Authentication & Authorization Flashcards
6 cards from real ASP.NET Core practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Authentication & Authorization flashcards as text
Which handler class must be extended to implement a custom authorization requirement handler?
Answer: AuthorizationHandler
Custom handlers inherit from AuthorizationHandler and implement HandleRequirementAsync() to evaluate the requirement.
What does context.Succeed(requirement) do inside an authorization handler?
Answer: Marks the requirement as successfully satisfied
Calling context.Succeed(requirement) signals to the authorization framework that this requirement has passed.
Which OpenID Connect flow is recommended for server-side ASP.NET Core web applications?
Answer: Authorization Code Flow
Authorization Code Flow is the most secure flow for server-side apps, exchanging an authorization code for tokens on the back channel.
What does [Authorize(Policy = "MinimumAge")] require in ASP.NET Core?
Answer: A named policy 'MinimumAge' to be registered with requirements in AddAuthorization()
Policy-based authorization evaluates the named policy's requirements, which must be registered during application startup.
What is the purpose of refresh tokens in JWT authentication?
Answer: To obtain new access tokens without requiring re-authentication when the access token expires
Refresh tokens are long-lived credentials used to get new short-lived access tokens, avoiding frequent login prompts.
Which ASP.NET Core feature allows resource-based authorization where the resource is passed to the handler?
Answer: Resource-based authorization using IAuthorizationService.AuthorizeAsync(user, resource, requirement)
IAuthorizationService.AuthorizeAsync() accepts an optional resource object, allowing handlers to make decisions based on the specific resource.