Official Syllabus

Unit V — Syllabus Overview

Designing Web API and ASP.NET Core Ecosystem — official course topics mapped to hands-on sessions.

Unit – V
Designing Web API and ASP.NET Core Ecosystem
10
Designing Web API – Building a Web API with ASP.NET Core – Designing RESTful Interface – Securing a web API. ASP.NET Core Runtime Environment – ASP.NET core host – Embedded HTTP Server – ASP.NET Core middleware.

📘 How to read this page: The official syllabus contains 8 major topics. Below, each syllabus topic is visually connected to the sessions in this course that teach it. Click any session pill to jump directly to that session.

Syllabus Topic Flow

This diagram shows how the official Unit V syllabus branches into topics, and each topic is covered by one or more sessions in this course.

UNIT V Designing Web API and ASP.NET Core Ecosystem (10 Credits)
Topic 1
Designing Web API
Foundations of Web APIs, HTTP, and client-server communication.
S1 S2 S3 S4
Topic 2
Building a Web API with ASP.NET Core
Visual Studio project, structure, Program.cs, models, controllers.
S5 S6 S7 S8 S9
Topic 3
Designing RESTful Interface
GET, POST, PUT, DELETE, REST principles, status codes.
S10 S11 S12 S13 S14 S15 S16
Topic 4
Securing a Web API
Authentication, Authorization, JWT tokens, [Authorize] attribute.
S22 S23 S24 S25
Topic 5
ASP.NET Core Runtime Environment
The .NET runtime, CLR, memory management, application lifetime.
S19
Topic 6
ASP.NET Core Host
Generic Host, configuration, logging, dependency injection, lifetime.
S20
Topic 7
Embedded HTTP Server
Kestrel — the cross-platform web server built into ASP.NET Core.
S21
Topic 8
ASP.NET Core Middleware
Request/response pipeline, ordering, custom middleware.
S18

Supplementary Sessions

These sessions support the syllabus topics with testing, practice, and complete picture walkthroughs.

Swagger Testing

Session 17 — Test the API endpoints interactively.

Complete Request Flow

Session 26 — End-to-end request lifecycle.

Complete Project

Session 27 — All files ready to copy.

Hands-On Exercises

Session 28 — 8 levels of practice.

Interview Questions

Session 29 — 18 beginner-friendly Q&A.

Final Revision

Session 30 — Cheat sheet and final flow.

Syllabus → Session Mapping Table

# Syllabus Topic Covered In Sessions
1 Designing Web API Sessions 1, 2, 3, 4
2 Building a Web API with ASP.NET Core Sessions 5, 6, 7, 8, 9
3 Designing RESTful Interface Sessions 10, 11, 12, 13, 14, 15, 16
4 Securing a Web API Sessions 22, 23, 24, 25
5 ASP.NET Core Runtime Environment Session 19
6 ASP.NET Core Host Session 20
7 Embedded HTTP Server Session 21
8 ASP.NET Core Middleware Session 18
+ Supplementary (Testing, Practice, Revision) Sessions 17, 26, 27, 28, 29, 30

✅ Coverage: Every topic in the official Unit V syllabus is covered by at least one session in this course, with additional sessions dedicated to hands-on practice, testing, and revision.

Dashboard

Session Dashboard

All 30 sessions in Unit V — click any card to jump to that session.

📊 Total Sessions: 30  |  Completed: 0 / 30

Section 01

What Are We Building?

Introducing the Product Management Web API — the single application we'll build throughout Unit V.

🎯 Our Goal: Build a complete REST API called ProductApi that manages products.

The Application: Product Management API

We are building a Web API that allows any client (web app, mobile app, Postman, Swagger) to manage a list of products.

CREATE
POST
READ
GET
UPDATE
PUT
DELETE
DELETE

💡 Memory Trick: CRUD = Create, Read, Update, Delete → POST, GET, PUT, DELETE.

Section 02

Web Application Basics

Before writing code, let's understand how web applications work.

