Magnus Mårtensson
Microsoft Regional Director, Azure MVP, CEO Loftysoft
Avirag Jain
Director & CTO R Systems
Mahesh Chand
Founder C# Corner, CEO Mindcracker
Chris Gali
CEO & Co-Founder Graphite
Subinder Khurana
Chief Architect StoryProcess, Founder NASSCOM DeepTech Club
Bryan Rishforth
Investor, Chairman Graphite
Bryn Everson
Director Biz Dev Graphite
Raj Tiwari
Digital Transformation Leader, Futurist and Visionary
Joseph Guadagno
Microsoft MVP, Lead Quicken Loans
Nikita Sachdev
Entrepreneur, Blockchain Enthusiast & Advisor, Social Media Influencer
Doug Wagner
COO & Founder Adapt Technical Group
Ritesh Modi
Architect, Senior Evangelist, Cloud Architect
Crystal Wenrick
Director Communications Mindcracker
Allen O’Neill
Microsoft MVP, Consulting Engineer/Architect
Praveen Kumar
CEO MCN Solutions
Chris Love
Founder Love2Dev, Microsoft MVP, Author
Sanjay Vyas
Microsoft Regional Director, Microsoft MVP, Founder & CEO SkillLabs Technologies
Veena Sarda
Deep Learning Consultant, Author
Sekhar Srinivasan
C# Corner MVP, Microsoft Certified Trainer, Pluralsight Author
Lalit Bansal
Founder & CEO - EIY SYS
Navdeep Garg
CEO Revinfotech
Prakash Tripathi
Tech Manager/Leader, Microsoft MVP, Blogger
Bhavna Jain
Breakthrough Consultant
Naveen Sharma
Enterprise Architect, Leadership Coach, Author
Vidya Vrat Agarwal
Principal Architect, Microsoft MVP, Author
Sheetal Agarwal
Founder Clownselors, Medical Clown, Trainer
Abhishek Kant
Founder GTM Catalyst
Vishnu Saran
Founder & CEO VoiceQube
Sandeep Soni
Founder & CEO Deccansoft, Microsoft Certified Trainer
Parveen Malik
AVP InfoSec & Vulnerability Management, Information Security Expert
Nitin Pandit
Microsoft MVP, Developer Evangelist, Author
Niloshima Srivastava
C# Corner MVP, Tech Architect, Trainer, Blogger
Bala Chirtsabesan
Senior Software Engineer at Microsoft, Author
Manoj Mittal
Sr. Technical Architect, C# Corner MVP, Author
Chandni Di
Co-Founder Voice of Slum
Vithal Wadje
Technical Lead, Microsoft MVP, Author
Shivam Ahuja
Founder SkillCircle, Business Mentor
Chervine Bhiwoo
Solution Architect, Microsoft MVP, Author
Saurabh Jain
Vice President Paytm, Founder Fun2Do Labs, Author
Vinay Solanki
Head IoT at Lenovo, Founder IoT-NCR
Anshu kumari
Founder Blockchainkids, Inventor, Trainer
Amit Singal
CEO Startup Buddy
Dev Pratap
Co-Founder & CEO Voice of Slum
Amey Vartak
Technology Consultant, Full Stack Developer, C# Corner MVP, Author
Viswanatha Swamy
Principal Software Engineer, C# Corner MVP, Author
Sanket Verma
Research Engineer @ Ballistics (Forensics) and Chair, PyData Delhi
Sourabh Somani
Lead Developer, Microsoft MVP, Author
Abhishek Mishra
Software Architect, C# Corner MVP, Author
Siddharth Vaghasia
Technical Consultant, C# Corner MVP, Blogger
Bassam Alugili
Senior Software Specialist, Database Expert
S Ravi Kumar
Solution Architect, C# Corner MVP, Author
Sundaram Subramanian
Full Stack Developer, C# Corner MVP, Speaker
Deepesh Somani
Solution Architect, Microsoft MVP, Author
Debasis Saha
Technical Project Manager, C# Corner MVP, Blogger, Author
Vipul Jain
