Spring AOP
Spring AOP
Beginner
Q1: What is AOP?
AOP (Aspect-Oriented Programming) is a way to modularize cross-cutting concerns like logging, security, and transactions.
Q2: What is Spring AOP?
Spring AOP is Spring’s proxy-based AOP framework for method-level interception on Spring-managed beans.
Q3: Why use Spring AOP?
To keep cross-cutting logic separate from business code and reduce duplication.
Q4: What is a cross-cutting concern?
A concern affecting multiple modules, e.g., logging, metrics, auth checks.
Q5: What is an Aspect?
A class that groups advice and pointcut definitions.
Q6: What is Advice?
Action executed at a matched join point (before/after/around/etc.).
Q7: What is a Join Point in Spring AOP?
A method execution point on a proxied bean.
Q8: What is a Pointcut?
A predicate/expression selecting which join points should run advice.
Q9: What is Weaving?
Applying aspects to target objects (in Spring AOP, via runtime proxies).
Q10: Is Spring AOP compile-time weaving?
No, it is primarily runtime proxy-based weaving.
Q11: What are common advice types?
- Before
- After
- AfterReturning
- AfterThrowing
- Around
Q12: What does @Before do?
Runs advice before target method execution.
Q13: What does @After do?
Runs advice after method finishes (success or exception).
Q14: What does @AfterReturning do?
Runs only when method returns successfully.
Q15: What does @AfterThrowing do?
Runs only when method throws an exception.
Q16: What does @Around do?
Wraps method execution and controls whether/when target executes.
Q17: What is ProceedingJoinPoint?
Object passed to around advice enabling proceed() invocation.
Q18: What happens if around advice never calls proceed()?
Target method is skipped.
Q19: What is @Aspect?
Annotation marking a class as an aspect.
Q20: What is @EnableAspectJAutoProxy?
Enables proxy-based AOP processing in Spring configuration.
Q21: Is AspectJ required to use Spring AOP annotations?
AspectJ expression syntax is used, but full AspectJ weaving is not required for basic Spring AOP.
Q22: What is a target object?
The original bean instance being proxied/intercepted.
Q23: What is an AOP proxy?
A wrapper object that intercepts method calls and applies advice.
Q24: JDK dynamic proxy vs CGLIB in Spring AOP?
JDK proxies interfaces; CGLIB subclasses concrete classes.
Q25: When does Spring use JDK proxies?
When target implements at least one interface (default strategy).
Q26: When does Spring use CGLIB?
When proxying class-based targets (or when forced).
Q27: Can final classes be proxied by CGLIB?
Final classes cannot be subclassed, so class-based proxying is limited.
Q28: Can final methods be advised with Spring proxy AOP?
Generally no, because subclass proxies cannot override final methods.
Q29: Can private methods be advised in Spring proxy AOP?
No, proxy interception targets externally invoked methods.
Q30: What is self-invocation problem?
A method within a bean calling another method in same bean bypasses proxy.
Q31: Why does self-invocation bypass advice?
Internal call uses this directly, not proxy reference.
Q32: What is the simplest fix for self-invocation issue?
Move advised method to another bean and call through container-managed proxy.
Q33: What is pointcut expression language in Spring AOP?
AspectJ pointcut expression syntax for matching methods/types.
Q34: Common pointcut designator in Spring AOP?
execution(...) is most common.
Q35: Example execution expression?
execution(* com.example.service.*.*(..))
Q36: What does *(..) mean in pointcut?
Any method name with any argument list.
Q37: What does package wildcard .. mean?
Matches current package and subpackages.
Q38: What is @annotation pointcut?
Matches methods annotated with a specific annotation.
Q39: What is within pointcut?
Matches join points within certain types/packages.
Q40: What is this() in pointcuts?
Matches based on proxy type.
Q41: What is target() in pointcuts?
Matches based on target object type.
Q42: What is args() in pointcuts?
Matches runtime argument types.
Q43: What is bean() pointcut in Spring?
Spring-specific designator matching bean names.
Q44: Why keep pointcuts specific?
Prevents accidental interception and performance/noise issues.
Q45: What is advice ordering?
Determines execution precedence when multiple aspects match same join point.
Q46: How define order?
Use @Order or Ordered interface.
Q47: What is use case for before advice?
Input validation, correlation ID setup, audit pre-log.
Q48: What is use case for after returning advice?
