Magnus Mårtensson
Microsoft Regional Director, Azure MVP, CEO Loftysoft
Avirag Jain
Director & CTO R Systems
Mahesh Chand
Founder C# Corner, CEO Mindcracker
Chris Gali
CEO & Co-Founder Graphite
Subinder Khurana
Chief Architect StoryProcess, Founder NASSCOM DeepTech Club
Bryan Rishforth
Investor, Chairman Graphite
Bryn Everson
Director Biz Dev Graphite
Raj Tiwari
Digital Transformation Leader, Futurist and Visionary
Joseph Guadagno
Microsoft MVP, Lead Quicken Loans
Nikita Sachdev
Entrepreneur, Blockchain Enthusiast & Advisor, Social Media Influencer
Doug Wagner
COO & Founder Adapt Technical Group
Ritesh Modi
Architect, Senior Evangelist, Cloud Architect
Crystal Wenrick
Director Communications Mindcracker
Allen O’Neill
Microsoft MVP, Consulting Engineer/Architect
Praveen Kumar
CEO MCN Solutions
Chris Love
Founder Love2Dev, Microsoft MVP, Author
Sanjay Vyas
Microsoft Regional Director, Microsoft MVP, Founder & CEO SkillLabs Technologies
Veena Sarda
Deep Learning Consultant, Author
Sekhar Srinivasan
C# Corner MVP, Microsoft Certified Trainer, Pluralsight Author
Lalit Bansal
Founder & CEO - EIY SYS
Navdeep Garg
CEO Revinfotech
Prakash Tripathi
Tech Manager/Leader, Microsoft MVP, Blogger
Bhavna Jain
Breakthrough Consultant
Naveen Sharma
Enterprise Architect, Leadership Coach, Author
Vidya Vrat Agarwal
Principal Architect, Microsoft MVP, Author
Sheetal Agarwal
Founder Clownselors, Medical Clown, Trainer
Abhishek Kant
Founder GTM Catalyst
Vishnu Saran
Founder & CEO VoiceQube
Sandeep Soni
Founder & CEO Deccansoft, Microsoft Certified Trainer
Parveen Malik
AVP InfoSec & Vulnerability Management, Information Security Expert
Nitin Pandit
Microsoft MVP, Developer Evangelist, Author
Niloshima Srivastava
C# Corner MVP, Tech Architect, Trainer, Blogger
Bala Chirtsabesan
Senior Software Engineer at Microsoft, Author
Manoj Mittal
Sr. Technical Architect, C# Corner MVP, Author
Chandni Di
Co-Founder Voice of Slum
Vithal Wadje
Technical Lead, Microsoft MVP, Author
Shivam Ahuja
Founder SkillCircle, Business Mentor
Chervine Bhiwoo
Solution Architect, Microsoft MVP, Author
Saurabh Jain
Vice President Paytm, Founder Fun2Do Labs, Author
Vinay Solanki
Head IoT at Lenovo, Founder IoT-NCR
Anshu kumari
Founder Blockchainkids, Inventor, Trainer
Amit Singal
CEO Startup Buddy
Dev Pratap
Co-Founder & CEO Voice of Slum
Amey Vartak
Technology Consultant, Full Stack Developer, C# Corner MVP, Author
Viswanatha Swamy
Principal Software Engineer, C# Corner MVP, Author
Sanket Verma
Research Engineer @ Ballistics (Forensics) and Chair, PyData Delhi
Sourabh Somani
Lead Developer, Microsoft MVP, Author
Abhishek Mishra
Software Architect, C# Corner MVP, Author
Siddharth Vaghasia
Technical Consultant, C# Corner MVP, Blogger
Bassam Alugili
Senior Software Specialist, Database Expert
S Ravi Kumar
Solution Architect, C# Corner MVP, Author
Sundaram Subramanian
Full Stack Developer, C# Corner MVP, Speaker
Deepesh Somani
Solution Architect, Microsoft MVP, Author
Debasis Saha
Technical Project Manager, C# Corner MVP, Blogger, Author
Vipul Jain
Software Architect, C# Corner MVP, Author
Akshay Patel
Technical Architect, Microsoft Certified Trainer, C# Corner MVP, Author
Stephen Simon
RPA Developer, Evangelist, Author
Vivek Sharma
Founder Kingster636, AR/VR Specialist
Jeetendra Gund
Technical Lead, C# Corner MVP, Author
Sujal Beniwal
AI Enthusiast, Student
M Viknaraj
Microsoft MVP, Azure Architect, Author
Prasham Sabadra
Software Architect, C# Corner MVP, Trainer, Author
Aakash Maurya
Senior Developer, C# Corner MVP, Speaker
Ankit Sharma
Senior Software Engineer, C# Corner MVP, Author
Mangesh Gaherwar
Team Lead, C# Corner MVP, Author
Viral Jain
Technical Consultant, C# Corner MVP, Author
Bhasker Das
