New to site?


Lost password? (X)

Already have an account?


(X)

Presents

#CSHARPCON20

The C# Corner Annual Conference 2020 is a three-day annual event for software professionals and developers.

3
DAYS
72
SPEAKERS
65
SESSIONS

Magnus Mårtensson
Microsoft Regional Director, Azure MVP, CEO Loftysoft

Avirag Jain
Director & CTO R Systems

Mahesh Chand
Founder C# Corner, CEO Mindcracker

Chris Gali
CEO & Co-Founder Graphite

Subinder Khurana
Chief Architect StoryProcess, Founder NASSCOM DeepTech Club

Bryan Rishforth
Investor, Chairman Graphite

Bryn Everson
Director Biz Dev Graphite

Raj Tiwari
Digital Transformation Leader, Futurist and Visionary

Joseph Guadagno
Microsoft MVP, Lead Quicken Loans

Nikita Sachdev
Entrepreneur, Blockchain Enthusiast & Advisor, Social Media Influencer

Doug Wagner
COO & Founder Adapt Technical Group

Ritesh Modi
Architect, Senior Evangelist, Cloud Architect

Crystal Wenrick
Director Communications Mindcracker

Allen O’Neill
Microsoft MVP, Consulting Engineer/Architect

Praveen Kumar
CEO MCN Solutions

Chris Love
Founder Love2Dev, Microsoft MVP, Author

Sanjay Vyas
Microsoft Regional Director, Microsoft MVP, Founder & CEO SkillLabs Technologies

Veena Sarda
Deep Learning Consultant, Author

Sekhar Srinivasan
C# Corner MVP, Microsoft Certified Trainer, Pluralsight Author

Lalit Bansal
Founder & CEO - EIY SYS

Navdeep Garg
CEO Revinfotech

Prakash Tripathi
Tech Manager/Leader, Microsoft MVP, Blogger

Bhavna Jain
Breakthrough Consultant

Naveen Sharma
Enterprise Architect, Leadership Coach, Author

Vidya Vrat Agarwal
Principal Architect, Microsoft MVP, Author

Sheetal Agarwal
Founder Clownselors, Medical Clown, Trainer

Abhishek Kant
Founder GTM Catalyst

Vishnu Saran
Founder & CEO VoiceQube

Sandeep Soni
Founder & CEO Deccansoft, Microsoft Certified Trainer

Parveen Malik
AVP InfoSec & Vulnerability Management, Information Security Expert

Nitin Pandit
Microsoft MVP, Developer Evangelist, Author

Niloshima Srivastava
C# Corner MVP, Tech Architect, Trainer, Blogger

Bala Chirtsabesan
Senior Software Engineer at Microsoft, Author

Manoj Mittal
Sr. Technical Architect, C# Corner MVP, Author

Chandni Di
Co-Founder Voice of Slum

Vithal Wadje
Technical Lead, Microsoft MVP, Author

Shivam Ahuja
Founder SkillCircle, Business Mentor

Chervine Bhiwoo
Solution Architect, Microsoft MVP, Author

Saurabh Jain
Vice President Paytm, Founder Fun2Do Labs, Author

Vinay Solanki
Head IoT at Lenovo, Founder IoT-NCR

Anshu kumari
Founder Blockchainkids, Inventor, Trainer

Amit Singal
CEO Startup Buddy

Dev Pratap
Co-Founder & CEO Voice of Slum

Amey Vartak
Technology Consultant, Full Stack Developer, C# Corner MVP, Author

Viswanatha Swamy
Principal Software Engineer, C# Corner MVP, Author

Sanket Verma
Research Engineer @ Ballistics (Forensics) and Chair, PyData Delhi

Sourabh Somani
Lead Developer, Microsoft MVP, Author

Abhishek Mishra
Software Architect, C# Corner MVP, Author

Siddharth Vaghasia
Technical Consultant, C# Corner MVP, Blogger

Bassam Alugili
Senior Software Specialist, Database Expert

S Ravi Kumar
Solution Architect, C# Corner MVP, Author

Sundaram Subramanian
Full Stack Developer, C# Corner MVP, Speaker

Deepesh Somani
Solution Architect, Microsoft MVP, Author

Debasis Saha
Technical Project Manager, C# Corner MVP, Blogger, Author

Vipul Jain
Software Architect, C# Corner MVP, Author

Akshay Patel
Technical Architect, Microsoft Certified Trainer, C# Corner MVP, Author

