Unit V — Syllabus Overview
Designing Web API and ASP.NET Core Ecosystem — official course topics mapped to hands-on sessions.
📘 How to read this page: The official syllabus contains 8 major topics. Below, each syllabus topic is visually connected to the sessions in this course that teach it. Click any session pill to jump directly to that session.
Syllabus Topic Flow
This diagram shows how the official Unit V syllabus branches into topics, and each topic is covered by one or more sessions in this course.
Supplementary Sessions
These sessions support the syllabus topics with testing, practice, and complete picture walkthroughs.
Session 17 — Test the API endpoints interactively.
Session 26 — End-to-end request lifecycle.
Session 27 — All files ready to copy.
Session 28 — 8 levels of practice.
Session 29 — 18 beginner-friendly Q&A.
Session 30 — Cheat sheet and final flow.
Syllabus → Session Mapping Table
| # | Syllabus Topic | Covered In Sessions |
|---|---|---|
| 1 | Designing Web API | Sessions 1, 2, 3, 4 |
| 2 | Building a Web API with ASP.NET Core | Sessions 5, 6, 7, 8, 9 |
| 3 | Designing RESTful Interface | Sessions 10, 11, 12, 13, 14, 15, 16 |
| 4 | Securing a Web API | Sessions 22, 23, 24, 25 |
| 5 | ASP.NET Core Runtime Environment | Session 19 |
| 6 | ASP.NET Core Host | Session 20 |
| 7 | Embedded HTTP Server | Session 21 |
| 8 | ASP.NET Core Middleware | Session 18 |
| + | Supplementary (Testing, Practice, Revision) | Sessions 17, 26, 27, 28, 29, 30 |
✅ Coverage: Every topic in the official Unit V syllabus is covered by at least one session in this course, with additional sessions dedicated to hands-on practice, testing, and revision.
Session Dashboard
All 30 sessions in Unit V — click any card to jump to that session.
📊 Total Sessions: 30 | Completed: 0 / 30
What Are We Building?
Introducing the Product Management Web API — the single application we'll build throughout Unit V.
🎯 Our Goal: Build a complete REST API called ProductApi that manages products.
The Application: Product Management API
We are building a Web API that allows any client (web app, mobile app, Postman, Swagger) to manage a list of products.
💡 Memory Trick: CRUD = Create, Read, Update, Delete → POST, GET, PUT, DELETE.
Web Application Basics
Before writing code, let's understand how web applications work.
The Big Picture
Real-Life Analogy: The Restaurant
What is an API?
API stands for Application Programming Interface.
Simple Definition: An API is a set of rules that allows two applications to talk to each other.
How a Web API Works
What is ASP.NET Core?
ASP.NET Core is the framework we'll use to build our Web API.
Simple Definition: ASP.NET Core is a free, open-source, cross-platform framework by Microsoft for building modern web applications and APIs using C#.
Runs on Windows, Linux, and macOS.
One of the fastest web frameworks available.
Create Project in Visual Studio
Step-by-step guide to creating your ProductApi project.
🎯 What you'll do: Create a new ASP.NET Core Web API project named ProductApi.
Alternative: Using the .NET CLI
dotnet new webapi -n ProductApi
cd ProductApi
dotnet run
⚠️ Important: Port numbers in console output are examples only. Your actual ports will differ.
Project Structure
Understanding the files and folders created by Visual Studio.
Program.cs
The entry point of every ASP.NET Core application.
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddControllers();
var app = builder.Build();
app.UseHttpsRedirection();
app.UseAuthorization();
app.MapControllers();
app.Run();
Model
Creating the Product model — the blueprint for our data.
namespace ProductApi.Models;
public class Product
{
public int Id { get; set; }
public string Name { get; set; } = string.Empty;
public decimal Price { get; set; }
}
💡 Analogy: A model is like a form with fields for Id, Name, and Price.
Controller
Creating the ProductsController — the heart of our API.
using Microsoft.AspNetCore.Mvc;
using ProductApi.Models;
namespace ProductApi.Controllers;
[ApiController]
[Route("api/[controller]")]
public class ProductsController : ControllerBase
{
private static readonly List<Product> Products = new()
{
new Product { Id = 1, Name = "Laptop", Price = 50000 },
new Product { Id = 2, Name = "Mouse", Price = 1000 }
};
[HttpGet]
public IActionResult GetAll() => Ok(Products);
[HttpGet("{id}")]
public IActionResult GetById(int id)
{
var product = Products.FirstOrDefault(x => x.Id == id);
if (product == null) return NotFound();
return Ok(product);
}
[HttpPost]
public IActionResult Create(Product product)
{
product.Id = Products.Count + 1;
Products.Add(product);
return Created("", product);
}
[HttpPut("{id}")]
public IActionResult Update(int id, Product product)
{
var existing = Products.FirstOrDefault(x => x.Id == id);
if (existing == null) return NotFound();
existing.Name = product.Name;
existing.Price = product.Price;
return Ok(existing);
}
[HttpDelete("{id}")]
public IActionResult Delete(int id)
{
var product = Products.FirstOrDefault(x => x.Id == id);
if (product == null) return NotFound();
Products.Remove(product);
return NoContent();
}
}
⚠️ Important: The in-memory list is only for learning. In production, use a database with Entity Framework Core.
GET API
Reading data — the most common API operation.
GET means READ. Never modifies data — only reads it.
Simulate a GET request.
POST API
Creating new data — adding products to our collection.