Software Architect, C# Corner MVP, Author
Akshay Patel
Technical Architect, Microsoft Certified Trainer, C# Corner MVP, Author
Stephen Simon
RPA Developer, Evangelist, Author
Vivek Sharma
Founder Kingster636, AR/VR Specialist
Jeetendra Gund
Technical Lead, C# Corner MVP, Author
Sujal Beniwal
AI Enthusiast, Student
M Viknaraj
Microsoft MVP, Azure Architect, Author
Prasham Sabadra
Software Architect, C# Corner MVP, Trainer, Author
Aakash Maurya
Senior Developer, C# Corner MVP, Speaker
Ankit Sharma
Senior Software Engineer, C# Corner MVP, Author
Mangesh Gaherwar
Team Lead, C# Corner MVP, Author
Viral Jain
Technical Consultant, C# Corner MVP, Author
Bhasker Das
Solution Architect, Evangelist
Manish Dwivedi
Associate Project Manager
Ck Nitin
Programmer, Author
Rohit Gupta
Technical Trainer, Author
Manish Tewatia
Full-stack Marketer, UX Designer
Bhavya Gaur
Technical Illustrator
Rohit Tomar
SEO/SMO Expert
Web Track
Cloud & Data Track
Dev Track
Registration & Breakfast
Future of Desktop Apps with JS (ElectronJs)
Nitin Pandit
Building Serverless Microservices Using Microsoft Azure
Vithal Wadje
Innovating RPA: A Robot for Every Person
Stephen Simon
Managing Cloud Storage Accounts using Logic Apps
Viknaraj Manogararajah
Data visualization using Python
Sekhar Srinivasan
Going Cross platform with AR Foundation
Vivek Sharma
Keynote
Managing your Azure dependencies in ASP.NET Core apps using VS
Bala Chirtsabesan
Securing Applications on Intelligent Azure
Abhishek Mishra
Getting started with Blazor the Framework of Future
S Ravi Kumar
Lunch
Build Progressive Web Apps using Angular 9
Debasis Saha
Build and deploy to any platform using Azure DevOps
Chervine Bhiwoo
Deep Dive in Azure Service Bus
Akshay Patel
Build a Native Mobile Application using React Native and JavaScript
Joseph Guadagno
Making sense of Web Job, Web Job SDK and Functions in Azure
Prakash Tripathi
CloudFront Distribution in AWS
Viral Jain
Tea Break
Introduction to PowerBI
Aakash Maurya
Build Advanced SPFx solutions with React and Graph API
Siddharth Vaghasia
Build Business Intelligence Analyst (BIA) Skills
Sundaram Subramanian
Deep dive of Power Platform – AI BUILDER
Prasham Sabadra
Panel 1
What's new in SharePoint development
Vipul Jain
Build a SSO (Single Sign On) based Native JavaScript application with Microsoft Identity within 10 minutes
Manoj Mittal
Panel 2
Applications and working of AI
Veena Sarda
Deploying serverless API's with .Net core 3.0 on AWS & Azure
Amey Vartak
Panel 3
Blockchain with .NET Core (Ark)
Anshu Kumari
Closing Note & Prize Distribution
Dev Track
Cloud Track
Architecture Track
Emerging Tech Track
Registration & Breakfast
Creating Full-Stack Web Apps Using Server-Side Blazor
Ankit Sharma
Real time face recognition with MS Cognitive Services
Niloshima Srivastava
Building Scalable APIs with GraphQL
Jeetendra Gund
Future of development with AI and Blockchain
Navdeep Garg
Debugging Tips and Tricks with Visual Studio 2019
Joseph Guadagno
Azure Containers
Abhishek Kant
Enterprise Architecture
Naveen Sharma
Bot Framework - learn it fast and look like a boss!
