You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
| Create primary data must be one resource object (absent, null, collection, or identifier primary data rejected) | supported |`CREATE_REQUIRES_SINGLE_RESOURCE` at `/data`|
88
+
| Create resource `id` optional; `id` and `lid` remain independent | supported | Aggregate validator; neither substitutes for the other; empty/whitespace strings are present |
89
+
| Every relationship supplied on the primary create resource must contain `data`| supported | Reuses `RELATIONSHIP_DATA_REQUIRED` at `/data/relationships/<name>/data`; primary resource only |
90
+
| Relationship linkage preserved: null, single, empty and non-empty collection | supported | All `RelationshipData` variants valid, including `lid`-based linkage |
91
+
| Omitted/present-empty relationship wrappers; links/meta coexist with present linkage | supported | Absent vs `Relationships.empty()`; no normalization |
92
+
| Create rules scoped to the primary resource | supported |`included` resources are exempt from the primary relationship-data rule and gain no nested-create interpretation; full linkage still enforced; pre-existing id-optional identity leniency is unchanged document-wide |
93
+
| Links-only/meta-only relationships outside create-specific restrictions | supported | Valid general core/document representations per ADR-018; rejected only on the primary create resource |
94
+
| HTTP/method handling and mutation | out of scope | Application-owned; a future Spring layer selects `CREATE_REQUEST` from its own operation context; core stays method-neutral |
Construct model types first (local invariants run in constructors). Call `JsonApiDocumentValidator` with a `ValidationContext` for rules that need the whole document (identity uniqueness, full linkage, extension/profile policy, and similar). For update requests use `DocumentUsage.UPDATE_REQUEST`; a `withExpectedEndpointIdentity(EndpointIdentity)` context makes the validator compare the primary resource `type`+`id` against a caller-derived expected endpoint identity. HTTP/route derivation and mutation remain application-owned.
23
+
Construct model types first (local invariants run in constructors). Call `JsonApiDocumentValidator` with a `ValidationContext` for rules that need the whole document (identity uniqueness, full linkage, extension/profile policy, and similar). For create requests use `DocumentUsage.CREATE_REQUEST`: primary data must be a single resource object whose `id` may be omitted (`id` and `lid` stay independent), and every relationship supplied on that resource must contain `data` (null, single, and collection linkage all remain valid). For update requests use `DocumentUsage.UPDATE_REQUEST`; a `withExpectedEndpointIdentity(EndpointIdentity)` context makes the validator compare the primary resource `type`+`id` against a caller-derived expected endpoint identity. Included resources are exempt from the primary-resource relationship-data rule under both write usages; otherwise existing identity and aggregate rules apply unchanged. HTTP/route derivation and mutation remain application-owned.
0 commit comments