POST means CREATE. Sends data in the request body.
GET by ID
Retrieving a specific product by its unique identifier.
PUT API
Updating existing data — modifying product details.
DELETE API
Removing data — deleting products from the collection.
RESTful API
Understanding the design style behind our API.
REST = Representational State Transfer. A set of rules for designing APIs.
| Method | Endpoint | Action |
|---|---|---|
| GET | /api/products | Read All |
| GET | /api/products/1 | Read One |
| POST | /api/products | Create |
| PUT | /api/products/1 | Update |
| DELETE | /api/products/1 | Delete |
HTTP Status Codes
What the server tells the client with each response.
Swagger Testing
Testing your API without writing any client code.
Swagger/OpenAPI gives us a browser-based interface for testing our API.
ProductApi
v1
⚠️ Note: This Swagger UI is a simulation. Real Swagger runs when you launch ProductApi in Visual Studio and visit /swagger.
Middleware
The request/response pipeline.
var app = builder.Build();
// ORDER IS CRITICAL!
app.UseExceptionHandler("/Error");
app.UseHttpsRedirection();
app.UseRouting();
app.UseAuthentication();
app.UseAuthorization();
app.MapControllers();
app.Run();
ASP.NET Core Runtime
The environment that runs your application.
Generic Host
The manager of your application.
The Host is like a manager of a company. It sets up everything and keeps the app running.
Kestrel
The embedded HTTP server.
Kestrel is like the reception desk of a building. Every request first arrives here, then gets directed to the right place.
Authentication
"Who are you?" — Verifying identity.
Authorization
"What are you allowed to do?"
Question: WHO are you?
Result: 401 if it fails.
Question: WHAT can you do?
Result: 403 if it fails.
JWT
JSON Web Tokens — the ID card for your API.
A JWT is like a college ID card. The server issues it at login; the client shows it with every request.
⚠️ Security: Never hardcode secrets. Store JWT keys in configuration or environment variables.
Protect API with [Authorize]
Restricting access to specific endpoints.
[Authorize]
[HttpDelete("{id}")]
public IActionResult Delete(int id)
{
var product = Products.FirstOrDefault(x => x.Id == id);
if (product == null)
return NotFound();
Products.Remove(product);
return NoContent();
}
401 Unauthorized
204 No Content
Complete Request Flow
The biggest picture — end-to-end request journey.
Click any block to see a short explanation.
Complete Project
All the files you need — ready to copy into Visual Studio.
Models/Product.cs
namespace ProductApi.Models;
public class Product
{
public int Id { get; set; }
public string Name { get; set; } = string.Empty;
public decimal Price { get; set; }
}
Controllers/ProductsController.cs
using Microsoft.AspNetCore.Mvc;
using ProductApi.Models;
namespace ProductApi.Controllers;
[ApiController]
[Route("api/[controller]")]
public class ProductsController : ControllerBase
{
private static readonly List<Product> Products = new()
{
new Product { Id = 1, Name = "Laptop", Price = 50000 },
new Product { Id = 2, Name = "Mouse", Price = 1000 }
};
[HttpGet]
public IActionResult GetAll() => Ok(Products);
[HttpGet("{id}")]
public IActionResult GetById(int id)
{
var product = Products.FirstOrDefault(x => x.Id == id);
if (product == null) return NotFound();
return Ok(product);
}
[HttpPost]
public IActionResult Create(Product product)
{
product.Id = Products.Count + 1;
Products.Add(product);
return Created("", product);
}
[HttpPut("{id}")]
public IActionResult Update(int id, Product product)
{
var existing = Products.FirstOrDefault(x => x.Id == id);
if (existing == null) return NotFound();
existing.Name = product.Name;
existing.Price = product.Price;
return Ok(existing);
}
[HttpDelete("{id}")]
public IActionResult Delete(int id)
{
var product = Products.FirstOrDefault(x => x.Id == id);
if (product == null) return NotFound();
Products.Remove(product);
return NoContent();
}
}
Program.cs
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddControllers();
builder.Services.AddEndpointsApiExplorer();
builder.Services.AddSwaggerGen();
var app = builder.Build();
if (app.Environment.IsDevelopment())
{
app.UseSwagger();
app.UseSwaggerUI();
}
app.UseHttpsRedirection();
app.UseAuthorization();
app.MapControllers();
app.Run();
Hands-On Exercises
Practice what you've learned — from Level 1 to Level 8.
Task: Create a Product class with Id, Name, Price.
public class Product
Task: Add a GET endpoint returning all products.
Task: Add a POST endpoint to create a product.
Task: Add a PUT endpoint to update a product.
Task: Add a DELETE endpoint to remove a product.
Task: Create custom middleware to log request timings.
public RequestTimingMiddleware(RequestDelegate next, ILogger<RequestTimingMiddleware> logger)
public async Task InvokeAsync(HttpContext context)
Task: Configure JWT authentication in Program.cs.
Task: Add [Authorize] to the DELETE endpoint.
Interview Questions
Beginner-friendly questions — click to reveal answers.
Final Revision
Quick cheat sheet — everything you learned in Unit V.
Final One-Page Flow
UNIT V COMPLETE
You now understand:
- Web API
- ASP.NET Core
- REST
- CRUD
- HTTP Methods
- Status Codes
- Swagger
- Middleware
- Runtime
- Generic Host
- Kestrel
- Authentication
- Authorization
- JWT
- Protected APIs
- Complete Request Lifecycle