New to site?


Lost password? (X)

Already have an account?


(X)

Presents

#CSHARPCON20

The C# Corner Annual Conference 2020 is a three-day annual event for software professionals and developers.

3
DAYS
72
SPEAKERS
65
SESSIONS

Magnus Mårtensson
Microsoft Regional Director, Azure MVP, CEO Loftysoft

Avirag Jain
Director & CTO R Systems

Mahesh Chand
Founder C# Corner, CEO Mindcracker

Chris Gali
CEO & Co-Founder Graphite

Subinder Khurana
Chief Architect StoryProcess, Founder NASSCOM DeepTech Club

Bryan Rishforth
Investor, Chairman Graphite

Bryn Everson
Director Biz Dev Graphite

Raj Tiwari
Digital Transformation Leader, Futurist and Visionary

Joseph Guadagno
Microsoft MVP, Lead Quicken Loans

Nikita Sachdev
Entrepreneur, Blockchain Enthusiast & Advisor, Social Media Influencer

Doug Wagner
COO & Founder Adapt Technical Group

Ritesh Modi
Architect, Senior Evangelist, Cloud Architect

Crystal Wenrick
Director Communications Mindcracker

Allen O’Neill
Microsoft MVP, Consulting Engineer/Architect

Praveen Kumar
CEO MCN Solutions

Chris Love
Founder Love2Dev, Microsoft MVP, Author

Sanjay Vyas
Microsoft Regional Director, Microsoft MVP, Founder & CEO SkillLabs Technologies

Veena Sarda
Deep Learning Consultant, Author

Sekhar Srinivasan
C# Corner MVP, Microsoft Certified Trainer, Pluralsight Author

Lalit Bansal
Founder & CEO - EIY SYS

Navdeep Garg
CEO Revinfotech

Prakash Tripathi
Tech Manager/Leader, Microsoft MVP, Blogger

Bhavna Jain
Breakthrough Consultant

Naveen Sharma
Enterprise Architect, Leadership Coach, Author

Vidya Vrat Agarwal
Principal Architect, Microsoft MVP, Author

Sheetal Agarwal
Founder Clownselors, Medical Clown, Trainer

Abhishek Kant
Founder GTM Catalyst

Vishnu Saran
Founder & CEO VoiceQube

Sandeep Soni
Founder & CEO Deccansoft, Microsoft Certified Trainer

Parveen Malik
AVP InfoSec & Vulnerability Management, Information Security Expert

Nitin Pandit
Microsoft MVP, Developer Evangelist, Author

Niloshima Srivastava
C# Corner MVP, Tech Architect, Trainer, Blogger

Bala Chirtsabesan
Senior Software Engineer at Microsoft, Author

Manoj Mittal
Sr. Technical Architect, C# Corner MVP, Author

Chandni Di
Co-Founder Voice of Slum

Vithal Wadje
Technical Lead, Microsoft MVP, Author

Shivam Ahuja
Founder SkillCircle, Business Mentor

Chervine Bhiwoo
Solution Architect, Microsoft MVP, Author

Saurabh Jain
Vice President Paytm, Founder Fun2Do Labs, Author

Vinay Solanki
Head IoT at Lenovo, Founder IoT-NCR

Anshu kumari
Founder Blockchainkids, Inventor, Trainer

Amit Singal
CEO Startup Buddy

Dev Pratap
Co-Founder & CEO Voice of Slum

Amey Vartak
Technology Consultant, Full Stack Developer, C# Corner MVP, Author

Viswanatha Swamy
Principal Software Engineer, C# Corner MVP, Author

Sanket Verma
Research Engineer @ Ballistics (Forensics) and Chair, PyData Delhi

Sourabh Somani
Lead Developer, Microsoft MVP, Author

Abhishek Mishra
Software Architect, C# Corner MVP, Author

Siddharth Vaghasia
Technical Consultant, C# Corner MVP, Blogger

Bassam Alugili
Senior Software Specialist, Database Expert

S Ravi Kumar
Solution Architect, C# Corner MVP, Author

Sundaram Subramanian
Full Stack Developer, C# Corner MVP, Speaker

Deepesh Somani
Solution Architect, Microsoft MVP, Author

Debasis Saha
Technical Project Manager, C# Corner MVP, Blogger, Author

Vipul Jain
Software Architect, C# Corner MVP, Author

Akshay Patel
Technical Architect, Microsoft Certified Trainer, C# Corner MVP, Author

