Login and Sessions
Goal
This snapshot advances Northline Press by teaching you to authenticate with hand-wired cookie auth.
Every numbered folder is a complete app. Run this stage independently, then compare it with the previous folder.
Prerequisites
Use .NET 8 SDK, a terminal, and Docker for Postgres stages. You should recognize C#, HTTP verbs, and basic HTML.
Port 5080 must be free. Copy .env.example and review appsettings.json before database stages.
- .NET 8 SDK
- A code editor and terminal
- Docker from part 4 onward
Concepts
AddAuthentication with cookies stores a signed auth cookie. Keep only the user id in claims and load the user per request—no Identity UI scaffolding.
Keep page models thin: Razor Pages accept input, services and EF Core enforce rules, and Razor escapes output by default.
Walkthrough
Verify email/password, call SignInAsync with claims, and SignOutAsync on logout.
Read the example, then open the matching snapshot. The repository includes the surrounding setup and error handling.
await HttpContext.SignInAsync(CookieAuthenticationDefaults.AuthenticationScheme, principal);
Run and verify
Enter 07-Login-And-Sessions, restore packages, and run on port 5080.
Open http://127.0.0.1:5080. Watch the terminal for validation and database errors.
docker compose up -d
git clone https://github.com/michaeldunga1/fcc-aspnet-blog.git
cd fcc-aspnet-blog/07-Login-And-Sessions
cp .env.example .env
dotnet restore
dotnet run --urls http://127.0.0.1:5080
Troubleshooting
UseAuthentication and UseAuthorization must run before MapRazorPages. Changing cookie settings invalidates existing cookies.
Restore errors usually mean the SDK is missing or you opened the wrong folder. For Postgres failures, confirm Docker is running and the northline_NN database name matches the snapshot.
- Read the first error first
- Restart after environment changes
- Never commit .env or production secrets
Try this
Log in, restart the app, confirm the session persists, then log out.
Test a happy path and one invalid or unauthorized request.
- Make one small change
- Test it in the browser
- Compare with the next snapshot only after it works
Next: Profiles and Media
Comments
One comment per signed-in account. Comments are saved with this page’s URL.