The Big Picture

USER
↓
FRONTEND
↓
WEB API
↓
BACKEND
↓
DATABASE
↓
RESPONSE

Real-Life Analogy: The Restaurant

CUSTOMER
↓
WAITER (API)
↓
KITCHEN (Backend)
↓
FOOD (Response)
Section 03

What is an API?

API stands for Application Programming Interface.

Simple Definition: An API is a set of rules that allows two applications to talk to each other.

How a Web API Works

CLIENT
↓
HTTP REQUEST
↓
WEB API
↓
HTTP RESPONSE (JSON)
↓
CLIENT displays data
Section 04

What is ASP.NET Core?

ASP.NET Core is the framework we'll use to build our Web API.

Simple Definition: ASP.NET Core is a free, open-source, cross-platform framework by Microsoft for building modern web applications and APIs using C#.

Cross-Platform

Runs on Windows, Linux, and macOS.

High Performance

One of the fastest web frameworks available.

Section 05

Create Project in Visual Studio

Step-by-step guide to creating your ProductApi project.

🎯 What you'll do: Create a new ASP.NET Core Web API project named ProductApi.

Alternative: Using the .NET CLI

Terminal — CLI Commands
dotnet new webapi -n ProductApi
cd ProductApi
dotnet run

⚠️ Important: Port numbers in console output are examples only. Your actual ports will differ.

Section 06

Project Structure

Understanding the files and folders created by Visual Studio.

ProductApi/
├── Controllers/
│ └── ProductsController.cs
├── Models/
│ └── Product.cs
├── Program.cs
├── appsettings.json
└── ProductApi.csproj
Section 07

Program.cs

The entry point of every ASP.NET Core application.

Program.cs
var builder = WebApplication.CreateBuilder(args);

builder.Services.AddControllers();

var app = builder.Build();

app.UseHttpsRedirection();
app.UseAuthorization();
app.MapControllers();

app.Run();
CREATE
↓
CONFIGURE
↓
BUILD
↓
PIPELINE
↓
RUN
Section 08

Model

Creating the Product model — the blueprint for our data.

Models/Product.cs
namespace ProductApi.Models;

public class Product
{
    public int Id { get; set; }
    public string Name { get; set; } = string.Empty;
    public decimal Price { get; set; }
}

💡 Analogy: A model is like a form with fields for Id, Name, and Price.

Section 09

Controller

Creating the ProductsController — the heart of our API.

Controllers/ProductsController.cs
using Microsoft.AspNetCore.Mvc;
using ProductApi.Models;

namespace ProductApi.Controllers;

[ApiController]
[Route("api/[controller]")]
public class ProductsController : ControllerBase
{
    private static readonly List<Product> Products = new()
    {
        new Product { Id = 1, Name = "Laptop", Price = 50000 },
        new Product { Id = 2, Name = "Mouse", Price = 1000 }
    };

    [HttpGet]
    public IActionResult GetAll() => Ok(Products);

    [HttpGet("{id}")]
    public IActionResult GetById(int id)
    {
        var product = Products.FirstOrDefault(x => x.Id == id);
        if (product == null) return NotFound();
        return Ok(product);
    }

    [HttpPost]
    public IActionResult Create(Product product)
    {
        product.Id = Products.Count + 1;
        Products.Add(product);
        return Created("", product);
    }

    [HttpPut("{id}")]
    public IActionResult Update(int id, Product product)
    {
        var existing = Products.FirstOrDefault(x => x.Id == id);
        if (existing == null) return NotFound();
        existing.Name = product.Name;
        existing.Price = product.Price;
        return Ok(existing);
    }

    [HttpDelete("{id}")]
    public IActionResult Delete(int id)
    {
        var product = Products.FirstOrDefault(x => x.Id == id);
        if (product == null) return NotFound();
        Products.Remove(product);
        return NoContent();
    }
}

⚠️ Important: The in-memory list is only for learning. In production, use a database with Entity Framework Core.

Section 10

GET API

Reading data — the most common API operation.

GET means READ. Never modifies data — only reads it.

Interactive Simulation

Simulate a GET request.