Allen O’Neill
Keynote
.Net Core & C# 8 Performance
David McCarter
Working with Azure kubernetes services
Ritesh Modi
Becoming an Architect
Vidyavrat Agarwal
Why Techies Need to Learn Product Management
Saurabh Jain
Lunch
Build a rules engine in .Net Core
Sanjay Vyas
Building CI and CD Pipeline using Azure DevOps
Sandeep Soni
Entity Framework Core - Tips and Tricks, Performance Optimization, and Tuning
Bassam Alugili
Hacking your way into Data Science
Sanket Verma
Speed up your .Net Core Website
Sourabh Somani
Azure
Magnus Mårtensson
Demystifying Open Distro for Elasticsearch
Suman Debnath
Future of Data
Shivam Ahuja
Tea Break
gRPC with C# and .Net Core
Mangesh Gaherwar
Panel 1
Essentials of Cloud security
Parveen Malik
Power platform and Dynamics 365
Deepesh Somani
Microservices - the gRPC Way
Viswanatha Swamy
Panel 2
Reserved
Reserved
Closing Note & Prize Distribution
Implementing JWT Bearer Authentication In ASP.NET Core Razor Pages
JSON Web Tokens (JWTs) provide a compact way to represent a user’s identity and permissions between an ASP.NET Core application and a client. In a Razor Pages solution, JWT bearer authentication is especially useful when pages call separate Web APIs, JavaScript components, mobile apps, or services hosted in Microsoft Azure.
The important design decision is understanding where the token travels. A browser does not automatically attach a bearer token when a user moves between Razor Pages. JWT authentication works cleanly when the browser deliberately sends an Authorization: Bearer header, while traditional Razor Pages navigation often suits cookie authentication better. Selecting the right model early avoids awkward security workarounds later.
| Authentication approach | Best fit | Browser behaviour | Main security consideration |
|---|---|---|---|
| JWT bearer | APIs, SPAs, mobile clients, service-to-service calls | Token must be added to each request | Protect the access token from theft |
| Cookie authentication | Server-rendered Razor Pages | Browser sends the cookie automatically | Use antiforgery protection for state-changing requests |
| OpenID Connect | Enterprise sign-in and external identity providers | Redirects through an identity provider | Validate issuer, audience, and callback settings |
| API key | Simple internal integrations | Client sends a fixed key | Limited identity and rotation capabilities |
Choosing The Right Authentication Shape
A Razor Pages application can use JWT bearer authentication to protect page handlers, but the request must contain a valid bearer token. This commonly happens when a JavaScript client calls a protected handler or when another application consumes an endpoint hosted by the Razor Pages project.
For a standard server-rendered website, cookie authentication is usually more natural. The user signs in once, the server issues an encrypted authentication cookie, and subsequent page requests carry that cookie automatically. JWTs become a strong option when the same identity must be accepted by an API, a React or Blazor front end, a mobile client, and background services.
A practical architecture for an Australian business might use Razor Pages for an administration portal, an ASP.NET Core API for customer data, and Azure App Service in Australia East. The portal could use cookies for its page navigation while the API validates access tokens issued by Microsoft Entra ID or another identity provider. Mixing schemes is possible, but each endpoint should clearly state which scheme it expects.
Bearer tokens are self-contained. They normally include a subject identifier, issuer, audience, expiry time, and optional roles or scopes. The API validates the token’s signature and claims rather than querying a session store for every request. This improves scalability, although revoking an already-issued token requires a short lifetime, a deny list, or an identity provider with revocation support.
Preparing The ASP.NET Core Application
Install the JWT bearer package that matches the application’s target framework:
dotnet add package Microsoft.AspNetCore.Authentication.JwtBearer
Register authentication and authorisation in Program.cs. The signing key should come from a managed secret store, environment variable, or development secret rather than being committed to source control.