Stephen Simon
RPA Developer, Evangelist, Author

Vivek Sharma
Founder Kingster636, AR/VR Specialist

Jeetendra Gund
Technical Lead, C# Corner MVP, Author

Sujal Beniwal
AI Enthusiast, Student

M Viknaraj
Microsoft MVP, Azure Architect, Author

Prasham Sabadra
Software Architect, C# Corner MVP, Trainer, Author

Aakash Maurya
Senior Developer, C# Corner MVP, Speaker

Ankit Sharma
Senior Software Engineer, C# Corner MVP, Author

Mangesh Gaherwar
Team Lead, C# Corner MVP, Author

Viral Jain
Technical Consultant, C# Corner MVP, Author

Bhasker Das
Solution Architect, Evangelist

Manish Dwivedi
Associate Project Manager

Ck Nitin
Programmer, Author

Rohit Gupta
Technical Trainer, Author

Manish Tewatia
Full-stack Marketer, UX Designer

Bhavya Gaur
Technical Illustrator

Rohit Tomar
SEO/SMO Expert

Web Track

Cloud & Data Track

Dev Track

8am-9am

Registration & Breakfast

9am-10am

Future of Desktop Apps with JS (ElectronJs)

Nitin Pandit

Building Serverless Microservices Using Microsoft Azure

Vithal Wadje

Innovating RPA: A Robot for Every Person

Stephen Simon

10am-11am

Managing Cloud Storage Accounts using Logic Apps

Viknaraj Manogararajah

Data visualization using Python

Sekhar Srinivasan

Going Cross platform with AR Foundation

Vivek Sharma

11am-12pm

Keynote

12pm-1pm

Managing your Azure dependencies in ASP.NET Core apps using VS

Bala Chirtsabesan

Securing Applications on Intelligent Azure

Abhishek Mishra

Getting started with Blazor the Framework of Future

S Ravi Kumar

1pm-2pm

Lunch

2pm-2:45pm

Build Progressive Web Apps using Angular 9

Debasis Saha

Build and deploy to any platform using Azure DevOps

Chervine Bhiwoo

Deep Dive in Azure Service Bus

Akshay Patel

2:45pm-3:45pm

Build a Native Mobile Application using React Native and JavaScript

Joseph Guadagno

Making sense of Web Job, Web Job SDK and Functions in Azure

Prakash Tripathi

CloudFront Distribution in AWS

Viral Jain

3:45pm-4pm

Tea Break

4pm-4:30pm

Introduction to PowerBI

Aakash Maurya

Build Advanced SPFx solutions with React and Graph API

Siddharth Vaghasia

Build Business Intelligence Analyst (BIA) Skills

Sundaram Subramanian

4:30pm-5pm

Deep dive of Power Platform – AI BUILDER

Prasham Sabadra

Panel 1

What's new in SharePoint development

Vipul Jain

5pm-5:30pm

Build a SSO (Single Sign On) based Native JavaScript application with Microsoft Identity within 10 minutes

Manoj Mittal

Panel 2

Applications and working of AI

Veena Sarda

5:30pm-6pm

Deploying serverless API's with .Net core 3.0 on AWS & Azure

Amey Vartak

Panel 3

Blockchain with .NET Core (Ark)

Anshu Kumari

6pm-6:30pm

Closing Note & Prize Distribution

Dev Track

Cloud Track

Architecture Track

Emerging Tech Track

8am-9am

Registration & Breakfast

9am-10am

Creating Full-Stack Web Apps Using Server-Side Blazor

Ankit Sharma

Real time face recognition with MS Cognitive Services

Niloshima Srivastava

Building Scalable APIs with GraphQL

Jeetendra Gund

Future of development with AI and Blockchain

Navdeep Garg

10am-11am

Debugging Tips and Tricks with Visual Studio 2019

Joseph Guadagno

Azure Containers

Abhishek Kant

Enterprise Architecture

Naveen Sharma

Bot Framework - learn it fast and look like a boss!

