IConfiguration vs IOptions NET
Synchronous and Asynchronous in .NET Core
Model Binding and Validation in ASP.NET Core
ControllerBase vs Controller in ASP.NET Core
ConfigureServices and Configure methods
IHostedService interface in .NET Core
ASP.NET Core request processing
| Database per Service Pattern :👈 | 👉:Securing an ASP.NET Core Web API |
API Gateway Security |
API Gateway Security refers to implementing security controls at the API Gateway layer to protect all backend microservices from unauthorized access, attacks, and misuse.
Instead of securing every microservice individually for common security concerns, the API Gateway acts as the central security checkpoint.
Without an API Gateway:
Client │ ├── Customer Service ├── Order Service ├── Payment Service ├── Inventory Service └── Shipping Service
Every service must implement:
This results in duplicated code and inconsistent security.
API Gateway
│
┌───────────────┼───────────────┐
│ │ │
▼ ▼ ▼
Customer Service Order Service Payment Service
The gateway becomes the single entry point.
All requests pass through it first.
Authentication answers:
"Who are you?"
The gateway validates:
Flow:
User Login
│
▼
Identity Provider
│
▼
JWT Token Generated
│
▼
API Gateway
│
Validate Token
│
▼
Microservice
Authorization: Bearer eyJhbGciOi...
The gateway validates the token before forwarding the request.
Authorization answers:
"What are you allowed to do?"
Example:
Admin
-> Create Product
-> Delete Product
Customer
-> View Product
-> Place Order
Gateway checks:
{
"role": "Admin"
}
before forwarding requests.
HTTPS encryption is usually handled at the gateway.
Client │ HTTPS ▼ API Gateway │ HTTP/HTTPS ▼ Microservices
Benefits:
Prevents abuse and DDoS-like traffic.
Example:
Maximum 100 Requests/Minute/User
If a client exceeds the limit:
429 Too Many Requests
User A
↓
5000 requests/minute
Gateway blocks excess requests.
Allow only specific IP addresses.
Allowed: 10.10.1.1 10.10.1.2
Block:
Unknown IPs
Used in:
Some APIs require an API key.
x-api-key: abcd1234
Gateway validates the key before forwarding.
Checks:
Example:
Content-Type: application/json
Reject invalid requests before they hit microservices.
Gateway can block:
Attack:
' OR 1=1 --
Attack:
<script>alert('hack')</script>
100 MB Request Body
Gateway rejects suspicious requests.
Gateway records:
Who accessed? When? Which API? Response Status?
User: john API: /orders Status: 200 Time: 10:20 AM
Useful for:
Gateway can detect:
1 Million Requests in a short period
and throttle/block traffic.
Common cloud protections:
dotnet add package Ocelot dotnet add package Microsoft.AspNetCore.Authentication.JwtBearer
builder.Services
.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
.AddJwtBearer(options =>
{
options.Authority =
"https://localhost:5001";
options.Audience = "microservices-api";
});
builder.Services.AddAuthorization();
{
"Routes": [
{
"UpstreamPathTemplate": "/orders/{everything}",
"DownstreamPathTemplate": "/api/orders/{everything}",
"DownstreamScheme": "https",
"DownstreamHostAndPorts": [
{
"Host": "localhost",
"Port": 7001
}
],
"AuthenticationOptions": {
"AuthenticationProviderKey": "Bearer"
}
}
]
}
app.UseAuthentication(); app.UseAuthorization(); await app.UseOcelot();
Now:
Client │ ▼ Ocelot Gateway │ Verify JWT │ ▼ Order Service
GET /orders/1001
Internet │ ▼ API Gateway │ ▼ Microservices
Stateless and scalable.
TLS 1.2+
Protects from abuse.
Use:
Extra protection against:
For an e-commerce application:
Client │ ▼ API Gateway │ ├── Customer Service ├── Product Service ├── Order Service ├── Payment Service └── Shipping Service
Security handled by Gateway:
Backend services focus only on business logic.
API Gateway Security is the practice of implementing security controls at the API Gateway layer in a microservices architecture. The gateway acts as a central entry point that handles authentication, authorization, SSL/TLS termination, rate limiting, API key validation, request filtering, logging, and protection against attacks such as DDoS, SQL Injection, and XSS. This centralizes security, reduces duplication across microservices, and improves manageability and consistency.
| Database per Service Pattern :👈 | 👉:Securing an ASP.NET Core Web API |