using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.IdentityModel.Tokens;
using System.Text;
var builder = WebApplication.CreateBuilder(args);
var signingKey = builder.Configuration["Jwt:SigningKey"]
?? throw new InvalidOperationException("JWT signing key is missing.");
builder.Services.AddRazorPages(options =>
{
options.Conventions.AuthorizeFolder("/Admin");
});
builder.Services.AddAuthentication(options =>
{
options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
})
.AddJwtBearer(options =>
{
options.TokenValidationParameters = new TokenValidationParameters
{
ValidateIssuerSigningKey = true,
IssuerSigningKey = new SymmetricSecurityKey(
Encoding.UTF8.GetBytes(signingKey)),
ValidateIssuer = true,
ValidIssuer = builder.Configuration["Jwt:Issuer"],
ValidateAudience = true,
ValidAudience = builder.Configuration["Jwt:Audience"],
ValidateLifetime = true,
ClockSkew = TimeSpan.FromMinutes(1)
};
});
builder.Services.AddAuthorization();
var app = builder.Build();
app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();
app.UseAuthentication();
app.UseAuthorization();
app.MapRazorPages();
app.Run();
The middleware order matters. Routing must run before authentication and authorisation can evaluate endpoint metadata. Authentication identifies the caller; authorisation then decides whether that caller can access the selected page or handler. If UseAuthentication() is omitted, HttpContext.User will not be populated from the token.
A configuration file can define the issuer and audience without exposing the signing key:
{
"Jwt": {
"Issuer": "https://login.example.com",
"Audience": "customer-api"
}
}
For an Australian deployment, Azure Key Vault is a sensible location for production secrets. Teams handling health, financial, or government-related information should also consider the hosting region, access logging, retention rules, and obligations under the Privacy Act 1988. Australia East in New South Wales and Australia Southeast in Victoria are common Azure regions, but the selected region should match contractual and data-residency requirements.
Issuing And Validating Access Tokens
The component that issues a token must authenticate the user first. A real system should normally delegate this responsibility to Microsoft Entra ID, an approved OpenID Connect provider, or a dedicated identity server. Creating a token after checking a password in a custom controller is possible, but password storage, multi-factor authentication, account recovery, lockout, and breach monitoring quickly become substantial responsibilities.
A simplified token creation example illustrates the required claims:
using System.IdentityModel.Tokens.Jwt;
using System.Security.Claims;
using System.Text;
using Microsoft.IdentityModel.Tokens;
var claims = new[]
{
new Claim(JwtRegisteredClaimNames.Sub, user.Id.ToString()),
new Claim(ClaimTypes.Name, user.Email),
new Claim(ClaimTypes.Role, "Manager")
};
var credentials = new SigningCredentials(
new SymmetricSecurityKey(Encoding.UTF8.GetBytes(signingKey)),
SecurityAlgorithms.HmacSha256);
var token = new JwtSecurityToken(
issuer: configuration["Jwt:Issuer"],
audience: configuration["Jwt:Audience"],
claims: claims,
expires: DateTime.UtcNow.AddMinutes(15),
signingCredentials: credentials);
var accessToken = new JwtSecurityTokenHandler().WriteToken(token);
Use UTC for token dates and keep access tokens short-lived. A refresh token, if required, should be handled as a separate credential with stronger storage and rotation rules. Never place passwords, payment details, or unnecessary personal information inside a JWT. Anyone holding the token can decode its payload, even though they cannot alter it without invalidating the signature.
Protect a Razor Page with the Authorize attribute:
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc.RazorPages;
[Authorize]
public class ReportsModel : PageModel
{
public string? CurrentUser { get; private set; }
public void OnGet()
{
CurrentUser = User.Identity?.Name;
}
}
Roles and policies provide more precise controls:
[Authorize(Policy = "Reports.Read")]
public class ReportsModel : PageModel
{
}
The policy must be registered with a matching claim requirement:
builder.Services.AddAuthorization(options =>
{
options.AddPolicy("Reports.Read", policy =>
policy.RequireClaim("scope", "reports.read"));
});
Keep claim names consistent with the identity provider. A token containing roles is not automatically equivalent to one containing a scope claim, and a mismatch can produce confusing 403 responses after authentication has succeeded.
