ASP.NET Core / Blazor / Web API : how to securely store user data?

Viewed 758

I hope its possible someone can point me in the right direction. This is 100% a education issue.

Problem

I need to create a web application at the moment I would like to use with ASP.NET Core MVC or Blazor Server. But I would like to move this to either a Blazor Web Assembly or Angular application in the future.

I am creating what seems to be a very simple web application. Users can sign up and request a licence key. Users can have multiples of these keys. Once a form is filled in this is then awaiting authorization. This part isn't the problem.

I am finding it hard to work out how to and the best way to get this data stored in a database. The licences will be linked to the user stored in the Identity database. I have followed multiple tutorials and tech papers online on how to use authorisation and authentication but none seem to go into details about storing user data. Obviously only the logged in user can view/create their licences and will have no access to anyone else's.

I understand the process will be different for ASP.NET Core MVC/Blazor server and Angular/Blazor WA as these will require an API.

I hope that someone can point me in the right direction as I have been scanning online for 3 days now and kind of need to be put out of my misery.

Thanks in advance.

1 Answers

Below is one of the way to handle.

  1. Create a table with UserId, license, Active, and any other required fields.
  2. Expose a Web API Controller with the Authorize attribute. Only the users with valid JWT tokens will be able to access this Controller.
  3. UserLicensesController will be talking to the table which stores the Licenses.
  4. Use Blazor Web Assembly, OR Angular, OR React JS. Login with valid credentials.
  5. Invoke the Get/Post/Put methods from UI to UserLicensesController Web API, and pass the JWT token.

Please let me know if you need any further assistance.

[19-May-2021] Here is a basic solution.

  1. I have created a basic solution.
  2. UserMgmtStore.sqlproj contains the Database Project.
  3. UserMgmt.API.csproj contains the Web API with JWT authentication.
  4. I am using Auth0 for the authentication and authorization platform.
  5. UserMgmt.Web.csproj contains the Blazor Web Assembly Project.
  6. I have used the Username and Password to retrieve the JWT token from Auth0.
  7. As each individual project with have their own Identity/STS system. I have hard-coded the token just to complete the Proof Of Concept.
  8. I have checked in the POC into my GitHub Repository.

URL: https://github.com/vishipayyallore/mini-projects-2021/tree/master/Projects/UserLicenses

Solution

UI Look and Feel

Related