Allen O’Neill

11am-12:30pm

Keynote

12:30pm-1:30pm

.Net Core & C# 8 Performance

David McCarter

Working with Azure kubernetes services

Ritesh Modi

Becoming an Architect

Vidyavrat Agarwal

Why Techies Need to Learn Product Management

Saurabh Jain

1:30pm-2:30pm

Lunch

2:30pm-3:30pm

Build a rules engine in .Net Core

Sanjay Vyas

Building CI and CD Pipeline using Azure DevOps

Sandeep Soni

Entity Framework Core - Tips and Tricks, Performance Optimization, and Tuning

Bassam Alugili

Hacking your way into Data Science

Sanket Verma

3:30-4:15pm

Speed up your .Net Core Website

Sourabh Somani

Azure

Magnus Mårtensson

Demystifying Open Distro for Elasticsearch

Suman Debnath

Future of Data

Shivam Ahuja

4:15pm-4:30pm

Tea Break

4:30pm-5:15pm

gRPC with C# and .Net Core

Mangesh Gaherwar

Panel 1

Essentials of Cloud security

Parveen Malik

Power platform and Dynamics 365

Deepesh Somani

5:15pm-6pm

Microservices - the gRPC Way

Viswanatha Swamy

Panel 2

Reserved

Reserved

6pm-6:30pm

Closing Note & Prize Distribution

Implementing JWT Bearer Authentication In ASP.NET Core Razor Pages

JSON Web Tokens (JWTs) provide a compact way to represent a user’s identity and permissions between an ASP.NET Core application and a client. In a Razor Pages solution, JWT bearer authentication is especially useful when pages call separate Web APIs, JavaScript components, mobile apps, or services hosted in Microsoft Azure.

The important design decision is understanding where the token travels. A browser does not automatically attach a bearer token when a user moves between Razor Pages. JWT authentication works cleanly when the browser deliberately sends an Authorization: Bearer header, while traditional Razor Pages navigation often suits cookie authentication better. Selecting the right model early avoids awkward security workarounds later.

Authentication approach Best fit Browser behaviour Main security consideration
JWT bearer APIs, SPAs, mobile clients, service-to-service calls Token must be added to each request Protect the access token from theft
Cookie authentication Server-rendered Razor Pages Browser sends the cookie automatically Use antiforgery protection for state-changing requests
OpenID Connect Enterprise sign-in and external identity providers Redirects through an identity provider Validate issuer, audience, and callback settings
API key Simple internal integrations Client sends a fixed key Limited identity and rotation capabilities

Choosing The Right Authentication Shape

A Razor Pages application can use JWT bearer authentication to protect page handlers, but the request must contain a valid bearer token. This commonly happens when a JavaScript client calls a protected handler or when another application consumes an endpoint hosted by the Razor Pages project.

For a standard server-rendered website, cookie authentication is usually more natural. The user signs in once, the server issues an encrypted authentication cookie, and subsequent page requests carry that cookie automatically. JWTs become a strong option when the same identity must be accepted by an API, a React or Blazor front end, a mobile client, and background services.

A practical architecture for an Australian business might use Razor Pages for an administration portal, an ASP.NET Core API for customer data, and Azure App Service in Australia East. The portal could use cookies for its page navigation while the API validates access tokens issued by Microsoft Entra ID or another identity provider. Mixing schemes is possible, but each endpoint should clearly state which scheme it expects.

Bearer tokens are self-contained. They normally include a subject identifier, issuer, audience, expiry time, and optional roles or scopes. The API validates the token’s signature and claims rather than querying a session store for every request. This improves scalability, although revoking an already-issued token requires a short lifetime, a deny list, or an identity provider with revocation support.

