Magnus Mårtensson
Microsoft Regional Director, Azure MVP, CEO Loftysoft
Avirag Jain
Director & CTO R Systems
Mahesh Chand
Founder C# Corner, CEO Mindcracker
Chris Gali
CEO & Co-Founder Graphite
Subinder Khurana
Chief Architect StoryProcess, Founder NASSCOM DeepTech Club
Bryan Rishforth
Investor, Chairman Graphite
Bryn Everson
Director Biz Dev Graphite
Raj Tiwari
Digital Transformation Leader, Futurist and Visionary
Joseph Guadagno
Microsoft MVP, Lead Quicken Loans
Nikita Sachdev
Entrepreneur, Blockchain Enthusiast & Advisor, Social Media Influencer
Doug Wagner
COO & Founder Adapt Technical Group
Ritesh Modi
Architect, Senior Evangelist, Cloud Architect
Crystal Wenrick
Director Communications Mindcracker
Allen O’Neill
Microsoft MVP, Consulting Engineer/Architect
Praveen Kumar
CEO MCN Solutions
Chris Love
Founder Love2Dev, Microsoft MVP, Author
Sanjay Vyas
Microsoft Regional Director, Microsoft MVP, Founder & CEO SkillLabs Technologies
Veena Sarda
Deep Learning Consultant, Author
Sekhar Srinivasan
C# Corner MVP, Microsoft Certified Trainer, Pluralsight Author
Lalit Bansal
Founder & CEO - EIY SYS
Navdeep Garg
CEO Revinfotech
Prakash Tripathi
Tech Manager/Leader, Microsoft MVP, Blogger
Bhavna Jain
Breakthrough Consultant
Naveen Sharma
Enterprise Architect, Leadership Coach, Author
Vidya Vrat Agarwal
Principal Architect, Microsoft MVP, Author
Sheetal Agarwal
Founder Clownselors, Medical Clown, Trainer
Abhishek Kant
Founder GTM Catalyst
Vishnu Saran
Founder & CEO VoiceQube
Sandeep Soni
Founder & CEO Deccansoft, Microsoft Certified Trainer
Parveen Malik
AVP InfoSec & Vulnerability Management, Information Security Expert
Nitin Pandit
Microsoft MVP, Developer Evangelist, Author
Niloshima Srivastava
C# Corner MVP, Tech Architect, Trainer, Blogger
Bala Chirtsabesan
Senior Software Engineer at Microsoft, Author
Manoj Mittal
Sr. Technical Architect, C# Corner MVP, Author
Chandni Di
Co-Founder Voice of Slum
Vithal Wadje
Technical Lead, Microsoft MVP, Author
Shivam Ahuja
Founder SkillCircle, Business Mentor
Chervine Bhiwoo
Solution Architect, Microsoft MVP, Author
Saurabh Jain
Vice President Paytm, Founder Fun2Do Labs, Author
Vinay Solanki
Head IoT at Lenovo, Founder IoT-NCR
Anshu kumari
Founder Blockchainkids, Inventor, Trainer
Amit Singal
CEO Startup Buddy
Dev Pratap
Co-Founder & CEO Voice of Slum
Amey Vartak
Technology Consultant, Full Stack Developer, C# Corner MVP, Author
Viswanatha Swamy
Principal Software Engineer, C# Corner MVP, Author
Sanket Verma
Research Engineer @ Ballistics (Forensics) and Chair, PyData Delhi
Sourabh Somani
Lead Developer, Microsoft MVP, Author
Abhishek Mishra
Software Architect, C# Corner MVP, Author
Siddharth Vaghasia
Technical Consultant, C# Corner MVP, Blogger
Bassam Alugili
Senior Software Specialist, Database Expert
S Ravi Kumar
Solution Architect, C# Corner MVP, Author
Sundaram Subramanian
Full Stack Developer, C# Corner MVP, Speaker
Deepesh Somani
Solution Architect, Microsoft MVP, Author
Debasis Saha
Technical Project Manager, C# Corner MVP, Blogger, Author
Vipul Jain
Software Architect, C# Corner MVP, Author
Akshay Patel
Technical Architect, Microsoft Certified Trainer, C# Corner MVP, Author
Stephen Simon
RPA Developer, Evangelist, Author
Vivek Sharma
Founder Kingster636, AR/VR Specialist
Jeetendra Gund
Technical Lead, C# Corner MVP, Author
Sujal Beniwal
AI Enthusiast, Student
M Viknaraj
Microsoft MVP, Azure Architect, Author
Prasham Sabadra
Software Architect, C# Corner MVP, Trainer, Author
Aakash Maurya
Senior Developer, C# Corner MVP, Speaker
Ankit Sharma
Senior Software Engineer, C# Corner MVP, Author
Mangesh Gaherwar
Team Lead, C# Corner MVP, Author
Viral Jain
Technical Consultant, C# Corner MVP, Author
Bhasker Das
Solution Architect, Evangelist