Solution Architect, Evangelist
Manish Dwivedi
Associate Project Manager
Ck Nitin
Programmer, Author
Rohit Gupta
Technical Trainer, Author
Manish Tewatia
Full-stack Marketer, UX Designer
Bhavya Gaur
Technical Illustrator
Rohit Tomar
SEO/SMO Expert
Web Track
Cloud & Data Track
Dev Track
Registration & Breakfast
Future of Desktop Apps with JS (ElectronJs)
Nitin Pandit
Building Serverless Microservices Using Microsoft Azure
Vithal Wadje
Innovating RPA: A Robot for Every Person
Stephen Simon
Managing Cloud Storage Accounts using Logic Apps
Viknaraj Manogararajah
Data visualization using Python
Sekhar Srinivasan
Going Cross platform with AR Foundation
Vivek Sharma
Keynote
Managing your Azure dependencies in ASP.NET Core apps using VS
Bala Chirtsabesan
Securing Applications on Intelligent Azure
Abhishek Mishra
Getting started with Blazor the Framework of Future
S Ravi Kumar
Lunch
Build Progressive Web Apps using Angular 9
Debasis Saha
Build and deploy to any platform using Azure DevOps
Chervine Bhiwoo
Deep Dive in Azure Service Bus
Akshay Patel
Build a Native Mobile Application using React Native and JavaScript
Joseph Guadagno
Making sense of Web Job, Web Job SDK and Functions in Azure
Prakash Tripathi
CloudFront Distribution in AWS
Viral Jain
Tea Break
Introduction to PowerBI
Aakash Maurya
Build Advanced SPFx solutions with React and Graph API
Siddharth Vaghasia
Build Business Intelligence Analyst (BIA) Skills
Sundaram Subramanian
Deep dive of Power Platform – AI BUILDER
Prasham Sabadra
Panel 1
What's new in SharePoint development
Vipul Jain
Build a SSO (Single Sign On) based Native JavaScript application with Microsoft Identity within 10 minutes
Manoj Mittal
Panel 2
Applications and working of AI
Veena Sarda
Deploying serverless API's with .Net core 3.0 on AWS & Azure
Amey Vartak
Panel 3
Blockchain with .NET Core (Ark)
Anshu Kumari
Closing Note & Prize Distribution
Dev Track
Cloud Track
Architecture Track
Emerging Tech Track
Registration & Breakfast
Creating Full-Stack Web Apps Using Server-Side Blazor
Ankit Sharma
Real time face recognition with MS Cognitive Services
Niloshima Srivastava
Building Scalable APIs with GraphQL
Jeetendra Gund
Future of development with AI and Blockchain
Navdeep Garg
Debugging Tips and Tricks with Visual Studio 2019
Joseph Guadagno
Azure Containers
Abhishek Kant
Enterprise Architecture
Naveen Sharma
Bot Framework - learn it fast and look like a boss!
Allen O’Neill
Keynote
.Net Core & C# 8 Performance
David McCarter
Working with Azure kubernetes services
Ritesh Modi
Becoming an Architect
Vidyavrat Agarwal
Why Techies Need to Learn Product Management
Saurabh Jain
Lunch
Build a rules engine in .Net Core
Sanjay Vyas
Building CI and CD Pipeline using Azure DevOps
Sandeep Soni
Entity Framework Core - Tips and Tricks, Performance Optimization, and Tuning
Bassam Alugili
Hacking your way into Data Science
Sanket Verma
Speed up your .Net Core Website
Sourabh Somani
Azure
Magnus Mårtensson
Demystifying Open Distro for Elasticsearch
Suman Debnath
Future of Data
Shivam Ahuja
Tea Break
gRPC with C# and .Net Core
Mangesh Gaherwar
Panel 1
Essentials of Cloud security
Parveen Malik
Power platform and Dynamics 365
Deepesh Somani
Microservices - the gRPC Way
Viswanatha Swamy
Panel 2
Reserved
Reserved
Closing Note & Prize Distribution
Creating a Dynamic LINQ Query Builder for User-Defined Filters
Business software rarely knows every filter users will need in advance. A warehouse manager may want orders above a particular value, while a customer service team may need overdue tickets from a selected suburb. Hard-coding each combination quickly produces brittle controllers, duplicated SQL, and a user interface that cannot keep pace with operational needs.
