ASP.NET Core Identity: Authorization Management

ASP.NET Core Identity: Authorization Management

1h 28mAdvanced2019-04-25

Authors

Ervis Trupja

Ervis Trupja

Full-Stack .NET Web Developer with a mathematical background

Course details

Authenticating users and authorizing their level of access is a key component to any application. In this course, learn how to authorize varying levels of access and add layers of security to your ASP.NET Core applications. Instructor Ervis Trupja shows how to authorize users in .NET Core using a simple, role-based model, as well as a rich, policy-based model. Throughout the course, he covers how to add requirements to an authorization policy, use handlers for one or multiple requirements, and create custom authorized attributes. To wrap up, he demonstrates how to use imperative authorization and write a resource-based handler.

Learning objectives
Different authorization types
Applying the Authorize and AllowAnonymous attributes
Adding role checks
Claims-based and policy-based authorization
Creating and using custom attributes
Using imperative authorization
Writing a resource-based handler

Skills covered

ASP.NET CoreBack-End Web DevelopmentFull-Stack Web DevelopmentFront-End Web DevelopmentWeb DevelopmentMicrosoftDeep Dive (X:Y)

Concepts

Introduction

  • Securing ASP.NET Core apps with authorization
  • What you should know

Getting Started

  • What is authorization
  • ASP.NET Core authorization types
  • ASP.NET Core authorization namespaces

Simple and Role-Based Authorization

  • Authorize and AllowAnonymous attributes
  • Adding role checks
  • Policy-based role checks

Claims-Based and Policy-Based Authorization

  • Adding claims checks
  • Authorization policy requirements
  • Working with authorization handlers
  • Analyzing handler results
  • Using a func to fulfill a policy

Authorization Policy Providers

  • Custom authorization attributes
  • Using custom IAuthorizationPolicyProvider
  • Default policy

Resource-Based and View-Based Authorization

  • Using imperative authorization
  • Writing a resource-based handler
  • Injecting and using authorization in a view

Conclusion

  • Next steps
40,000 Toman