// Click "Send GET Request"...
Section 11

POST API

Creating new data — adding products to our collection.

POST means CREATE. Sends data in the request body.

Interactive Simulation
// Fill fields and click...
Section 12

GET by ID

Retrieving a specific product by its unique identifier.

Interactive Simulation
// Enter ID and click...
Section 13

PUT API

Updating existing data — modifying product details.

Interactive Simulation
// Fill fields and click...
Section 14

DELETE API

Removing data — deleting products from the collection.

Interactive Simulation
// Enter ID and click...
Section 15

RESTful API

Understanding the design style behind our API.

REST = Representational State Transfer. A set of rules for designing APIs.

MethodEndpointAction
GET/api/productsRead All
GET/api/products/1Read One
POST/api/productsCreate
PUT/api/products/1Update
DELETE/api/products/1Delete
Section 16

HTTP Status Codes

What the server tells the client with each response.

200 OK
Success
Request succeeded.
201 Created
Resource Created
New resource created.
204 No Content
Success, No Body
Succeeded, nothing to return.
400 Bad Request
Invalid Request
Malformed request.
401 Unauthorized
Not Authenticated
Log in required.
403 Forbidden
Not Authorized
No permission.
404 Not Found
Resource Missing
Resource doesn't exist.
500 Internal Server Error
Server Bug
Unexpected server error.
Section 17

Swagger Testing

Testing your API without writing any client code.

Swagger/OpenAPI gives us a browser-based interface for testing our API.

/swagger/v1/swagger.json

ProductApi

v1

GET /api/products Get all products
// Click "Try it out"
POST /api/products Add a new product
// Click "Try it out"
PUT /api/products/{id} Update a product
// Click "Try it out"
DELETE /api/products/{id} Delete a product
// Click "Try it out"

⚠️ Note: This Swagger UI is a simulation. Real Swagger runs when you launch ProductApi in Visual Studio and visit /swagger.

Section 18

Middleware

The request/response pipeline.

REQUEST
↓
Middleware 1
↓
Middleware 2
↓
CONTROLLER
↓
RESPONSE
Program.cs — Full Pipeline
var app = builder.Build();

// ORDER IS CRITICAL!
app.UseExceptionHandler("/Error");
app.UseHttpsRedirection();
app.UseRouting();
app.UseAuthentication();
app.UseAuthorization();
app.MapControllers();

app.Run();
Section 19

ASP.NET Core Runtime

The environment that runs your application.

C# Code
↓
.NET Runtime (CLR)
↓
ASP.NET Core
↓
Your Application
Section 20

Generic Host

The manager of your application.

Host
├── Configuration
├── Logging
├── Dependency Injection
├── Application Lifetime
└── Server (Kestrel)

The Host is like a manager of a company. It sets up everything and keeps the app running.

Section 21

Kestrel

The embedded HTTP server.

Browser
↓
HTTPS Request
↓
Kestrel
↓
ASP.NET Core Runtime
↓
Middleware
↓
Controller

Kestrel is like the reception desk of a building. Every request first arrives here, then gets directed to the right place.

Section 22

Authentication

"Who are you?" — Verifying identity.

User
↓
Login
↓
Verify credentials
↓
Identity verified ✓
Section 23

Authorization

"What are you allowed to do?"

Authentication

Question: WHO are you?

Result: 401 if it fails.

Authorization

Question: WHAT can you do?

Result: 403 if it fails.

Section 24

JWT

JSON Web Tokens — the ID card for your API.

A JWT is like a college ID card. The server issues it at login; the client shows it with every request.

Login
↓
Server verifies
↓
JWT Token generated
↓
Client sends: Bearer TOKEN
↓
Server validates

⚠️ Security: Never hardcode secrets. Store JWT keys in configuration or environment variables.

Section 25

Protect API with [Authorize]

Restricting access to specific endpoints.

