Claude
Skills
Sign in
Back

aspnet-core-advanced

Included with Lifetime
$97 forever

Master advanced ASP.NET Core development including Entity Framework Core, authentication, testing, and enterprise patterns for production applications.

Backend & APIsscriptsassets

What this skill does


# ASP.NET Core Advanced Development

## Skill Overview

Production-grade advanced skill for enterprise ASP.NET Core applications. Covers Entity Framework Core 8/9, authentication, advanced testing, caching, and design patterns with comprehensive observability.

## Advanced Skills

### Entity Framework Core 8/9
```yaml
core_features:
  dbcontext:
    - Lifetime management (scoped)
    - Connection pooling
    - Query tracking behavior
    - Interceptors and events
    - Compiled models

  mapping:
    fluent_api:
      - Entity configuration
      - Relationships (HasOne, HasMany)
      - Complex types (.NET 8+)
      - JSON columns
      - Owned types
    conventions:
      - Table naming
      - Key naming
      - Property discovery

  queries:
    linq:
      - Projection (Select)
      - Filtering (Where)
      - Sorting (OrderBy)
      - Grouping (GroupBy)
      - Joins (Include, ThenInclude)
    raw_sql:
      - FromSqlRaw
      - FromSqlInterpolated
      - ExecuteSql

  performance:
    optimization:
      - No-tracking queries
      - Split queries (AsSplitQuery)
      - Compiled queries
      - Bulk operations
      - Connection resiliency
    monitoring:
      - Query logging
      - Execution plan analysis
      - Missing index detection

new_in_ef9:
  - LINQ improvements
  - Better JSON column support
  - Improved migrations
  - ExecuteUpdate/Delete enhancements
```

### Authentication & Authorization
```yaml
authentication_schemes:
  jwt_bearer:
    setup:
      - Configure token validation
      - Set issuer and audience
      - Configure signing key
    best_practices:
      - Short token expiry
      - Refresh token rotation
      - Secure key storage

  cookie:
    setup:
      - Configure cookie options
      - Set secure and httpOnly
      - Configure SameSite policy
    use_cases:
      - Server-rendered apps
      - MVC applications

  oauth2_openid:
    providers:
      - Microsoft Identity
      - Google
      - GitHub
      - Custom OIDC
    flows:
      - Authorization code
      - Client credentials
      - Device code

authorization:
  role_based:
    - [Authorize(Roles = "Admin")]
    - User.IsInRole("Admin")

  claims_based:
    - [Authorize(Policy = "RequireClaim")]
    - RequireClaim("permission", "read")

  policy_based:
    - Custom requirements
    - Authorization handlers
    - Resource-based

  resource_based:
    - IAuthorizationService
    - Document-level permissions
```

### Testing Strategies
```yaml
unit_testing:
  frameworks:
    - xUnit (recommended)
    - NUnit
    - MSTest
  patterns:
    - Arrange-Act-Assert (AAA)
    - Given-When-Then (BDD)
  mocking:
    - Moq
    - NSubstitute
    - FakeItEasy

integration_testing:
  web_application_factory:
    - In-memory test server
    - Custom configuration
    - Service replacement
  database:
    - In-memory provider
    - TestContainers
    - Respawn for cleanup

test_data:
  builders:
    - Fluent builders
    - Object mothers
    - AutoFixture
  fixtures:
    - Shared context
    - Disposable resources

coverage:
  tools:
    - Coverlet
    - ReportGenerator
  targets:
    - 80% line coverage
    - 70% branch coverage
```

### Caching Strategies
```yaml
in_memory:
  IMemoryCache:
    - Local cache
    - Fast access
    - Limited to single instance
  best_for:
    - Session data
    - Configuration
    - Frequently accessed data

distributed:
  IDistributedCache:
    providers:
      - Redis
      - SQL Server
      - NCache
    features:
      - Multi-instance support
      - Persistence
      - TTL policies

hybrid_cache:  # .NET 9
  features:
    - Two-tier caching
    - Automatic stampede protection
    - Tag-based invalidation
  configuration:
    - L1 (memory)
    - L2 (distributed)

output_caching:
  attributes:
    - [OutputCache(Duration = 60)]
    - [OutputCache(VaryByQuery = "id")]
  policies:
    - Custom cache policies
    - Cache profiles

response_caching:
  headers:
    - Cache-Control
    - ETag
    - Vary
```

