<?xml version="1.0" encoding="UTF-8"?>
<!--
  SpotBugs exclusion filter. Kept intentionally small; every exclusion below is
  a documented false-positive class, not a way to silence real findings.
-->
<FindBugsFilter>
    <!-- Generated Spring Boot application bootstrap has no meaningful bug surface. -->
    <Match>
        <Class name="com.codebyte.api.ApiServerApplication"/>
    </Match>

    <!-- MapStruct-generated mappers (added in later phases) are not our source. -->
    <Match>
        <Class name="~.*MapperImpl"/>
    </Match>

    <!-- The DI/config layers hold constructor-injected Spring singletons and immutable value
         records (DTOs, @ConfigurationProperties, small result records). EI_EXPOSE on these is a
         false positive: the references are shared by design, not a mutable-state leak. -->
    <Match>
        <Bug pattern="EI_EXPOSE_REP,EI_EXPOSE_REP2"/>
        <Or>
            <Package name="~com\.codebyte\.api\..*\.service"/>
            <Package name="~com\.codebyte\.api\..*\.api"/>
            <Package name="~com\.codebyte\.api\..*\.security"/>
            <Package name="~com\.codebyte\.api\.config(\..*)?"/>
            <Package name="com.codebyte.api.common.web"/>
        </Or>
    </Match>

    <!-- JPA entities own mutable collections/associations by necessity (managed by Hibernate). -->
    <Match>
        <Bug pattern="EI_EXPOSE_REP,EI_EXPOSE_REP2"/>
        <Package name="~com\.codebyte\.api\..*\.domain"/>
    </Match>

    <!-- API DTOs are records used as immutable value carriers; EI_EXPOSE on their components
         (e.g. a page's content list) is expected and harmless. -->
    <Match>
        <Bug pattern="EI_EXPOSE_REP,EI_EXPOSE_REP2"/>
        <Or>
            <Package name="~com\.codebyte\.api\..*\.api\.dto"/>
            <Class name="com.codebyte.api.common.web.PagedResponse"/>
        </Or>
    </Match>
</FindBugsFilter>
