Building and Securing Restful APIs in .NET
2h 49mAdvanced2024-06-04
Authors

Matt Milner
Independent Consultant, Web Developer, Trainer
Course details
Most people have heard of REST APIs, but the underlying concept—representational state transfer (REST)—can still cause a good deal of confusion. RESTful APIs use REST architecture along with HTTP requests to transfer data and changes in application state between clients and servers. This course shows you how to apply the principles of REST while building secure RESTful APIs on top of ASP.NET.
Join instructor Matt Milner as he provides an overview of how to get up and running with RESTful design in ASP.NET. Learn how to create APIs, entities, and databases, as well as work with resources, add link support, and configure and enable authentication options. By the end of the course, you should know the basics—how to properly request and return data in ASP.NET—and the best practices for building secure and scalable APIs to serve web clients, mobile clients, and beyond.
Join instructor Matt Milner as he provides an overview of how to get up and running with RESTful design in ASP.NET. Learn how to create APIs, entities, and databases, as well as work with resources, add link support, and configure and enable authentication options. By the end of the course, you should know the basics—how to properly request and return data in ASP.NET—and the best practices for building secure and scalable APIs to serve web clients, mobile clients, and beyond.
Skills covered
.NETAPIsFull-Stack Web DevelopmentAdvancedSoftware Development ToolsWeb DevelopmentMicrosoftSoftware Development
Concepts
0. Introduction
- 01 - Introduction to RESTful APIs in .NET
- 02 - What you should know
- 03 - Exercise files
1. REST in ASP.NET
- 04 - REST level set
- 05 - Creating the API project
- 06 - Creating the database entities
- 07 - Creating and seeding the database
- 08 - Defining the resources
- 09 - Mapping resources and entities
- 10 - Setting up the resource controller
- 11 - Set up the HTTP test file
2. Working with Resources
- 12 - Defining URI templates
- 13 - Implement resource collection GET
- 14 - Implement resource GET
- 15 - Implement resource POST
- 16 - Implement resource PUT
- 17 - Implement resource PATCH
- 18 - Implement resource DELETE
- 19 - Review additional resource operations
3. Adding Link Support
- 20 - HATEOAS and the API root
- 21 - Create a link base class
- 22 - Update resource with link support
- 23 - Validate linking support
- 24 - Industry linking formats
4. API Authentication
- 25 - Authentication options
- 26 - Securing the data in transit and at rest
- 27 - Securing APIs with API key
- 28 - Checking for API keys
- 29 - Securing APIs with a token
- 30 - Enabling ASP.NET Identity for APIs
- 31 - Enforcing and validating token identity
- 32 - Testing identity APIs
- 33 - Using proxies for authentication
- 34 - Using OAuth providers for tokens
5. API Authorization
- 35 - Defining security policies
- 36 - Creating a security policy for write operations
- 37 - Applying the security policy
Conclusion
- 38 - Next steps