Result transformation metadata logging, success metrics.
Q49: What is use case for after throwing advice?
Error logging, exception metrics, alert enrichment.
Q50: What is use case for around advice?
Timing, retries, transaction wrappers, conditional execution.
Q51: Is around advice most powerful?
Yes, but also easiest to misuse.
Q52: Can advice change method arguments?
Around advice can supply different args when calling proceed(args).
Q53: Can advice change return value?
Around advice can wrap/replace return value.
Q54: Should business logic live in aspects?
No, keep aspects focused on cross-cutting concerns.
Q55: What is best first AOP use in projects?
Observability concerns (logging, metrics, tracing).
Q56: How to test if aspect is applied?
Integration tests with Spring context and assertions on side effects.
Q57: Can you apply AOP to non-Spring objects?
Not with Spring proxy AOP unless object is managed/proxied by container.
Q58: What is proxy exposure option?
Allows obtaining current proxy in special cases (use sparingly).
Q59: Is Spring AOP only method-level?
Yes for proxy model; field/constructor join points require AspectJ weaving.
Q60: Beginner best practice?
Use narrow pointcuts, simple advice, and avoid hidden business behavior.
Intermediate
Q61: How do multiple advices execute on same method?
According to precedence/order; around advice nests others.
Q62: Around advice call chain concept?
Outer aspect proceeds to next interceptor until target executes.
Q63: What happens if around advice catches exception and swallows it?
Caller sees success path, which may break semantics/monitoring.
Q64: Should around advice always proceed exactly once?
Usually yes; multiple/no proceed calls require deliberate design.
Q65: What is reusable named pointcut?
Method annotated with @Pointcut reused across advice methods.
Q66: Why use named pointcuts?
Improves readability and consistency across aspects.
Q67: Can pointcuts be composed?
Yes, using boolean operators (&&, ||, !).
Q68: Example composed pointcut idea?
Service package AND public methods AND annotated with @Timed.
Q69: What is join point context access?
Reading method signature, args, target class from JoinPoint.
Q70: How get method name in advice?
From joinPoint.getSignature().getName().
Q71: How access method arguments in advice?
joinPoint.getArgs().
Q72: How get target class?
joinPoint.getTarget().getClass() (or signature metadata).
Q73: What is MethodSignature in AOP?
Signature subtype exposing method-specific metadata.
Q74: What is annotation-driven pointcut common use?
Custom annotations like @Auditable, @Timed, @Retryable.
Q75: Why prefer annotation pointcuts over broad package cuts?
More explicit intent and lower accidental match risk.
Q76: What is introduction/inter-type declaration in AOP concept?
Adding interfaces/behavior to proxied objects (limited in Spring vs full AspectJ).
Q77: Does Spring AOP support full AspectJ introductions?
Limited compared to full AspectJ weaving.
Q78: What is proxyTargetClass flag?
Forces class-based (CGLIB) proxies.
Q79: Tradeoff of forcing CGLIB?
Can proxy classes without interfaces but has subclassing constraints.
Q80: What is exposeProxy flag?
Exposes current proxy via AopContext for advanced scenarios.
Q81: Why avoid heavy AopContext usage?
Creates coupling and hides design issues (often self-invocation smell).
Q82: What is transaction advice relationship?
@Transactional is implemented via AOP proxies/interceptors.
Q83: Why does @Transactional fail on private method?
Proxy cannot intercept private method calls.
Q84: Why does @Transactional fail on self-invocation?
Internal method call bypasses transactional proxy.
Q85: How does AOP relate to method security annotations?
Annotations like @PreAuthorize are applied via interceptors/proxies.
Q86: How does AOP support caching annotations?
@Cacheable and related annotations rely on proxy interception.
Q87: Why proxy order matters with tx/cache/security?
Different interceptor order changes behavior and side effects.
Q88: What is advisor in Spring AOP?
Combination of advice + pointcut packaged for application.
Q89: What is Advised interface?
Exposes proxy configuration details for advanced inspection.
Q90: What is ProxyFactory?
Programmatic API to create AOP proxies manually.
Q91: What is DefaultPointcutAdvisor?
Common advisor implementation combining pointcut and advice.
Q92: What is static vs dynamic pointcut?
Static matched by signature; dynamic may evaluate runtime arguments.
Q93: Why avoid overly dynamic pointcuts?