Preparing The ASP.NET Core Application

Install the JWT bearer package that matches the application’s target framework:

dotnet add package Microsoft.AspNetCore.Authentication.JwtBearer

Register authentication and authorisation in Program.cs. The signing key should come from a managed secret store, environment variable, or development secret rather than being committed to source control.

using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.IdentityModel.Tokens;
using System.Text;

var builder = WebApplication.CreateBuilder(args);

var signingKey = builder.Configuration["Jwt:SigningKey"]
    ?? throw new InvalidOperationException("JWT signing key is missing.");

builder.Services.AddRazorPages(options =>
{
    options.Conventions.AuthorizeFolder("/Admin");
});

builder.Services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
})
.AddJwtBearer(options =>
{
    options.TokenValidationParameters = new TokenValidationParameters
    {
        ValidateIssuerSigningKey = true,
        IssuerSigningKey = new SymmetricSecurityKey(
            Encoding.UTF8.GetBytes(signingKey)),

        ValidateIssuer = true,
        ValidIssuer = builder.Configuration["Jwt:Issuer"],

        ValidateAudience = true,
        ValidAudience = builder.Configuration["Jwt:Audience"],

        ValidateLifetime = true,
        ClockSkew = TimeSpan.FromMinutes(1)
    };
});

builder.Services.AddAuthorization();

var app = builder.Build();

app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();

app.UseAuthentication();
app.UseAuthorization();

app.MapRazorPages();

app.Run();

The middleware order matters. Routing must run before authentication and authorisation can evaluate endpoint metadata. Authentication identifies the caller; authorisation then decides whether that caller can access the selected page or handler. If UseAuthentication() is omitted, HttpContext.User will not be populated from the token.

A configuration file can define the issuer and audience without exposing the signing key:

{
  "Jwt": {
    "Issuer": "https://login.example.com",
    "Audience": "customer-api"
  }
}

For an Australian deployment, Azure Key Vault is a sensible location for production secrets. Teams handling health, financial, or government-related information should also consider the hosting region, access logging, retention rules, and obligations under the Privacy Act 1988. Australia East in New South Wales and Australia Southeast in Victoria are common Azure regions, but the selected region should match contractual and data-residency requirements.

Issuing And Validating Access Tokens

The component that issues a token must authenticate the user first. A real system should normally delegate this responsibility to Microsoft Entra ID, an approved OpenID Connect provider, or a dedicated identity server. Creating a token after checking a password in a custom controller is possible, but password storage, multi-factor authentication, account recovery, lockout, and breach monitoring quickly become substantial responsibilities.

A simplified token creation example illustrates the required claims:

using System.IdentityModel.Tokens.Jwt;
using System.Security.Claims;
using System.Text;
using Microsoft.IdentityModel.Tokens;

var claims = new[]
{
    new Claim(JwtRegisteredClaimNames.Sub, user.Id.ToString()),
    new Claim(ClaimTypes.Name, user.Email),
    new Claim(ClaimTypes.Role, "Manager")
};

var credentials = new SigningCredentials(
    new SymmetricSecurityKey(Encoding.UTF8.GetBytes(signingKey)),
    SecurityAlgorithms.HmacSha256);

var token = new JwtSecurityToken(
    issuer: configuration["Jwt:Issuer"],
    audience: configuration["Jwt:Audience"],
    claims: claims,
    expires: DateTime.UtcNow.AddMinutes(15),
    signingCredentials: credentials);

var accessToken = new JwtSecurityTokenHandler().WriteToken(token);

Use UTC for token dates and keep access tokens short-lived. A refresh token, if required, should be handled as a separate credential with stronger storage and rotation rules. Never place passwords, payment details, or unnecessary personal information inside a JWT. Anyone holding the token can decode its payload, even though they cannot alter it without invalidating the signature.

Protect a Razor Page with the Authorize attribute:

using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc.RazorPages;

[Authorize]
public class ReportsModel : PageModel
{
    public string? CurrentUser { get; private set; }

    public void OnGet()
    {
        CurrentUser = User.Identity?.Name;
    }
}

Roles and policies provide more precise controls:

[Authorize(Policy = "Reports.Read")]
public class ReportsModel : PageModel
{
}

The policy must be registered with a matching claim requirement:

builder.Services.AddAuthorization(options =>
{
    options.AddPolicy("Reports.Read", policy =>
        policy.RequireClaim("scope", "reports.read"));
});

Keep claim names consistent with the identity provider. A token containing roles is not automatically equivalent to one containing a scope claim, and a mismatch can produce confusing 403 responses after authentication has succeeded.

