Record who changed what and when, automatically, by overriding SaveChangesAsync and walking the EF Core change tracker - with old/new values as JSON, sensitive fields stripped, and the current user pulled from the request.
Build a real PDF report in .NET with QuestPDF - a code-first document with a header and logo, a striped data table, and page-numbered footers - served straight from a minimal API endpoint.
Put validation in a MediatR pipeline behavior so every command is checked before its handler runs - no validation calls in handlers, no validation logic in endpoints.
API keys are the right fit for server-to-server APIs where full OAuth is overkill. Three ways to enforce one in ASP.NET Core - middleware, an MVC filter, and a minimal API endpoint filter - and when each fits.
Put roles in the JWT, seed them with Identity, and gate endpoints with RequireRole - plus refresh tokens in HttpOnly cookies so the whole flow works from a browser.
A constructor with ten parameters is a call site nobody can read. The fluent builder pattern turns object construction into a chain of named, self-documenting steps.
Add caching, logging, or retry to a service without touching the service - wrap it. The decorator pattern in ASP.NET Core, made painless with Scrutor's Decorate extension.
Two requests read the same bank account balance and both write back - one update silently disappears. Fix it with an EF Core rowversion, a caught DbUpdateConcurrencyException, and a bounded retry.
Take an ASP.NET Core Web API from a Dockerfile to a running Kubernetes deployment - multi-stage image build, pushing to a registry, and a Deployment plus Service manifest with three replicas behind a load balancer.
Build a live shared shopping list with ASP.NET Core SignalR and Angular - hubs, groups, typed client events, and the CORS settings that make a browser WebSocket connection actually work.
Send email from an ASP.NET Core API with SmtpClient and a Gmail app password - behind an interface, configured through the Options pattern, and with a clear-eyed look at when to reach for a provider instead.
Wire ASP.NET Core Identity's built-in API endpoints to an Angular app - login, a bearer token on every request, and an HTTP interceptor that silently refreshes an expired token and retries the failed call.
Stop writing try/catch in every endpoint. One piece of middleware catches every unhandled exception, maps it to the right status code, logs it, and returns a consistent JSON error body.
Fire-and-forget, delayed, continuation, and recurring jobs in .NET with Hangfire - persistent queues backed by SQL Server, a monitoring dashboard, and a producer/consumer split so jobs survive a restart.