Higher runtime overhead and complexity.
Q94: What is control flow pointcut concept?
Match based on call stack/control flow (AspectJ concept, limited/expensive patterns).
Q95: What is common logging aspect pitfall?
Logging sensitive data or flooding logs in high-traffic methods.
Q96: How avoid sensitive logging in aspects?
Redact fields and define explicit allowlist for logged values.
Q97: What is performance timing aspect pattern?
Around advice measuring duration and recording metrics.
Q98: Why include tags in metrics aspect?
Supports filtering by operation/class/outcome in dashboards.
Q99: What is retry aspect risk?
Retrying non-idempotent operations can duplicate side effects.
Q100: How make retry safer?
Restrict to transient exceptions and idempotent operations.
Q101: What is exception translation aspect?
Maps low-level exceptions to domain-specific exceptions.
Q102: Should exception translation hide root cause?
No, preserve cause chain.
Q103: What is auditing aspect?
Captures who/what/when for critical actions.
Q104: Where should audit persistence occur?
Prefer reliable async/event pipeline or dedicated audit store pattern.
Q105: What is pointcut drift?
Pointcut unintentionally starts/stops matching after refactoring.
Q106: How prevent pointcut drift?
Use annotation markers and tests verifying interception coverage.
Q107: What is contract test for aspects?
Test asserting aspect behavior on representative target methods.
Q108: How debug whether bean is proxied?
Check class name/proxy utilities/logging of advisor application.
Q109: Can final return types affect proxying?
Proxy type compatibility must satisfy injection/casting expectations.
Q110: What is equals/hashCode caveat with proxies?
Proxy class may differ from target; equality assumptions can break.
Q111: What is serialization caveat with proxies?
Some proxies/handlers are not serialization-friendly by default.
Q112: What is thread safety requirement for aspects?
Aspect beans are usually singletons; state must be immutable/thread-safe.
Q113: Should aspects keep mutable per-request fields?
No, use method-local variables or request context holders.
Q114: What is MDC correlation in aspect usage?
Aspect sets request/trace context for logs and clears it reliably.
Q115: What happens if MDC is not cleared?
Context leakage across reused threads.
Q116: What is idempotent advice design?
Advice should avoid duplicate side effects if call chain retries/reenters.
Q117: How can AOP impact stack traces?
Adds proxy/interceptor frames, sometimes obscuring direct call flow.
Q118: What is best doc practice for aspects?
Document scope, pointcuts, order, and expected side effects.
Q119: When to use full AspectJ over Spring AOP?
Need field/constructor join points or non-Spring object weaving.
Q120: Key intermediate guideline?
Keep aspects explicit, test-covered, and limited to true cross-cutting needs.
Q121: What is perthis/pertarget concept (AspectJ)?
Aspect instantiation models beyond singleton; mostly full AspectJ territory.
Q122: Is Spring @Aspect bean singleton by default?
Yes, unless scope changed.
Q123: What is advisor chain inspection use case?
Troubleshooting unexpected behavior due to interceptor order.
Q124: What is no-op advice anti-pattern?
Interception overhead without meaningful value.
Q125: Intermediate anti-pattern summary?
Broad pointcuts + hidden side effects + poor tests.
Advanced
Q126: How does proxy depth affect latency?
Each interceptor adds call overhead; excessive chains increase latency.
Q127: What is interception hot-path concern?
Applying heavy advice to ultra-frequent methods can hurt throughput.
Q128: How profile AOP overhead?
Measure with/without aspects, inspect p95/p99 latency and CPU allocation.
Q129: What is compile-time weaving advantage (AspectJ)?
Broader join point model and potentially lower proxy indirection in some cases.
Q130: What is load-time weaving (LTW)?
Weaving aspects during class loading via agents/instrumentation.
Q131: Why is LTW operationally complex?
Agent setup, classloader interactions, and deployment constraints.
Q132: When is proxy-based AOP preferable?
Most enterprise method interception needs with simpler ops model.
Q133: What is architectural boundary aspect pattern?
Enforce rules (e.g., no repository access from controllers) via checks/instrumentation.
Q134: Should AOP enforce all architecture rules at runtime?
Prefer compile/test-time checks when possible; runtime checks for critical safeguards.
Q135: What is security boundary pitfall in AOP?
Assuming advice runs everywhere despite self-invocation or non-proxied objects.
Q136: How harden security with AOP?