Manish Dwivedi
Associate Project Manager
Ck Nitin
Programmer, Author
Rohit Gupta
Technical Trainer, Author
Manish Tewatia
Full-stack Marketer, UX Designer
Bhavya Gaur
Technical Illustrator
Rohit Tomar
SEO/SMO Expert
Web Track
Cloud & Data Track
Dev Track
Registration & Breakfast
Future of Desktop Apps with JS (ElectronJs)
Nitin Pandit
Building Serverless Microservices Using Microsoft Azure
Vithal Wadje
Innovating RPA: A Robot for Every Person
Stephen Simon
Managing Cloud Storage Accounts using Logic Apps
Viknaraj Manogararajah
Data visualization using Python
Sekhar Srinivasan
Going Cross platform with AR Foundation
Vivek Sharma
Keynote
Managing your Azure dependencies in ASP.NET Core apps using VS
Bala Chirtsabesan
Securing Applications on Intelligent Azure
Abhishek Mishra
Getting started with Blazor the Framework of Future
S Ravi Kumar
Lunch
Build Progressive Web Apps using Angular 9
Debasis Saha
Build and deploy to any platform using Azure DevOps
Chervine Bhiwoo
Deep Dive in Azure Service Bus
Akshay Patel
Build a Native Mobile Application using React Native and JavaScript
Joseph Guadagno
Making sense of Web Job, Web Job SDK and Functions in Azure
Prakash Tripathi
CloudFront Distribution in AWS
Viral Jain
Tea Break
Introduction to PowerBI
Aakash Maurya
Build Advanced SPFx solutions with React and Graph API
Siddharth Vaghasia
Build Business Intelligence Analyst (BIA) Skills
Sundaram Subramanian
Deep dive of Power Platform – AI BUILDER
Prasham Sabadra
Panel 1
What's new in SharePoint development
Vipul Jain
Build a SSO (Single Sign On) based Native JavaScript application with Microsoft Identity within 10 minutes
Manoj Mittal
Panel 2
Applications and working of AI
Veena Sarda
Deploying serverless API's with .Net core 3.0 on AWS & Azure
Amey Vartak
Panel 3
Blockchain with .NET Core (Ark)
Anshu Kumari
Closing Note & Prize Distribution
Dev Track
Cloud Track
Architecture Track
Emerging Tech Track
Registration & Breakfast
Creating Full-Stack Web Apps Using Server-Side Blazor
Ankit Sharma
Real time face recognition with MS Cognitive Services
Niloshima Srivastava
Building Scalable APIs with GraphQL
Jeetendra Gund
Future of development with AI and Blockchain
Navdeep Garg
Debugging Tips and Tricks with Visual Studio 2019
Joseph Guadagno
Azure Containers
Abhishek Kant
Enterprise Architecture
Naveen Sharma
Bot Framework - learn it fast and look like a boss!
Allen O’Neill
Keynote
.Net Core & C# 8 Performance
David McCarter
Working with Azure kubernetes services
Ritesh Modi
Becoming an Architect
Vidyavrat Agarwal
Why Techies Need to Learn Product Management
Saurabh Jain
Lunch
Build a rules engine in .Net Core
Sanjay Vyas
Building CI and CD Pipeline using Azure DevOps
Sandeep Soni
Entity Framework Core - Tips and Tricks, Performance Optimization, and Tuning
Bassam Alugili
Hacking your way into Data Science
Sanket Verma
Speed up your .Net Core Website
Sourabh Somani
Azure
Magnus Mårtensson
Demystifying Open Distro for Elasticsearch
Suman Debnath
Future of Data
Shivam Ahuja
Tea Break
gRPC with C# and .Net Core
Mangesh Gaherwar
Panel 1
Essentials of Cloud security
Parveen Malik
Power platform and Dynamics 365
Deepesh Somani
Microservices - the gRPC Way
Viswanatha Swamy
Panel 2
Reserved
Reserved
Closing Note & Prize Distribution
Implementing GraphQL APIs with HotChocolate and .NET
GraphQL gives clients a flexible way to request exactly the data they need through a strongly typed API. For .NET teams, HotChocolate provides a practical implementation built around familiar concepts such as dependency injection, middleware, Entity Framework Core, authentication and automated testing. It can sit alongside an existing ASP.NET Core application or become the main gateway for several services.