Stephen Simon
RPA Developer, Evangelist, Author

Vivek Sharma
Founder Kingster636, AR/VR Specialist

Jeetendra Gund
Technical Lead, C# Corner MVP, Author

Sujal Beniwal
AI Enthusiast, Student

M Viknaraj
Microsoft MVP, Azure Architect, Author

Prasham Sabadra
Software Architect, C# Corner MVP, Trainer, Author

Aakash Maurya
Senior Developer, C# Corner MVP, Speaker

Ankit Sharma
Senior Software Engineer, C# Corner MVP, Author

Mangesh Gaherwar
Team Lead, C# Corner MVP, Author

Viral Jain
Technical Consultant, C# Corner MVP, Author

Bhasker Das
Solution Architect, Evangelist

Manish Dwivedi
Associate Project Manager

Ck Nitin
Programmer, Author

Rohit Gupta
Technical Trainer, Author

Manish Tewatia
Full-stack Marketer, UX Designer

Bhavya Gaur
Technical Illustrator

Rohit Tomar
SEO/SMO Expert

Web Track

Cloud & Data Track

Dev Track

8am-9am

Registration & Breakfast

9am-10am

Future of Desktop Apps with JS (ElectronJs)

Nitin Pandit

Building Serverless Microservices Using Microsoft Azure

Vithal Wadje

Innovating RPA: A Robot for Every Person

Stephen Simon

10am-11am

Managing Cloud Storage Accounts using Logic Apps

Viknaraj Manogararajah

Data visualization using Python

Sekhar Srinivasan

Going Cross platform with AR Foundation

Vivek Sharma

11am-12pm

Keynote

12pm-1pm

Managing your Azure dependencies in ASP.NET Core apps using VS

Bala Chirtsabesan

Securing Applications on Intelligent Azure

Abhishek Mishra

Getting started with Blazor the Framework of Future

S Ravi Kumar

1pm-2pm

Lunch

2pm-2:45pm

Build Progressive Web Apps using Angular 9

Debasis Saha

Build and deploy to any platform using Azure DevOps

Chervine Bhiwoo

Deep Dive in Azure Service Bus

Akshay Patel

2:45pm-3:45pm

Build a Native Mobile Application using React Native and JavaScript

Joseph Guadagno

Making sense of Web Job, Web Job SDK and Functions in Azure

Prakash Tripathi

CloudFront Distribution in AWS

Viral Jain

3:45pm-4pm

Tea Break

4pm-4:30pm

Introduction to PowerBI

Aakash Maurya

Build Advanced SPFx solutions with React and Graph API

Siddharth Vaghasia

Build Business Intelligence Analyst (BIA) Skills

Sundaram Subramanian

4:30pm-5pm

Deep dive of Power Platform – AI BUILDER

Prasham Sabadra

Panel 1

What's new in SharePoint development

Vipul Jain

5pm-5:30pm

Build a SSO (Single Sign On) based Native JavaScript application with Microsoft Identity within 10 minutes

Manoj Mittal

Panel 2

Applications and working of AI

Veena Sarda

5:30pm-6pm

Deploying serverless API's with .Net core 3.0 on AWS & Azure

Amey Vartak

Panel 3

Blockchain with .NET Core (Ark)

Anshu Kumari

6pm-6:30pm

Closing Note & Prize Distribution

Dev Track

Cloud Track

Architecture Track

Emerging Tech Track

8am-9am

Registration & Breakfast

9am-10am

Creating Full-Stack Web Apps Using Server-Side Blazor

Ankit Sharma

Real time face recognition with MS Cognitive Services

Niloshima Srivastava

Building Scalable APIs with GraphQL

Jeetendra Gund

Future of development with AI and Blockchain

Navdeep Garg

10am-11am

Debugging Tips and Tricks with Visual Studio 2019

Joseph Guadagno

Azure Containers

Abhishek Kant

Enterprise Architecture

Naveen Sharma

Bot Framework - learn it fast and look like a boss!