ProductsController.cs — Protected Delete
[Authorize]
[HttpDelete("{id}")]
public IActionResult Delete(int id)
{
    var product = Products.FirstOrDefault(x => x.Id == id);
    if (product == null)
        return NotFound();
    Products.Remove(product);
    return NoContent();
}
Without Auth

401 Unauthorized

With Valid Auth

204 No Content

Section 26

Complete Request Flow

The biggest picture — end-to-end request journey.

Click any block to see a short explanation.

USER
↓
BROWSER / FRONTEND
↓
HTTP REQUEST
↓
KESTREL
↓
ASP.NET CORE RUNTIME
↓
MIDDLEWARE PIPELINE
↓
AUTHENTICATION
↓
AUTHORIZATION
↓
ROUTING
↓
CONTROLLER
↓
BUSINESS LOGIC
↓
DATA
↓
HTTP RESPONSE
↓
JSON
↓
FRONTEND
↓
USER
Section 27

Complete Project

All the files you need — ready to copy into Visual Studio.

ProductApi/
├── Controllers/
│ └── ProductsController.cs
├── Models/
│ └── Product.cs
├── Program.cs
├── appsettings.json
└── ProductApi.csproj

Models/Product.cs

Models/Product.cs
namespace ProductApi.Models;

public class Product
{
    public int Id { get; set; }
    public string Name { get; set; } = string.Empty;
    public decimal Price { get; set; }
}

Controllers/ProductsController.cs

Controllers/ProductsController.cs
using Microsoft.AspNetCore.Mvc;
using ProductApi.Models;

namespace ProductApi.Controllers;

[ApiController]
[Route("api/[controller]")]
public class ProductsController : ControllerBase
{
    private static readonly List<Product> Products = new()
    {
        new Product { Id = 1, Name = "Laptop", Price = 50000 },
        new Product { Id = 2, Name = "Mouse", Price = 1000 }
    };

    [HttpGet]
    public IActionResult GetAll() => Ok(Products);

    [HttpGet("{id}")]
    public IActionResult GetById(int id)
    {
        var product = Products.FirstOrDefault(x => x.Id == id);
        if (product == null) return NotFound();
        return Ok(product);
    }

    [HttpPost]
    public IActionResult Create(Product product)
    {
        product.Id = Products.Count + 1;
        Products.Add(product);
        return Created("", product);
    }

    [HttpPut("{id}")]
    public IActionResult Update(int id, Product product)
    {
        var existing = Products.FirstOrDefault(x => x.Id == id);
        if (existing == null) return NotFound();
        existing.Name = product.Name;
        existing.Price = product.Price;
        return Ok(existing);
    }

    [HttpDelete("{id}")]
    public IActionResult Delete(int id)
    {
        var product = Products.FirstOrDefault(x => x.Id == id);
        if (product == null) return NotFound();
        Products.Remove(product);
        return NoContent();
    }
}

Program.cs

Program.cs
var builder = WebApplication.CreateBuilder(args);

builder.Services.AddControllers();
builder.Services.AddEndpointsApiExplorer();
builder.Services.AddSwaggerGen();

var app = builder.Build();

if (app.Environment.IsDevelopment())
{
    app.UseSwagger();
    app.UseSwaggerUI();
}

app.UseHttpsRedirection();
app.UseAuthorization();
app.MapControllers();

app.Run();
Section 28

Hands-On Exercises

Practice what you've learned — from Level 1 to Level 8.

Level 1 Create Product Model

Task: Create a Product class with Id, Name, Price.

namespace ProductApi.Models;

public class Product
{
  public int Id { get; set; }
  public string Name { get; set; } = string.Empty;
  public decimal Price { get; set; }
}
Level 2 Create GET Endpoint

Task: Add a GET endpoint returning all products.

[HttpGet]
public IActionResult GetAll() => Ok(Products);
Level 3 Create POST Endpoint

Task: Add a POST endpoint to create a product.

[HttpPost]
public IActionResult Create(Product product)
{
  product.Id = Products.Count + 1;
  Products.Add(product);
  return Created("", product);
}
Level 4 Create PUT Endpoint

Task: Add a PUT endpoint to update a product.

