# 03 — DictGroup 出入参规范化 **What to build:** DictGroupVO 改名为 DictGroupDTO(继承 BaseDTO,加 `fromEntity`/`toEntity`)。DictGroupController.saveOrUpdate 入参从 DictGroup(实体)改为 DictGroupDTO——客户端伪造 `builtin`/`createTime`/`creatorId` 等字段被 InitBinder strip 掉,结构性消除 mass assignment 漏洞。DictGroupController.enabledList 出参从 `List`(实体直出)改为 `List`——`deleted`/`creatorId`/`updaterId` 不再泄露给前端。Service 层手工置空审计字段的代码删除(InitBinder 接管)。 **Blocked by:** 01 (BaseDTO 重构), 02 (InitBinder) **Status:** ready-for-agent - [ ] `DictGroupVO` 改名为 `DictGroupDTO`,加 `@Data` + `@EqualsAndHashCode(callSuper = true)`,继承 `BaseDTO` - [ ] `DictGroupDTO` 上实现 `fromEntity(DictGroup)` 静态方法和 `toEntity()` 实例方法 - [ ] `DictGroupController.saveOrUpdate` 入参从 `DictGroup` 改为 `DictGroupDTO` - [ ] `DictGroupController.enabledList` 出参从 `List` 改为 `List` - [ ] Service 层手工置空 `createTime`/`creatorId`/`updaterId`/`deleted` 的代码删除 - [ ] Service 层手工强制 `builtin = false` 的代码删除 - [ ] DictGroupController 不再 import `DictGroup` 实体 - [ ] 测试:saveOrUpdate 入参为 DictGroupDTO,提交 `builtin=true` 被 strip - [ ] 测试:enabledList 返回的 JSON 中不包含 `deleted`/`creatorId`/`updaterId` - [ ] 测试:现有 dict 模块测试在改入参类型后仍全绿