Calling Protected Razor Page Handlers
A client must send the token in the standard HTTP header:
GET https://localhost:5001/Admin/Reports
Authorization: Bearer eyJhbGciOiJIUzI1NiIs...
A JavaScript client can add the header when calling a handler or API endpoint:
const response = await fetch("/Admin/Reports?handler=Summary", {
headers: {
"Authorization": `Bearer ${accessToken}`
}
});
The page model can expose a handler protected by the same page-level policy:
[Authorize]
public class ReportsModel : PageModel
{
public IActionResult OnGetSummary()
{
var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);
return new JsonResult(new
{
UserId = userId,
Status = "Available"
});
}
}
When an unauthenticated request arrives, ASP.NET Core returns a challenge, commonly a 401 response for bearer authentication. An authenticated user without sufficient claims receives a 403 response. These statuses are useful diagnostics: a 401 generally points to a missing, expired, malformed, or incorrectly signed token, while a 403 usually indicates a role, scope, or policy problem.
Avoid placing long-lived access tokens in browser local storage unless the application’s risk assessment accepts the consequences. A successful cross-site scripting attack can read local storage and send the token elsewhere. In many browser applications, keeping tokens in memory and using a secure, carefully designed refresh flow reduces exposure. If a token is placed in a cookie, configure Secure, HttpOnly, and an appropriate SameSite value, then assess cross-site request forgery risks.
Razor Pages forms still need antiforgery protection when cookies authenticate the request. Bearer tokens reduce the classic cookie-based CSRF pattern because the browser does not attach the header automatically, but they do not remove the need to prevent cross-site scripting. Encode output, validate input, apply a strong Content Security Policy where practical, and keep third-party scripts under control.
Operating Securely In Australian Environments
Australian users often expect fast responses across a large geography, from Perth to Brisbane and from Melbourne to regional New South Wales. Hosting an API in an Australian Azure region can reduce latency for local customers, but performance still depends on database placement, CDN configuration, private networking, and the location of external identity services.
Australian organisations also tend to assess security against the Essential Eight, industry-specific rules, and customer procurement requirements. JWT validation supports several of these controls, but it is only one part of the design. Apply HTTPS everywhere, rotate signing keys, restrict administrator access, patch dependencies, and send security events to a monitored logging platform. Do not log complete bearer tokens; redact the Authorization header and record safe identifiers such as issuer, audience, subject, and failure reason.
Deployment checks
- Store signing keys in Azure Key Vault or an equivalent managed secret service.
- Use distinct issuers, audiences, and keys for development, testing, and production.
- Set short access-token lifetimes and rotate refresh credentials.
- Confirm that application logs and backups do not contain token payloads or passwords.
A token issued for a staging API must not be accepted by production. Validate issuer and audience explicitly, and avoid accepting several audiences simply because it makes testing easier. When using RSA or an external identity provider, validate the signing certificate or discovery document and plan for key rollover.
Operational checks
- Alert on repeated invalid-token, expired-token, and forbidden-request events.
- Review roles and scopes whenever staff change teams or leave the organisation.
- Test clock differences between servers, especially across distributed services.
- Document data handling for customers in Sydney, Melbourne, Perth, and regional areas.
Clear documentation helps support teams explain a failed sign-in without resorting to guesswork. In an Australian workplace, someone might say a request is “bung” or that a deployment needs another “arvo” to settle, but the logs should provide precise technical evidence: whether the token was absent, expired, signed by an unknown key, aimed at the wrong audience, or rejected by a policy.
JWT bearer authentication is effective when its boundary is clear. Use it for APIs and clients that deliberately carry access tokens, validate every important claim, and avoid forcing it into ordinary page navigation where secure cookies may provide a simpler and safer user experience.
1, CBD, Maharaj Surajmal Road, Near Yamuna Sports Complex, Delhi, 110032
GENERAL QUERIES
Manish Tewatia
manish@csharpcon.com
+91-9718-431-042
TICKET QUERIES
Atul Gupta
conference@csharpcon.com
+91-9910-125-804