NET Centric ComputingUnit 95 min read
ASP.NET Core Security: Authentication, Authorization, Identity & Threats
Unit 9 of NET Centric Computing covers securing ASP.NET Core applications through authentication (Identity, OAuth, JWT), authorization (policies, roles, claims), data protection, and mitigating common threats like XSS, CSRF, and injection attacks. Real-world examples from eSewa, Ncell, and global platforms illustrate i
Key Concepts and Mechanisms
Authentication: Verifying User Identity
Authentication ensures that users are who they claim to be. In ASP.NET Core, this is typically handled via Identity Framework (built-in) or third-party providers (Google, Facebook, etc.).
1. ASP.NET Core Identity
- Built-in framework for managing user accounts, roles, and claims.
- Uses Entity Framework Core to store user data in a database.
- Supports password hashing, email confirmation, and two-factor authentication (2FA).
classDiagram
class User {
+string UserName
+string Email
+string PasswordHash
+bool EmailConfirmed
}
class Role {
+string Name
}
class Claim {
+string Type
+string Value
}
User "1" -- "0..*" Role : has
User "1" -- "0..*" Claim : has2. External Authentication (OAuth 2.0 / OpenID Connect)
- Allows users to log in using third-party providers (Google, Facebook, Microsoft).
- Uses JWT (JSON Web Tokens) for stateless authentication.
- Example: eSewa uses OAuth to integrate with banks for secure transactions.
sequenceDiagram
participant User
participant ClientApp
participant AuthServer
participant ResourceServer
User->>ClientApp: Requests login via Google
ClientApp->>AuthServer: Redirects to Google OAuth
AuthServer-->>ClientApp: Returns Access Token (JWT)
ClientApp->>ResourceServer: Sends JWT for API access
ResourceServer-->>ClientApp: Returns protected dataWorked Example: eSewa’s Secure Login
- When a user logs into eSewa via their bank, the system uses OAuth 2.0 to authenticate.
- The bank issues a JWT token, which eSewa validates before granting access.
- If the token is invalid, the request is rejected.
Authorization: Controlling Access
Authorization determines what an authenticated user can do. ASP.NET Core provides multiple ways to enforce access control:
1. Role-Based Authorization
- Users are assigned roles (e.g., Admin, User, Guest).
- Policies check if a user has a specific role before granting access.
// Example: Require "Admin" role
[Authorize(Roles = "Admin")]
public IActionResult AdminDashboard() { ... }
2. Policy-Based Authorization
- More flexible than roles; uses claims (e.g.,
CanEdit,IsPremiumUser). - Defined in
Startup.csorProgram.cs.
services.AddAuthorization(options =>
{
options.AddPolicy("RequirePremium", policy =>
policy.RequireClaim("PremiumUser"));
});
3. Claims-Based Authorization
- Users have claims (key-value pairs) attached to their identity.
- Example: A user with
Claim("Age", "18+")can access adult content.
Securing Data and APIs
1. Data Protection (Encryption)
- Anti-Forgery Tokens: Prevent CSRF (Cross-Site Request Forgery) attacks.
- HTTPS: Ensures data is encrypted in transit.
- JWT Validation: Ensures tokens are not tampered with.
2. API Security (OData, Swagger)
- Swagger/OpenAPI: Document APIs and enforce authentication.
- CORS (Cross-Origin Resource Sharing): Restrict which domains can access your API.
Worked Example: Ncell’s API Security
- Ncell’s developer portal uses OAuth 2.0 for API access.
- Each request must include a valid JWT token in the
Authorizationheader. - If missing or invalid, the API returns
401 Unauthorized.
Common Threats and Mitigations
| Threat | Description | Mitigation in ASP.NET Core |
|---|---|---|
| XSS (Cross-Site Scripting) | Inject malicious scripts into web pages. | Use HtmlEncoder and AntiForgeryToken. |
| CSRF | Trick users into executing unwanted actions. | Use [ValidateAntiForgeryToken] and same-site cookies. |
| SQL Injection | Malicious SQL queries via user input. | Use Entity Framework Core (parameterized queries). |
| Man-in-the-Middle (MITM) | Intercept communication between client and server. | Enforce HTTPS and HSTS. |
In the Real World
eSewa (Nepal)
- Uses OAuth 2.0 to integrate with banks for secure transactions.
- JWT tokens are issued after successful authentication, ensuring stateless security.
Ncell (Nepal)
- Secures its API using OAuth 2.0 and JWT validation.
- Prevents unauthorized access to user data via role-based policies.
Google (Global)
- Uses OpenID Connect for single sign-on (SSO) across services (Gmail, Drive).
- Claims-based authorization ensures users access only permitted features.
Exam Tip
- Authentication vs. Authorization:
- Authentication = "Who are you?" (Identity, OAuth, JWT).
- Authorization = "What can you do?" (Roles, Policies, Claims).
- Common Exam Questions:
- Explain how ASP.NET Core Identity stores user data.
- Compare role-based vs. policy-based authorization.
- Describe how JWT works in OAuth 2.0.
- List three security threats and their mitigations in ASP.NET Core.
- Practical Scenario:
- Given a scenario (e.g., "Design a secure login system for a bank"), explain:
- How OAuth 2.0 would be used.
- How JWT tokens would be validated.
- How role-based policies would restrict access.
- Given a scenario (e.g., "Design a secure login system for a bank"), explain:
Key Takeaways:
- ASP.NET Core Identity manages user accounts securely.
- OAuth 2.0/OpenID Connect enables third-party logins (e.g., Google, Facebook).
- JWT provides stateless authentication for APIs.
- Role-based and policy-based authorization control access.
- Always use HTTPS, anti-forgery tokens, and parameterized queries to prevent attacks.
Based on the TU BIT syllabus for NET Centric Computing (BIT351), unit 9.
Discussion
Loading…