1---2name: go-api-development3description: Go API development guidelines using the standard library (1.22+) with best practices for RESTful API design, error handling, and security4---5
6# Go API Development with Standard Library
7
8## Core Principles
9
10- Always use the latest stable version of Go (1.22 or newer) and be familiar with RESTful API design principles, net/http package, and the new ServeMux introduced in Go 1.22
11- Follow the user's requirements carefully and to the letter
12- First think step-by-step - describe your plan for the API structure, endpoints, and data flow in pseudocode, written out in great detail
13- Write correct, up-to-date, bug-free, fully functional, secure, and efficient Go code for APIs
14- Leave NO todos, placeholders, or missing pieces in the API implementation
15- Always prioritize security, scalability, and maintainability in your API designs
16
17## API Development Guidelines
18
19### Routing and HTTP Handling
20
21- Use the new `http.ServeMux` introduced in Go 1.22 for routing
22- Implement proper HTTP method handling (GET, POST, PUT, DELETE, PATCH)
23- Use appropriate HTTP status codes for responses
24- Implement proper content-type handling for requests and responses
25
26### Error Handling
27
28- Implement proper error handling, including custom error types when beneficial
29- Return appropriate HTTP status codes with error responses
30- Use structured error responses in JSON format
31- Log errors appropriately for debugging and monitoring
32
33### Input Validation
34
35- Implement input validation for API endpoints
36- Validate request bodies, query parameters, and path parameters
37- Return clear validation error messages to clients
38- Sanitize inputs to prevent injection attacks
39
40### JSON Handling
41
42- Use `encoding/json` for JSON serialization/deserialization
43- Implement proper struct tags for JSON field mapping
44- Handle JSON parsing errors gracefully
45- Use appropriate JSON formatting for responses
46
47### Concurrency
48
49- Leverage Go's built-in concurrency features when appropriate for API performance
50- Use goroutines for concurrent operations where beneficial
51- Implement proper synchronization for shared state
52- Use context for request cancellation and timeouts
53
54### Middleware
55
56- Implement middleware for cross-cutting concerns (logging, authentication, rate limiting)
57- Use middleware chaining for composable request processing
58- Implement CORS handling where needed
59- Add request/response logging middleware
60
61### Security
62
63- Implement authentication and authorization where appropriate
64- Use HTTPS in production
65- Implement rate limiting to prevent abuse
66- Validate and sanitize all user inputs
67- Use secure defaults for cookies and sessions
68
69### Logging
70
71- Use standard library logging with structured output
72- Log appropriate information for debugging and monitoring
73- Avoid logging sensitive information
74- Use log levels appropriately
75
76### Testing
77
78- Write unit tests for handlers and business logic
79- Implement integration tests for API endpoints
80- Use table-driven tests where appropriate
81- Mock external dependencies in tests