection
  • authentication and authorization failure
  • downstream dependency failure
  • unexpected internal failure

Do not collapse all non-success outcomes into one generic error envelope.

Status Code Rules

  • Use 400 for malformed input, type mismatch, or invalid transport shape.
  • Use 401 for authentication failure and 403 for authorization failure.
  • Use 404 when the addressed resource is absent.
  • Use 409 for state conflicts, optimistic locking failures, duplicate idempotency keys, and uniqueness races when conflict semantics matter.
  • Use 422 when the payload is structurally valid but violates business rules.
  • Use 429, 502, 503, or 504 deliberately when gateway or dependency behavior is part of the contract.
  • Reserve 500 for genuinely unexpected internal failures.

Advanced Contract Decisions

  • Separate machine-readable error code from human-readable message. Clients should not parse prose.
  • Decide whether field-level validation errors should be aggregated or first-failure only. Make the rule consistent.
  • Preserve nested field paths for complex payloads and collections.
  • Decide whether localization is a server concern, client concern, or documentation-only concern.
  • Standardize correlation or trace identifiers in the error payload only if the platform can produce them consistently.
  • Decide how unknown fields, enum mismatches, and unreadable date formats surface. These are common client-integration pain points.
  • Map downstream failures carefully. Not every remote 500 should become your own 500.
  • If using RFC 7807 Problem Details, decide which extensions are stable parts of the contract and which are internal.

Validation Rules

  • Keep transport validation separate from domain validation even if both ultimately reject the request.
  • Use Kotlin @field: targets for Bean Validation annotations on DTO constructor properties.
  • Prefer dedicated validators or domain rules over abusing regex annotations for business semantics.
  • Validate required configuration or invariants at startup when they are not truly request-scoped.

Framework Exception Coverage

  • Cover MethodArgumentNotValidException, ConstraintViolationException, HttpMessageNotReadableException, MethodArgumentTypeMismatchException, missing-parameter exceptions, and unsupported media-type cases explicitly if the API claims a stable error contract.
  • Decide how security exceptions participate in the shared error model. AuthenticationEntryPoint and AccessDeniedHandler often need explicit alignment with controller advice.
  • Decide how async, scheduled, and messaging failures are reported differently from HTTP failures. One global envelope does not fit every boundary.
  • If the platform uses Problem Details, verify framework-generated problem payloads do not diverge from custom ones during upgrades.

Expert Heuristics

  • Let validation errors help the client recover, but let internal logs help operators diagnose. These are different audiences and should not share the same detail level.
  • If the service is public, keep error-code taxonomy versionable and stable even when internal exception types change.
  • When multiple validation layers reject the same request, choose the most user-actionable signal instead of stacking redundant errors.
  • If a downstream dependency failure is part of the business path, decide whether the contract should expose dependency semantics or normalize them to your own domain.

Output Contract

Return these sections:

  • Error taxonomy: the categories and stable codes.
  • Status mapping: which exception or failure type maps to which status and why.
  • Payload shape: the fields that belong in every error.
  • Framework coverage: which framework exceptions must be handled explicitly.
  • Minimal implementation plan: advice class, exception types, and tests to add.
  • Logging rule: what to log server-side versus what to expose to clients.

Guardrails

  • Do not leak stack traces, SQL fragments, class names, tokens, or secrets to clients.
  • Do not use one generic message for all failures if clients need actionable categories.
  • Do not map every domain failure to 400.
  • Do not let security exceptions bypass the common contract unintentionally.
  • Do not rely on the framework default error shape if the service claims to have a stable API contract.

Quality Bar

A good run of this skill gives clients a predictable error language and gives operators enough server-side detail to debug safely. A bad run produces a pretty error JSON that still conflates malformed input, business rejection, and internal failure.

kotlinのその他のスキル

kotlin-backend-jpa-entity-mapping
kotlin
KotlinのデータクラスはDTOには自然ですが、JPAエンティティには危険です。Hibernateはデータクラスが破壊する同一性セマンティクスに依存しています。全フィールドに対するequals/hashCodeは状態変更後にSet/Mapのメンバーシップを破損させ、自動生成されるcopy()は管理対象エンティティのデタッチされた重複を作成します。
kotlin-tooling-agp9-migration
kotlin
Android Gradle Plugin 9.0により、同一モジュール内でAndroidアプリケーションおよびライブラリプラグインがKotlin Multiplatformプラグインと互換性がなくなります。このスキルは、移行手順を案内します。
kotlin-tooling-cocoapods-spm-migration
kotlin
KMPプロジェクトをCocoaPods(kotlin("native.cocoapods"))からSwift Package Manager(swiftPMDependencies DSL)に移行します — pod()をswiftPackage()に置き換え、…
kotlin-tooling-immutable-collections-0-5-x-migration
kotlin
Kotlin(およびJava)コードをkotlinx.collections.immutable 0.3.x / 0.4.xから最新の0.5.xに移行します。0.5.x系では、コピーを返すすべてのメソッドの名称が変更されています…
kotlin-tooling-java-to-kotlin
kotlin
Javaソースファイルを、各ステップで5つの不変条件をチェックする規律ある4ステップ変換手法を用いて、慣用的なKotlinに変換します。アノテーションサイトターゲット、ライブラリのイディオム、APIの保存を処理するフレームワーク対応変換をサポートします。
kotlin-tooling-native-build-performance
kotlin
iOSをターゲットとするKotlin Multiplatformプロジェクトにおける遅いKotlin/Nativeコンパイルとリンクを診断し、修正します。ユーザーがiOSの遅さや…を報告した場合に使用します。
kotlin-spring-proxy-compatibility
kotlin
Diagnose and prevent Kotlin plus Spring proxy failures around `@Transactional`, `@Cacheable`, `@Async`, method security, retry, configuration proxies, and JPA…
ci-cd-containerization-advisor
kotlin
再現可能なビルド、イメージ、デプロイメントパイプラインをKotlinとSpringアプリケーション向けに設計します。CI検証、レイヤードコンテナ、ロールアウトの安全性などを含みます。