Authentication answers who is calling. Authorization answers what they are allowed to do. They get discussed together and they fail separately, which is why they have separate sections below.
ASP.NET Core Identity handles the first one for you: users, passwords, lockout, confirmation emails, two-factor. Most of what follows is either configuring it, replacing a piece of it, or connecting it to something external like Duende, Auth0 or Azure AD.
The last few sections are not framework features at all. They cover the mistakes that get made anyway: weak password storage, a missing CORS rule, the OWASP risks that keep turning up in real breaches.
ASP.NET Core Identity
The built-in user store, and the parts of it you will end up changing.
- Extending IdentityUser
- User Lockout with ASP.NET Core Identity
- Email Confirmation with ASP.NET Core Identity
- Password Reset with ASP.NET Core Identity
- Authentication With ASP.NET Core Identity
- Introducing Identity to the ASP.NET Core Project
- Two-Step Verification with ASP.NET Core Identity
- Two-Factor Authentication With SMS
- Unit Testing With UserManager and RoleManager in ASP.NET Core Identity
- User Registration with ASP.NET Core Identity
- Implementing Passwordless Authentication
- How Does the Default ASP.NET Core Identity Password Hasher Work?
JWT, Tokens and Refresh Tokens
Stateless authentication and the token lifecycle that comes with it.
- JWT Authentication in ASP.NET Core Web API
- Secure Microservices Using JWT With Ocelot in .NET Core
- Add Custom Claims to Access Token in Duende
- How to Decode JWT Tokens
- How to Get an Access Token from HttpContext
- Using Refresh Tokens in ASP.NET Core Authentication
- How to Use HttpOnly Cookie in .NET Core for Authentication and Refresh Token Actions
OAuth, OpenID Connect and External Providers
Letting somebody else own the login, and the flows you have to pick between when you do.
- External Identity Provider with ASP.NET Core Identity
- IdentityServer4 Authorization and Working with Claims
- IdentityServer4 UI and Web API Basic Security
- Firebase Authentication
- IdentityServer4 Integration with ASP.NET Core
- The Hybrid Flow – Securing ASP.NET Core Web Application
- Securing Web API with the Hybrid Flow
- How to Use Multiple Authentication Schemes
- Adding a User Login to a .NET App With Auth0
Authorization
Policies, claims and roles. Most authorization bugs are a claim that was never issued rather than a policy that was wrong.
- View-Based Authorization
- Resource-Based Authorization
- Get Current User With Claims
- How to Create a Custom Authorize Attribute
- Using Authorization with Swagger
- Implement Custom Authorization Policy Provider
API Security: Keys, CORS and Headers
Guarding an API rather than a browser session.
- Enabling CORS
- How to Fix CORS Error With AnyOrigin and AllowCredentials
- How to Use Basic Authentication With HttpClient?
- Implement API Key Authentication
- How to Include AntiForgeryToken for MVC Integration Testing
Cryptography and Password Storage
Hashing, salting and the .NET APIs that do it properly so you do not have to invent anything.
- Bouncy Castle Cryptography Library for .NET
- Hashing and Salting Passwords in C# – Best Practices
- Protecting Data with IDataProtector
- Cryptography Implementations
- How to Secure Passwords with BCrypt.NET
The OWASP Top 10
The failures that keep appearing in real breaches, each with what it looks like in .NET code.
- OWASP Top 10 – Sensitive Data Exposure
- OWASP Top 10 – Broken Authentication
- OWASP Top 10 – Injection
Where to Go Next
Identity is rarely the whole job. These are the pages next to it:
- ASP.NET Core
- IdentityServer4, OAuth and OpenID Connect
- OWASP Top 10 Vulnerabilities
- Blazor WebAssembly
Test the failure path. An authorization rule that has only ever been exercised by a user who passes it has not been tested at all.
