Book Image

Mastering ASP.NET Web API

By : Mithun Pattankar
Book Image

Mastering ASP.NET Web API

By: Mithun Pattankar

Overview of this book

Microsoft has unified their main web development platforms. This unification will help develop web applications using various pieces of the ASP.NET platform that can be deployed on both Windows and LINUX. With ASP.NET Core (Web API), it will become easier than ever to build secure HTTP services that can be used from any client. Mastering ASP.NET Web API starts with the building blocks of the ASP.NET Core, then gradually moves on to implementing various HTTP routing strategies in the Web API. We then focus on the key components of building applications that employ the Web API, such as Kestrel, Middleware, Filters, Logging, Security, and Entity Framework.Readers will be introduced to take the TDD approach to write test cases along with the new Visual Studio 2017 live unit testing feature. They will also be introduced to integrate with the database using ORMs. Finally, we explore how the Web API can be consumed in a browser as well as by mobile applications by utilizing Angular 4, Ionic and ReactJS. By the end of this book, you will be able to apply best practices to develop complex Web API, consume them in frontend applications and deploy these applications to a modern hosting infrastructure.
Table of Contents (14 chapters)

CORS

Cross Origin Resource Sharing (CORS) allows cross origin apps to access the application. In case of web API, it's a faceless application that receives a request and returns a response; however, when this web API is consumed in another web application (using AJAX in JavaScript to call APIs), the client would be on a different domain.

Consider an example, the web API is hosted as www.packtdemo.com/api and the web application is hosted as www.packtdemoweb.com. When the web app calls, the API responds with No Access-Control-Allow-Origin header is present on the requested resource. This means your domain is not allowed to access API resources.

This CORS concept can also be used to limit any unwanted web applications to access the web API. The idea behind this is to add the CORS policy in ASP.NET Core Startup processing and apply them either globally or as per controller.

...