CSC367 NET Centric Computing

NET Centric ComputingUnit 76 min read

Authentication & ASP.NET Core Identity: Roles, Claims, Identity Framework

Unit 7 of NET Centric Computing covers ASP.NET Core Identity—how to implement secure user authentication (login, registration, role-based access), claims-based identity, and integration with external providers (Google, Facebook) using Identity Framework. Learn about Identity models, password hashing, cookie-based auth,


---

## **Core Concepts: Authentication vs. Authorization**
Authentication is the process of verifying a user’s identity (e.g., username/password, biometrics). Authorization determines what an authenticated user can access (e.g., admin vs. regular user).

```figure
{"type":"tree","root":{"v":"Authentication & Authorization","children":[{"v":"Authentication","children":[{"v":"What it is","children":[{"v":"Verifies identity (e.g., username/password, OAuth)"}]},{"v":"How it works","children":[{"v":"1. User submits credentials"},{"v":"2. System validates against stored data"},{"v":"3. Grants access if valid"}]},{"v":"Types","children":[{"v":"Password-based"},{"v":"Multi-factor (MFA)"},{"v":"External (Google, Facebook)"},{"v":"Certificate-based"}]}]},{"v":"Authorization","children":[{"v":"What it is","children":[{"v":"Determines access rights (e.g., admin vs. user)"}]},{"v":"How it works","children":[{"v":"1. Checks user roles/claims"},{"v":"2. Grants/denies permissions"},{"v":"3. Logs access for auditing"}]}]}]},"caption":"Hierarchical comparison of Authentication vs. Authorization"}

ASP.NET Core Identity Framework

Identity Framework is a built-in library for managing users, roles, and claims. It includes:

  • User Store: Stores user data (username, email, hashed passwords).
  • Role Store: Manages role assignments (e.g., Admin, Customer).
  • Claim Store: Stores user attributes (e.g., Email, FullName).
  • Password Hasher: Securely hashes passwords (never store plaintext).
IdentityUser (User model)IdentityRole (Role model)UserManager<TUser> (User operations)RoleManager<IRole> (Role operations)SignInManager<TUser> (Authentication)ASP.NET Core Identity Framework
Core classes in ASP.NET Core Identity Framework

Key Classes

Class Purpose
UserManager<TUser> Manages user creation, login, and password updates.
RoleManager<TRole> Manages role creation and assignment.
SignInManager<TUser> Handles login/logout and external logins (e.g., Google, Facebook).
ClaimsPrincipal Represents the authenticated user and their claims.

How Authentication Works in ASP.NET Core

  1. User Registration:

    • Client submits Username, Email, Password.
    • UserManager.CreateAsync() hashes the password and saves the user.
    var user = new ApplicationUser { UserName = "john.doe", Email = "john@example.com" };
    var result = await _userManager.CreateAsync(user, "Secure@Pass123");
    
  2. User Login:

    • Client submits credentials → SignInManager.PasswordSignInAsync() validates them.
    • If valid, a cookie (or token) is issued with user claims.
  3. Role Assignment:

    • Admins assign roles using RoleManager:
    await _roleManager.CreateAsync(new IdentityRole("Admin"));
    await _userManager.AddToRoleAsync(user, "Admin");
    
  4. Authorization:

    • Use [Authorize(Roles = "Admin")] on controllers/actions to restrict access.

Real-World Example: eSewa’s User Authentication

eSewa uses ASP.NET Core Identity (or a similar framework) to:

  • Register users with email/phone verification.
  • Authenticate via OTP or password.
  • Assign roles (e.g., Customer, Merchant, Admin).
  • Authorize actions like transferring money (only Admin can freeze accounts).

Claims-Based Identity

Claims are key-value pairs describing user attributes (e.g., Email, IsAdmin). Example:

var claims = new List<Claim>
{
    new Claim(ClaimTypes.Email, "user@example.com"),
    new Claim(ClaimTypes.Name, "John Doe"),
    new Claim("Department", "IT")
};
var identity = new ClaimsIdentity(claims, "CustomAuth");
var principal = new ClaimsPrincipal(identity);

Use Case: A bank app might use claims to show different menus:

  • IsAdmin=true → Admin dashboard.
  • Department=Finance → Finance-specific features.
2005Microsoftintroduces Windows Ide2012OAuth 2.0standardized for web A2016ASP.NET CoreIdentity 1.0 released2020Claim-based authbecomes default in .NE
Key milestones in claims-based identity evolution

External Login Providers (Google, Facebook)

ASP.NET Core supports OAuth for external logins:

services.AddAuthentication()
    .AddGoogle(options =>
    {
        options.ClientId = "your-client-id";
        options.ClientSecret = "your-client-secret";
    });

How it works:

  1. User clicks "Login with Google."
  2. Redirects to Google’s OAuth endpoint.
  3. Google returns a token → ASP.NET validates it and creates a local user if needed.

OAuth 2.0 flow diagramAuthorization code grant process (Image: Premeditated, CC0, via Wikimedia Commons)


Security Threats & Mitigations

Threat Description Mitigation in ASP.NET Core Identity
Brute Force Attacks Repeated login attempts. Lockout after failed attempts (LockoutEnabled).
Password Leaks Plaintext passwords stored. Use PasswordHasher (PBKDF2/SHA256).
CSRF Fake login forms stealing cookies. Use [ValidateAntiForgeryToken] and AntiForgery.
Session Hijacking Stolen session cookies. Use SameSite cookies and HTTPS.
011.2522.533.7545Brute Force Attacks45CSRF30XSS20Session Hijacking5Insecure Direct Object Reference10
Common ASP.NET security threats (2023 survey data)

Exam Tip

  1. Differentiate Authentication vs. Authorization:
    • Authentication = "Who are you?" (login).
    • Authorization = "What can you do?" (roles/claims).
  2. ASP.NET Core Identity Components:
    • Memorize UserManager, RoleManager, and SignInManager.
  3. External Logins:
    • Know OAuth flow (Authorization Code Grant).
  4. Security:
    • Always hash passwords, use [Authorize], and enable HTTPS.
  5. Practical Questions:
    • Expect code snippets for registration/login (e.g., CreateAsync, PasswordSignInAsync).
    • Be ready to explain role-based access control (RBAC) with [Authorize(Roles = "Admin")].

Based on the TU BSc CSIT syllabus for NET Centric Computing (CSC367), unit 7.

Discussion

Loading…