Part 6 · 1 chapters · ~8 min
ASP.NET Core End to End
A minimal API from dotnet new web, the middleware pipeline and its order, routing and parameter binding, validation, problem details (RFC 9457) errors, authentication with JWT bearer, authorisation policies, the built-in rate limiter, EF Core with Npgsql, idempotency keys, OpenAPI, health checks, and a controllers comparison.
7
A transfers endpoint
code
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddDbContext<LedgerDb>(o => o.UseNpgsql(builder.Configuration.GetConnectionString("Ledger")));
builder.Services.AddAuthentication().AddJwtBearer();
builder.Services.AddRateLimiter(o => o.AddTokenBucketLimiter("api", l => { l.TokenLimit = 100; l.TokensPerPeriod = 50; l.ReplenishmentPeriod = TimeSpan.FromSeconds(1); }));
builder.Services.AddProblemDetails();
builder.Services.AddScoped<TransferService>();
var app = builder.Build();
app.UseExceptionHandler(); app.UseAuthentication(); app.UseAuthorization(); app.UseRateLimiter();
app.MapPost("/v1/transfers", async ([FromHeader(Name = "Idempotency-Key")] string key, CreateTransfer body, TransferService svc, CancellationToken ct) =>
await svc.CreateAsync(body, key, ct) switch
{
TransferResult.Ok ok => Results.Created($"/v1/transfers/{ok.T.Id}", ok.T.ToDto()),
TransferResult.InsufficientFunds f => Results.Problem(statusCode: 422, title: "Insufficient funds", detail: $"Available: {f.Available}"),
_ => Results.Problem(statusCode: 500)
}).RequireAuthorization().RequireRateLimiting("api");
app.MapHealthChecks("/healthz");
app.Run();AN ASP.NET CORE REQUEST
Kestrel, middleware, routing, endpoint
swipe the figure sideways, or tap expand for full screen
1/4
Kestrel
Kestrel is ASP.NET Core's built-in, high-performance HTTP server; in production it often sits behind a reverse proxy or load balancer (part 10).
built-in serverfast, cross-platform