Calling Protected Razor Page Handlers

A client must send the token in the standard HTTP header:

GET https://localhost:5001/Admin/Reports
Authorization: Bearer eyJhbGciOiJIUzI1NiIs...

A JavaScript client can add the header when calling a handler or API endpoint:

const response = await fetch("/Admin/Reports?handler=Summary", {
    headers: {
        "Authorization": `Bearer ${accessToken}`
    }
});

The page model can expose a handler protected by the same page-level policy:

[Authorize]
public class ReportsModel : PageModel
{
    public IActionResult OnGetSummary()
    {
        var userId = User.FindFirstValue(ClaimTypes.NameIdentifier);

        return new JsonResult(new
        {
            UserId = userId,
            Status = "Available"
        });
    }
}

When an unauthenticated request arrives, ASP.NET Core returns a challenge, commonly a 401 response for bearer authentication. An authenticated user without sufficient claims receives a 403 response. These statuses are useful diagnostics: a 401 generally points to a missing, expired, malformed, or incorrectly signed token, while a 403 usually indicates a role, scope, or policy problem.

Avoid placing long-lived access tokens in browser local storage unless the application’s risk assessment accepts the consequences. A successful cross-site scripting attack can read local storage and send the token elsewhere. In many browser applications, keeping tokens in memory and using a secure, carefully designed refresh flow reduces exposure. If a token is placed in a cookie, configure Secure, HttpOnly, and an appropriate SameSite value, then assess cross-site request forgery risks.

Razor Pages forms still need antiforgery protection when cookies authenticate the request. Bearer tokens reduce the classic cookie-based CSRF pattern because the browser does not attach the header automatically, but they do not remove the need to prevent cross-site scripting. Encode output, validate input, apply a strong Content Security Policy where practical, and keep third-party scripts under control.

Operating Securely In Australian Environments

Australian users often expect fast responses across a large geography, from Perth to Brisbane and from Melbourne to regional New South Wales. Hosting an API in an Australian Azure region can reduce latency for local customers, but performance still depends on database placement, CDN configuration, private networking, and the location of external identity services.

Australian organisations also tend to assess security against the Essential Eight, industry-specific rules, and customer procurement requirements. JWT validation supports several of these controls, but it is only one part of the design. Apply HTTPS everywhere, rotate signing keys, restrict administrator access, patch dependencies, and send security events to a monitored logging platform. Do not log complete bearer tokens; redact the Authorization header and record safe identifiers such as issuer, audience, subject, and failure reason.

Deployment checks

  • Store signing keys in Azure Key Vault or an equivalent managed secret service.
  • Use distinct issuers, audiences, and keys for development, testing, and production.
  • Set short access-token lifetimes and rotate refresh credentials.
  • Confirm that application logs and backups do not contain token payloads or passwords.

A token issued for a staging API must not be accepted by production. Validate issuer and audience explicitly, and avoid accepting several audiences simply because it makes testing easier. When using RSA or an external identity provider, validate the signing certificate or discovery document and plan for key rollover.

Operational checks

  • Alert on repeated invalid-token, expired-token, and forbidden-request events.
  • Review roles and scopes whenever staff change teams or leave the organisation.
  • Test clock differences between servers, especially across distributed services.
  • Document data handling for customers in Sydney, Melbourne, Perth, and regional areas.

Clear documentation helps support teams explain a failed sign-in without resorting to guesswork. In an Australian workplace, someone might say a request is “bung” or that a deployment needs another “arvo” to settle, but the logs should provide precise technical evidence: whether the token was absent, expired, signed by an unknown key, aimed at the wrong audience, or rejected by a policy.

JWT bearer authentication is effective when its boundary is clear. Use it for APIs and clients that deliberately carry access tokens, validate every important claim, and avoid forcing it into ordinary page navigation where secure cookies may provide a simpler and safer user experience.

The Leela Ambience Convention Hotel

1, CBD, Maharaj Surajmal Road, Near Yamuna Sports Complex, Delhi, 110032

KNOW MORE

GENERAL QUERIES


Manish Tewatia

+91-9718-431-042

TICKET QUERIES


Atul Gupta

+91-9910-125-804