A dynamic LINQ query builder for user-defined filters provides a structured way to translate filter choices into executable C# expressions. With a careful design, the same approach can support Entity Framework Core, in-memory collections, reporting screens, and APIs while protecting the database from unsafe input. It is particularly useful for Australian organisations managing varied datasets across retail, logistics, finance, education, and public services.
Model filters as data before building expressions
The first design decision is to represent a filter as data rather than accepting raw LINQ or SQL from a browser. A useful filter object can contain a field name, comparison operator, value, and optional group information:
public sealed class FilterRule
{
public string Field { get; set; } = "";
public string Operator { get; set; } = "";
public string? Value { get; set; }
}
A request might contain rules such as Status equals Active, Total greaterThan 500, or CreatedAt greaterThanOrEqual 2024-01-01. The server should map each public field name to an approved model property. That prevents a caller from requesting hidden columns, navigation properties, or arbitrary members through reflection.
Simple rules become more powerful when the model supports groups. For example, a customer might need orders where the status is Paid and the total exceeds $500, or where the delivery suburb is Richmond or Footscray. A group structure can carry AND and OR logic without forcing the user interface to understand expression tree syntax.
A production filter contract should also include paging, sorting, and a maximum number of rules. Values should arrive in a predictable culture-independent format, especially for dates and decimals. Australian users may enter dates as 31/12/2024, but APIs should generally transport dates as ISO 8601 values and convert them deliberately at the boundary.
Create expression trees with strongly typed properties
LINQ providers execute a predicate such as x => x.Status == "Active" in different ways. With Entity Framework Core, the expression is usually translated into SQL; with an in-memory list, it is compiled and run by the application. Expression trees bridge those execution models.
The builder begins with a parameter representing the entity and then resolves the requested property. A simplified equality expression looks like this:
var parameter = Expression.Parameter(typeof(Order), "order");
var property = Expression.Property(parameter, "Status");
var constant = Expression.Constant("Active");
var body = Expression.Equal(property, constant);
var predicate = Expression.Lambda<Func<Order, bool>>(body, parameter);
A general implementation needs to convert the incoming string to the property’s underlying type. Nullable values require special handling, as do enums, Guid, DateTime, and decimal amounts. TypeDescriptor.GetConverter, Enum.Parse, and explicit conversion routines can help, but parsing should return a controlled validation error rather than allowing an exception to escape from a request handler.
String operations deserve careful treatment. A contains operator may map to string.Contains, while startsWith can use StartsWith. Null checks should be generated when a property is optional. For case-insensitive searches, the chosen behaviour should be explicit because database collation differs between providers and installations. This matters when an application runs in Sydney, Perth, or a cloud region outside Australia with a different default configuration.
Combine rules safely for real-world logic
A query builder becomes useful when it can combine individual predicates. Expression.AndAlso is suitable for conditions that must all match, while Expression.OrElse handles alternatives. These operators preserve short-circuit semantics and produce the logical structure most LINQ providers expect.
A common pattern is to start with a null predicate and add rules progressively:
Expression<Func<Order, bool>>? current = null;
foreach (var rule in rules)
{
var next = BuildRule<Order>(rule);
if (current is null)
current = next;
else
current = Combine(current, next, Expression.AndAlso);
}
The Combine method must replace parameters so that both expression bodies refer to the same parameter instance. Libraries such as LinqKit can simplify predicate composition, but a small custom expression visitor is often easier to audit when the supported operators are limited.
Grouping deserves attention in the user interface and the server contract. Consider (Status = Paid OR Status = Shipped) AND Total > 500. If the API flattens all rules into one list, it may accidentally produce Status = Paid OR (Status = Shipped AND Total > 500), returning incorrect records. A recursive filter node with Group and Rule variants preserves parentheses and makes the intended logic clear.
The builder should reject unsupported combinations rather than silently changing them. For instance, applying greaterThan to a text field or contains to a numeric column should produce a useful validation message. This is important for Australian businesses with compliance reporting, where a subtly incorrect result can affect payroll, GST records, or customer communications.
Connect the builder to Entity Framework Core
A dynamic predicate should be applied as early as possible in the query pipeline:
IQueryable<Order> query = db.Orders.AsNoTracking();
if (predicate is not null)
query = query.Where(predicate);
query = query
.OrderByDescending(order => order.CreatedAt)
.Skip(page * pageSize)
.Take(pageSize);
Filtering before projection, pagination, and materialisation gives the database a chance to use indexes and return fewer rows. Calling ToList() before applying the predicate defeats that advantage and can cause an avoidable memory and latency problem. This risk is significant for distributed operations moving stock between Melbourne, Brisbane, and regional centres.