Combine method security with explicit boundary design and tests.
Q137: What is transactional consistency pitfall with nested proxies?
Unexpected propagation/ordering can alter commit/rollback behavior.
Q138: How validate tx + AOP behavior?
Integration tests covering propagation, exceptions, and rollback semantics.
Q139: What is distributed tracing aspect strategy?
Aspect creates spans/tags around service methods with error status recording.
Q140: Risk of double instrumentation?
Duplicate spans/metrics if both auto-instrumentation and custom aspects run.
Q141: How avoid double instrumentation?
Define clear ownership and disable overlapping instrumentation points.
Q142: What is adaptive sampling relevance for logging aspects?
Controls volume during high traffic/incidents while preserving diagnostic value.
Q143: What is resilient aspect design?
Advice failures should not cascade and break core business flow (unless required).
Q144: Should observability aspects throw business exceptions?
Generally no; fail open carefully and log internal failures.
Q145: What is fail-closed vs fail-open in security aspects?
Fail-closed denies on uncertainty; fail-open allows continuation—choose by risk model.
Q146: What is ordering contract documentation?
Explicitly define precedence among tracing, security, transactions, caching, retries.
Q147: Typical safe order heuristic?
Security/auth first, then idempotency/validation, then tx, then business, then logging/metrics (context-dependent).
Q148: Why can retry + transaction ordering be dangerous?
Incorrect nesting may retry inside same failed transaction context.
Q149: What is compensating action concern in around advice?
Custom rollback/compensation must align with transaction boundaries.
Q150: How to version aspect behavior safely?
Feature flags, canary rollout, and backward-compatible defaults.
Q151: What is aspect blast radius?
Number of methods/services affected by one pointcut change.
Q152: How reduce blast radius?
Narrow pointcuts, annotation markers, incremental rollout.
Q153: What is AOP governance in large orgs?
Review process for new aspects, pointcut patterns, and operational impact.
Q154: What metrics should be tracked for aspects?
Invocation count, added latency, error rate, dropped/skipped behavior counts.
Q155: What is reentrancy issue in aspects?
Advice triggers code paths that re-trigger same advice unintentionally.
Q156: How prevent reentrancy loops?
Guard flags/context markers and carefully scoped pointcuts.
Q157: What is classloader/proxy memory risk?
Many generated proxies can increase metaspace/memory pressure.
Q158: How mitigate proxy explosion?
Proxy only necessary beans and avoid dynamic per-tenant/per-request proxy generation.
Q159: What is native image consideration for Spring AOP?
Proxy/reflection configuration may need explicit AOT hints.
Q160: How does AOT change AOP strategy?
Encourage build-time analysis and explicit proxy registrations.
Q161: What is anti-corruption use with aspects?
Translate external exceptions/protocol concerns at boundary services.
Q162: What is domain purity rule regarding AOP?
Aspects should support domain logic, not replace explicit domain workflows.
Q163: Why keep aspects stateless?
Singleton scope + concurrency safety + easier reasoning.
Q164: What is incident response benefit of well-designed aspects?
Consistent logs/metrics/traces across services speed root-cause analysis.
Q165: What is biggest advanced anti-pattern in Spring AOP?
Using broad around advice as hidden control flow engine.
Q166: When should you refactor away from aspect logic?
When it encodes business decisions better expressed in explicit services.
Q167: What is mature AOP usage profile?
Small set of well-documented, high-value aspects with strict tests and observability.
Q168: What testing pyramid addition helps AOP-heavy apps?
Dedicated interception contract tests plus end-to-end behavior verification.
Q169: What deployment practice reduces AOP regressions?
Canary + shadow traffic + fast rollback for pointcut/order changes.
Q170: What code review checklist item is critical for AOP?
Verify pointcut scope, ordering, side effects, and failure behavior.
Q171: What is long-term maintenance strategy?
Centralize common pointcuts and deprecate risky patterns gradually.
Q172: What is principle of least astonishment for aspects?
Advice behavior should be predictable and unsurprising to developers.
Q173: What is advanced performance rule?
Never put expensive I/O inside ubiquitous advice on hot paths.
Q174: Final architecture rule for Spring AOP?
Prefer explicitness: annotate intent, constrain scope, measure impact.
Q175: Final maturity principle?
Use AOP as a precision tool for cross-cutting concerns, not as hidden business orchestration.