Allen O’Neill

11am-12:30pm

Keynote

12:30pm-1:30pm

.Net Core & C# 8 Performance

David McCarter

Working with Azure kubernetes services

Ritesh Modi

Becoming an Architect

Vidyavrat Agarwal

Why Techies Need to Learn Product Management

Saurabh Jain

1:30pm-2:30pm

Lunch

2:30pm-3:30pm

Build a rules engine in .Net Core

Sanjay Vyas

Building CI and CD Pipeline using Azure DevOps

Sandeep Soni

Entity Framework Core - Tips and Tricks, Performance Optimization, and Tuning

Bassam Alugili

Hacking your way into Data Science

Sanket Verma

3:30-4:15pm

Speed up your .Net Core Website

Sourabh Somani

Azure

Magnus Mårtensson

Demystifying Open Distro for Elasticsearch

Suman Debnath

Future of Data

Shivam Ahuja

4:15pm-4:30pm

Tea Break

4:30pm-5:15pm

gRPC with C# and .Net Core

Mangesh Gaherwar

Panel 1

Essentials of Cloud security

Parveen Malik

Power platform and Dynamics 365

Deepesh Somani

5:15pm-6pm

Microservices - the gRPC Way

Viswanatha Swamy

Panel 2

Reserved

Reserved

6pm-6:30pm

Closing Note & Prize Distribution

Practical rate limiting patterns for ASP.NET Core APIs

Public-facing APIs hosted in Australian data centres often experience sharp traffic spikes between 9am and 11am AEST, when Sydney and Melbourne offices start their day and queued batch jobs finally fire off accumulated requests. A well-tuned rate limiter keeps these bursts from overwhelming downstream services, throttles abusive clients, and gives backend teams predictable load. For organisations bound by the Privacy Act 1988, predictable throughput also reduces the chance of cascading failures that could trigger a notifiable data breach.

Rate limiting sits at the edge of an ASP.NET Core pipeline, where each incoming request is evaluated against a policy before any expensive work begins. Since .NET 7, the framework ships with a Microsoft.AspNetCore.RateLimiting middleware that supports several algorithms out of the box. This removes the historical need to pull in third-party libraries such as AspNetCoreRateLimit and keeps configuration declarative.

Australian developers working on fintech APIs in Brisbane or government portals in Canberra frequently need to combine rate limits with strong authentication and audit logging. The Australian Cyber Security Centre's Essential Eight guidance recommends rate limiting as a mitigation against brute-force and denial-of-service attempts, which makes the feature a practical checkbox for security accreditation. When the limiter rejects a request, the platform also needs a graceful response path that integrates cleanly with OpenTelemetry traces and existing Application Insights dashboards.

This article walks through choosing an algorithm, wiring the middleware into a typical Program.cs, partitioning limits per tenant, returning standards-compliant 429 responses, and finally observing the limiter in production. Code samples target .NET 8 and assume a hosted service running on Linux behind a reverse proxy, which is the common pattern for workloads deployed in Sydney or Perth regions of Azure.

Understanding rate limiting algorithms

The RateLimiter abstraction in ASP.NET Core supports four algorithms, each with different trade-offs around memory usage, fairness, and burst handling. Picking the right one is the foundation of a robust policy, because misconfigured limits either block legitimate traffic or fail to protect the backend during incidents.

A fixed window counter allows N requests per window of T seconds, resetting at the boundary. It is the cheapest to implement but suffers from boundary effects: a client can send N requests at second 59 and another N at second 60, effectively doubling the limit across two seconds. For low-stakes public endpoints in regional SaaS products, the simplicity often wins.

A sliding window refines the fixed approach by tracking the previous window's count and weighting it against the current window. Memory grows with the window size, but the boundary spike disappears. Token bucket replenishes tokens at a steady rate and allows controlled bursts up to the bucket capacity, which fits well for APIs serving a mix of human users and scheduled bots. Concurrency limiting caps the number of in-flight requests rather than the request rate, ideal for protecting a slow downstream like a SQL Server pool or an Azure SQL elastic database in Australia East.

Algorithm Memory per key Burst behaviour Best fit
Fixed window Constant High at boundary Public read endpoints
Sliding window Linear in window Smooth Mixed traffic APIs
Token bucket Constant Configurable burst APIs with batch jobs
Concurrency Constant None Slow DB or external calls

For most Australian SaaS products, a combination works best: a token bucket on authentication endpoints to absorb login storms, and a sliding window on per-user API keys to enforce monthly quotas.

Configuring the built-in middleware in Program.cs

The middleware lives in the Microsoft.AspNetCore.RateLimiting namespace and is registered through builder.Services.AddRateLimiter(...). A typical setup uses the named policy pattern, which lets different controllers or minimal API groups opt into different limits using [EnableRateLimiting("policyName")] or RequireRateLimiting.

builder.Services.AddRateLimiter(options =>
{
    options.RejectionStatusCode = StatusCodes.Status429TooManyRequests;
    options.OnRejected = async (context, token) =>
    {
        context.HttpContext.Response.Headers.RetryAfter =
            ((int)context.Lease.TryGetMetadata(MetadataName.RetryAfter)
                 ?.TotalSeconds ?? 1).ToString();
        await context.HttpContext.Response.WriteAsJsonAsync(new
        {
            error = "rate_limited",
            message = "Too many requests, slow down."
        }, token);
    };

    options.AddPolicy("per-user", httpContext =>
    {
        var userId = httpContext.User.Identity?.Name ?? "anonymous";
        return RateLimitPartition.GetTokenBucketLimiter(userId, _ => new TokenBucketRateLimiterOptions
        {
            TokenLimit = 60,
            ReplenishmentPeriod = TimeSpan.FromMinutes(1),
            TokensPerPeriod = 30,
            QueueLimit = 0,
            AutoReplenishment = true
        });
    });
});