Every permitted filter field should have a corresponding database strategy. Columns frequently used for equality or range searches may need indexes, while leading-wildcard searches can remain expensive even when the expression is valid. Query logs and execution plans reveal whether a flexible reporting feature is producing efficient SQL or creating table scans.
A robust API should cap page size, reject excessively deep group trees, and impose a sensible limit on the number of conditions. Timeouts and cancellation tokens should be passed through to Entity Framework Core. Sorting deserves the same allow-list treatment as filtering; accepting a client-supplied property name directly in OrderBy can expose fields or cause translation failures.
Security extends beyond SQL injection. Dynamic queries can become a denial-of-service vector when they generate expensive joins, huge Contains lists, or wildcard searches across large tables. Tenant isolation must be applied as a server-owned predicate, never as a rule the user can remove. This is relevant to Australian SaaS providers handling customer records under privacy obligations and hosting workloads through services such as Azure Australia East.
Design a usable filter experience
A filter builder is easier to use when it offers field-specific controls. Dates should use a date picker, numeric columns should display numeric inputs, and enumerations should appear as a select list. A free-text operator menu should not expose options that the backend cannot evaluate consistently.
The client can fetch field metadata from an endpoint containing a display label, data type, permitted operators, and available values. The server remains authoritative, so metadata improves usability without becoming a security boundary. Labels such as “Order total” and “Dispatch date” are clearer than internal names such as TotalAmount and CreatedAt.
User-defined filters often become saved views. A saved view should retain the filter definition, selected columns, sort order, and ownership details. Versioning the definition helps when a field is renamed or removed. Instead of failing mysteriously, the application can mark an obsolete rule and ask the user to select a replacement.
Accessibility and local conventions matter in enterprise applications. Keyboard navigation, readable contrast, clear validation, and screen-reader labels support a wider workforce, including users working in busy warehouses or call centres. Currency formatting should display Australian dollars when appropriate, and date labels should avoid ambiguity even though the backend uses an invariant representation.
Teams looking for broader examples of cloud, data, and .NET engineering topics can browse the C# Corner conference materials alongside their own implementation work. The underlying principle is the same: a useful technical feature must connect code, operations, and the people who rely on the result.
Test, compare, and operate the query system
Testing should cover the translation process and the result set. Unit tests can verify that each operator creates the expected expression, while integration tests against the real database provider confirm that Entity Framework Core can translate it. An expression that works with List<T> may still fail when sent to SQL, particularly when it uses custom methods or unsupported string operations.
Property-based tests are useful for combinations of nullable values, empty strings, dates, decimals, and nested groups. Security tests should attempt unknown fields, malformed values, oversized lists, deep nesting, and predicates that try to escape a tenant boundary. The expected behaviour should be a clear client error, not a server crash or a silently broadened query.
Observability completes the feature. Log a normalised representation of the filter, execution duration, result count, and database command metrics, while excluding personal information and confidential values. A correlation ID makes it easier to trace a slow report from an Australian office through an API and into the database. Monitoring can then identify popular filters that deserve indexes or redesigned screens.
The following comparison highlights practical implementation choices for a maintainable filter service:
| Concern | Safer approach | Common mistake |
|---|---|---|
| Field selection | Map public names to approved properties | Passing client property names directly to reflection |
| Value conversion | Parse by declared type with validation | Treating every value as a string |
| Logical groups | Build a recursive expression structure | Flattening all rules into one list |
| Database execution | Apply Where before materialisation |
Calling ToList before filtering |
| Sorting | Use an allow-list of sortable fields | Concatenating a raw sort expression |
| Performance | Cap rules, page size, and list lengths | Allowing unbounded filters |
| Security | Add tenant and permission predicates server-side | Trusting the client to enforce access |
| Verification | Test against the actual LINQ provider | Testing only with in-memory collections |
A well-structured implementation separates the request contract, field metadata, value conversion, expression construction, and data-access execution. That separation allows a web application to evolve from a small search form into a sophisticated reporting tool without placing query logic in controllers or exposing the database model to end users. It also gives development teams a clear foundation for future additions such as full-text search, reusable filter templates, and role-specific reporting permissions.
1, CBD, Maharaj Surajmal Road, Near Yamuna Sports Complex, Delhi, 110032
GENERAL QUERIES
Manish Tewatia
manish@csharpcon.com
+91-9718-431-042
TICKET QUERIES
Atul Gupta
conference@csharpcon.com
+91-9910-125-804