The approach is useful when a web application, mobile client and internal dashboard consume related data in different shapes. Instead of maintaining multiple REST endpoints for every screen, a GraphQL API exposes a discoverable schema and lets each client compose a query. This can reduce over-fetching, simplify front-end integration and give teams a clear contract between services and consumers.
Australian organisations also need to consider operational context from the beginning. A product serving customers in Sydney, Melbourne and Brisbane may use Azure Australia East or Australia Southeast for lower latency and data residency requirements. Teams must also account for the Privacy Act 1988, Australian Privacy Principles and the expectations of local customers around secure handling of personal information.
Choosing GraphQL for a .NET application
GraphQL is best suited to applications with connected domain data and several clients with different requirements. An e-commerce application might need products, categories, stock levels, reviews and delivery options on one page, while a warehouse tool needs only stock and fulfilment details. A single query can represent each use case without forcing the server to create a separate endpoint for every view.
HotChocolate is a widely used GraphQL server for the .NET ecosystem. It supports schema-first and code-first development, query resolvers, mutations, subscriptions, filtering, sorting, projections and pagination. Its integration with ASP.NET Core means that configuration, logging, authentication and dependency injection can follow established Microsoft development practices.
GraphQL does introduce a different set of responsibilities. Clients can submit expensive or deeply nested operations, and schema changes need careful governance because fields may remain in use for a long time. A successful implementation therefore starts with clear domain boundaries, query limits and an agreed approach to versioning rather than treating GraphQL as a thin replacement for every REST endpoint.
Designing a clear and durable schema
A GraphQL schema should describe business concepts rather than expose database tables. Types such as Customer, Order, Product and DeliveryAddress are easier for clients to understand than persistence-specific names. Fields should use consistent naming, meaningful nullability and types that reflect real business rules. A field that is always present should not be nullable simply because the database column happens to allow null values.
Queries retrieve data, mutations change state and subscriptions publish events to connected clients. A query might retrieve an order summary, while a mutation confirms payment or updates a delivery address. Mutations should be designed around business actions where possible, so that validation and authorisation have a clear home. Returning a useful payload with the changed object and any validation errors also makes client behaviour more predictable.
HotChocolate can build a schema from C# types and resolver methods, which allows teams to move quickly. Attributes can provide a lightweight configuration style, while explicit descriptor classes give larger projects more control over naming, middleware and field visibility. Schema documentation should be treated as part of the API contract, with descriptions that explain business meaning rather than repeating a property name.
Building resolvers with HotChocolate
A resolver is the component that obtains or calculates a field’s value. In a small application it may call Entity Framework Core directly, but larger systems generally benefit from a service layer. Resolvers should coordinate domain operations and data access without becoming large blocks of application logic. Registering those services through ASP.NET Core dependency injection keeps the design testable.
A common performance problem is the N+1 query pattern. A query for many orders may resolve each order’s customer separately, causing a large number of database calls. HotChocolate’s DataLoader pattern batches related lookups and caches results during the lifetime of a GraphQL request. This is particularly useful for relationships such as order-to-customer, product-to-category or invoice-to-account.
Entity Framework Core integration can add filtering, sorting and projection capabilities to suitable fields. Projection allows the database query to select only the columns needed by the GraphQL operation, reducing unnecessary data transfer. These features should be reviewed against generated SQL and database indexes rather than enabled indiscriminately. Complex joins and unrestricted filtering can still produce slow queries, even when the API syntax looks concise.
Connecting clients, databases and external services
A GraphQL endpoint commonly sits above more than one data source. A resolver may combine records from SQL Server, an inventory service, a payment provider and a search index. The schema should hide that implementation detail while preserving clear error behaviour. A temporary failure in a recommendation service should not necessarily make a customer’s basic product information unavailable.
Mutations need transactional thinking. If an operation creates an order, reserves stock and requests payment, the API should define what happens when one step fails. A domain service or orchestration layer can enforce those rules, publish an event and return a useful result. GraphQL itself does not replace a transaction manager, queue or distributed workflow pattern.