[HttpPut("{id}")]
public IActionResult Update(int id, Product product)
{
  var existing = Products.FirstOrDefault(x => x.Id == id);
  if (existing == null) return NotFound();
  existing.Name = product.Name;
  existing.Price = product.Price;
  return Ok(existing);
}
Level 5 Create DELETE Endpoint

Task: Add a DELETE endpoint to remove a product.

[HttpDelete("{id}")]
public IActionResult Delete(int id)
{
  var product = Products.FirstOrDefault(x => x.Id == id);
  if (product == null) return NotFound();
  Products.Remove(product);
  return NoContent();
}
Level 6 Add Middleware

Task: Create custom middleware to log request timings.

public class RequestTimingMiddleware
{
  private readonly RequestDelegate _next;
  private readonly ILogger<RequestTimingMiddleware> _logger;

  public RequestTimingMiddleware(RequestDelegate next, ILogger<RequestTimingMiddleware> logger)
  { _next = next; _logger = logger; }

  public async Task InvokeAsync(HttpContext context)
  {
    var sw = Stopwatch.StartNew();
    await _next(context);
    sw.Stop();
    _logger.LogInformation($"Request {context.Request.Path} took {sw.ElapsedMilliseconds} ms");
  }
}
Level 7 Add JWT Authentication

Task: Configure JWT authentication in Program.cs.

builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
  .AddJwtBearer(options =>
  {
    options.TokenValidationParameters = new TokenValidationParameters
    {
      ValidateIssuer = true,
      ValidateAudience = true,
      ValidateLifetime = true,
      ValidateIssuerSigningKey = true,
      ValidIssuer = builder.Configuration["Jwt:Issuer"],
      ValidAudience = builder.Configuration["Jwt:Audience"],
      IssuerSigningKey = new SymmetricSecurityKey(
        Encoding.UTF8.GetBytes(builder.Configuration["Jwt:Key"]!))
    };
  });
Level 8 Protect DELETE Endpoint

Task: Add [Authorize] to the DELETE endpoint.

[Authorize]
[HttpDelete("{id}")]
public IActionResult Delete(int id) { ... }
Section 29

Interview Questions

Beginner-friendly questions — click to reveal answers.

Section 30

Final Revision

Quick cheat sheet — everything you learned in Unit V.

ASP.NET CoreFramework for building web applications/APIs
APICommunication bridge between applications
RESTAPI design style using HTTP methods
GETRead data
POSTCreate new data
PUTUpdate existing data
DELETEDelete data
MiddlewareRequest/response pipeline component
KestrelEmbedded web server used by ASP.NET Core
RuntimeEnvironment that executes the application
HostManages configuration, logging, lifetime
AuthenticationWho are you?
AuthorizationWhat can you do?
JWTToken used for authentication
SwaggerAPI documentation and testing UI
[Authorize]Attribute to protect endpoints

Final One-Page Flow

CREATE PROJECT
↓
PROGRAM.CS
↓
MODEL
↓
CONTROLLER
↓
GET / POST / PUT / DELETE
↓
REST
↓
SWAGGER
↓
MIDDLEWARE
↓
RUNTIME + HOST
↓
KESTREL
↓
AUTHENTICATION
↓
JWT
↓
AUTHORIZATION
↓
PROTECTED API
↓
COMPLETE REQUEST / RESPONSE

UNIT V COMPLETE

You now understand:

  • Web API
  • ASP.NET Core
  • REST
  • CRUD
  • HTTP Methods
  • Status Codes
  • Swagger
  • Middleware
  • Runtime
  • Generic Host
  • Kestrel
  • Authentication
  • Authorization
  • JWT
  • Protected APIs
  • Complete Request Lifecycle
📋 Project Setup Steps:
1. Open Visual Studio
2. Create ASP.NET Core Web API project
3. Name it: ProductApi
4. Add Models/Product.cs
5. Add Controllers/ProductsController.cs
6. Update Program.cs
7. Press F5 to Run
8. Open Swagger at /swagger
9. Test GET /api/products
10. Test POST /api/products
11. Test PUT /api/products/1
12. Test DELETE /api/products/1