The call to app.UseRateLimiter() must come after UseAuthentication and UseAuthorization so the partition key can read the authenticated user. Placing it before authentication would force the limiter to key on IP address alone, which is awkward for users behind carrier-grade NAT on the NBN in regional areas such as Tamworth or Cairns. The policy is then applied per endpoint with .RequireRateLimiting("per-user") inside a MapGet or MapPost chain.

Partitioning limits per client and endpoint

Partitioning is what turns a single global cap into a fair per-tenant or per-IP policy. The RateLimitPartition factory exposes keyed limiters, and the key is computed from the incoming HttpContext. Common keys include the authenticated subject, an API key header, an Azure AD app registration, or the remote IP address with httpContext.Connection.RemoteIpAddress.

For B2B APIs sold to Australian retailers, partitioning by API key is the standard contract. A starter plan might get 60 requests per minute while an enterprise SKU gets 600. The same pattern works for the federal government's data.gov.au style portals, where each agency receives its own quota. When the limiter is keyed on IP, developers in shared office spaces such as Sydney's WeWork buildings need to be careful: a noisy neighbour can exhaust the IP's quota and starve the rest of the floor.

Endpoint-specific limits are useful for expensive operations. A POST /reports endpoint that runs an Azure Synapse query in Australia Southeast might warrant a tighter concurrency limit than a GET /health probe. Combining endpoint and client partitions is straightforward by composing policies or applying the [EnableRateLimiting] attribute at the action level, while a global policy covers the rest of the surface.

Responding with 429 and Retry-After headers

A rejected request should never look like a server crash. The HTTP standard reserves 429 Too Many Requests for this scenario and recommends a Retry-After header in seconds or as an HTTP-date. Clients built on HttpClient in .NET 8 respect this header automatically when used with Polly's retry strategy, which simplifies resilience on both ends.

Beyond the header, returning a structured JSON body with an error code and a human-readable message helps integrators diagnose the problem. Logging the rejection at warning level with the partition key, the rejected policy name, and the lease metadata produces a trail that supports the Office of the Australian Information Commissioner's expectations around reasonable technical safeguards. Some teams in Melbourne and Adelaide go further and emit a custom metric for rate_limit_rejections_total keyed by tenant, which feeds straight into an Azure Monitor alert when the rate climbs during an incident.

For partner integrations written in older .NET Framework, a plain text body remains a safer fallback. The OnRejected callback shown earlier lets the response be tailored per policy, so anonymous traffic can receive a minimal response while authenticated clients get richer details.

Observability and tuning in production

Limits that work on a developer's laptop rarely survive contact with real traffic. Once the middleware is live, three signals guide tuning: the 429 rejection rate per partition, the queue length of the token bucket, and p95 latency of the protected endpoint. Each is exposed through RateLimiter statistics and can be wired into OpenTelemetry using a custom Meter.

Application Insights in the Australia East region captures these metrics alongside dependency calls, which makes it easy to correlate a spike in rejections with a slow Cosmos DB query. When tuning, raising the TokenLimit is rarely the right first move; instead, look at whether the partition key is too coarse. If every authenticated user shares a single bucket because the NameIdentifier claim is missing, the policy degrades to a global cap and legitimate users get blocked. Adding structured logging for httpContext.User.Identity.IsAuthenticated at the partition factory surfaces this during a post-incident review.

Finally, write a load test in k6 or NBomber that targets the Australian endpoints from a region close to Australia Central to verify behaviour under realistic latency. A limit that looks generous locally may still be too tight when round-trip time pushes requests into the next replenishment window. Adjusting the policy, redeploying, and comparing the next day's dashboard closes the loop and keeps the API fair for everyone from a solo founder in Hobart to a national retailer's integration team in Parramatta. A streaming workload like building a media streaming app with .NET Core and Azure Media Services can apply the same patterns to protect its ingest endpoints from encoder bursts.

The Leela Ambience Convention Hotel

1, CBD, Maharaj Surajmal Road, Near Yamuna Sports Complex, Delhi, 110032

KNOW MORE

GENERAL QUERIES


Manish Tewatia

+91-9718-431-042

TICKET QUERIES


Atul Gupta

+91-9910-125-804