For Australian businesses, external integrations may include local payment providers, logistics platforms and government-related services. Data flows should be documented, especially where a provider stores information outside Australia. A Melbourne retailer serving customers nationwide may need to distinguish delivery addresses, billing records and analytics data so that each is retained and shared for a justified purpose.
Securing queries and personal information
ASP.NET Core authentication can establish the identity of a caller, while HotChocolate authorisation rules determine which types and fields that caller may access. A customer should see their own orders, a support employee may see selected account details, and an administrator may manage catalogue data. Field-level controls are important because hiding a screen in the front end does not protect an exposed API field.
Input validation should apply to arguments, variables and mutation payloads. Reject invalid identifiers, enforce sensible string lengths and validate date ranges before a resolver reaches the database. Query depth, complexity and maximum execution time limits help prevent abusive operations. Introspection may remain enabled for trusted development environments but should be assessed carefully for public production endpoints.
The Privacy Act 1988 and Australian Privacy Principles make privacy an engineering concern rather than a document produced after deployment. Avoid returning sensitive fields by default, redact personal data from logs and define retention rules for traces and failed requests. Encryption in transit and at rest, secret storage through a managed service and least-privilege database access are baseline controls for applications operating in Australia’s regulated market.
Testing schema behaviour and performance
GraphQL testing should cover the public contract as well as the underlying C# services. Schema tests can verify that required types and fields exist, deprecated fields are marked correctly and mutations return the expected payload. Resolver unit tests are useful for business rules, while integration tests can execute real GraphQL documents against a test database or a containerised dependency.
Representative queries should test authorisation boundaries. A user who owns one account must not retrieve another account by changing an identifier in a variable. Tests should also check partial errors, null handling and behaviour when an external service is unavailable. Snapshot testing can help detect accidental schema changes, although snapshots need review so that harmless formatting changes do not obscure meaningful differences.
Performance testing should use realistic nested queries rather than a simple request for one scalar field. Measure database round trips, response size, resolver duration and memory use. Test DataLoader batching, pagination and complexity limits under concurrent load. This matters for Australian services with sharp demand peaks, such as retail campaigns, ticket releases or morning commuter traffic in Sydney and Melbourne.
Operating the API in production
A production GraphQL service needs observability that follows an operation from the client through resolvers and downstream dependencies. Record operation names, duration, status and selected cost metrics, while excluding tokens, passwords and personal information. Correlation IDs make it easier to connect a failed request with application logs, database traces and queue activity.
Pagination should be the default for collections that can grow without a fixed limit. Cursor-based pagination is usually more stable than offset pagination when records are added or removed between requests. Persisted queries can restrict known operations, reduce request size and provide an additional control for public mobile applications. Caching should respect authorisation and personalisation boundaries; a cached private response must never become visible to another user.
Hosting in an Azure region close to the intended audience can improve responsiveness, but location alone does not guarantee compliance or resilience. Teams should define backups, disaster recovery targets and failover arrangements, including how dependent services behave when an Australian region is unavailable. The following comparison highlights practical choices for a .NET GraphQL deployment:
| Concern | Practical choice | Reason |
|---|---|---|
| Schema style | Code-first with explicit descriptors | Fast development with stronger control for a growing schema |
| Data access | EF Core plus DataLoader | Efficient projections and batched relationship queries |
| Client protection | Pagination, depth limits and persisted queries | Reduces accidental and abusive expensive operations |
| Identity | ASP.NET Core authentication with field-level authorisation | Aligns access decisions with existing .NET security |
| Hosting | Azure Australia East or Australia Southeast where appropriate | Supports latency, residency and operational requirements |
| Monitoring | Structured logs, traces and operation metrics | Helps locate resolver, database and integration failures |
A staged rollout is safer than replacing every endpoint at once. An ASP.NET Core application can expose GraphQL beside existing REST services, allowing one client or domain area to migrate first. Schema usage metrics can identify fields that are ready for deprecation, while contract tests protect consumers during ongoing development.
The most effective implementation treats GraphQL as a governed product interface. HotChocolate supplies the server capabilities, but durable results depend on thoughtful schema design, efficient data access, strong privacy controls and disciplined operations. With those foundations, a .NET team can provide flexible APIs that serve Australian customers and internal users without sacrificing performance or accountability.
1, CBD, Maharaj Surajmal Road, Near Yamuna Sports Complex, Delhi, 110032
GENERAL QUERIES
Manish Tewatia
manish@csharpcon.com
+91-9718-431-042
TICKET QUERIES
Atul Gupta
conference@csharpcon.com
+91-9910-125-804