### Performance Optimization
```yaml
async_patterns:
  best_practices:
    - Async all the way
    - Avoid .Result and .Wait()
    - Use CancellationToken
    - ConfigureAwait(false) in libraries
  common_issues:
    - Deadlocks
    - Thread starvation
    - Excessive allocations

memory_optimization:
  techniques:
    - Object pooling
    - Span<T> and Memory<T>
    - ArrayPool<T>
    - String interning
  tools:
    - dotnet-counters
    - dotnet-trace
    - Memory profilers

database_optimization:
  query_level:
    - Projection (select only needed)
    - Pagination
    - Indexing
    - Query splitting
  connection_level:
    - Connection pooling
    - Connection resiliency
    - Read replicas
```

## Code Examples

### Entity Framework Core Configuration
```csharp
// DbContext with production configuration
public class ApplicationDbContext : DbContext
{
    public ApplicationDbContext(DbContextOptions<ApplicationDbContext> options)
        : base(options) { }

    public DbSet<Product> Products => Set<Product>();
    public DbSet<Category> Categories => Set<Category>();
    public DbSet<Order> Orders => Set<Order>();

    protected override void OnModelCreating(ModelBuilder modelBuilder)
    {
        modelBuilder.ApplyConfigurationsFromAssembly(
            typeof(ApplicationDbContext).Assembly);

        // Global query filters
        modelBuilder.Entity<Product>()
            .HasQueryFilter(p => !p.IsDeleted);

        // JSON column mapping (.NET 8+)
        modelBuilder.Entity<Order>()
            .OwnsOne(o => o.ShippingAddress, builder =>
            {
                builder.ToJson();
            });
    }

    protected override void ConfigureConventions(
        ModelConfigurationBuilder configurationBuilder)
    {
        // Global conventions
        configurationBuilder.Properties<decimal>()
            .HavePrecision(18, 2);

        configurationBuilder.Properties<string>()
            .HaveMaxLength(500);
    }
}

// Entity configuration
public class ProductConfiguration : IEntityTypeConfiguration<Product>
{
    public void Configure(EntityTypeBuilder<Product> builder)
    {
        builder.ToTable("Products");

        builder.HasKey(p => p.Id);

        builder.Property(p => p.Name)
            .HasMaxLength(200)
            .IsRequired();

        builder.Property(p => p.Price)
            .HasPrecision(18, 2);

        builder.HasOne(p => p.Category)
            .WithMany(c => c.Products)
            .HasForeignKey(p => p.CategoryId)
            .OnDelete(DeleteBehavior.Restrict);

        builder.HasIndex(p => p.Sku)
            .IsUnique();

        builder.HasIndex(p => new { p.CategoryId, p.Name });
    }
}

// Registration with production settings
builder.Services.AddDbContext<ApplicationDbContext>(options =>
{
    options.UseSqlServer(
        builder.Configuration.GetConnectionString("Default"),
        sqlOptions =>
        {
            sqlOptions.EnableRetryOnFailure(
                maxRetryCount: 3,
                maxRetryDelay: TimeSpan.FromSeconds(30),
                errorNumbersToAdd: null);

            sqlOptions.CommandTimeout(30);
            sqlOptions.UseQuerySplittingBehavior(QuerySplittingBehavior.SplitQuery);
        });

    if (!builder.Environment.IsDevelopment())
    {
        options.UseQueryTrackingBehavior(QueryTrackingBehavior.NoTrackingWithIdentityResolution);
    }
});
```

### JWT Authentication Setup
```csharp
// Program.cs - JWT configuration
builder.Services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
})
.AddJwtBearer(options =>
{
    options.TokenValidationParameters = new TokenValidationParameters
    {
        ValidateIssuer = true,
        ValidateAudience = true,
        ValidateLifetime = true,
        ValidateIssuerSigningKey = true,
        ValidIssuer = builder.Configuration["Jwt:Issuer"],
        ValidAudience = build

Related in Backend & APIs