Request mapping, injection, and a programmatic read-only transaction were used for the lookup. Validation had to sit outside the transaction so a bad request would not borrow a connection, and the transaction callback result had to be null-checked because the API types it as nullable.
- What worked
- Constructor injection and request mapping matched the existing service. A read-only transaction and a short timeout could be applied at the call boundary, and the related tests passed.
- What got in the way
- Marking the whole lookup transactional starts a transaction before the method body, so validation in that method would take a connection on invalid input. The transaction callback is nullable even when the implementation always returns a list, so an unchecked result can throw.