UESTCO Certificate Verification API: Public Document Validity Lookup Service

A .NET 8 ASP.NET Core Web API that powers public certificate/document verification and internal certificate-registry management for UESTCO. External users can look up an issued certificate by document number and firm name through a public, rate-limited endpoint, while authenticated staff manage the full certificate lifecycle — issuance, validity windows, scope and expiry — through a permission-gated admin surface built on a hand-rolled endpoint-level RBAC layer.

Backend Developer — Document Verification & Identity API

  1. Public Verification Endpoint – Built an anonymous, input-guarded search endpoint (document number + firm name, minimum 3-character match) so external parties can verify certificate validity without authentication.
  2. Custom RBAC Middleware – Implemented endpoint-level permission checks via a custom PermissionMiddleware with an auth-endpoint whitelist bypass, layered on top of ASP.NET Core Identity.
  3. Hardened JWT Auth – Added refresh-token rotation with IP-address binding on tokens to mitigate session hijacking, tracked through a dedicated EF Core migration.
  4. Dual-Context Data Layer – Split business data (certificates, firms) and Identity data into two separate EF Core DbContexts with independent migration histories.
  5. Operational Hardening – Added global exception-handling middleware with a consistent JSON error envelope, Gzip response compression, and a locked-down CORS allow-list.

Features

  1. Public, anonymous certificate/document validity verification by document number + firm name
  2. Full authenticated CRUD lifecycle management for certificates (validity window, scope, expiry)
  3. Hand-rolled endpoint-level RBAC via custom PermissionMiddleware
  4. JWT access + IP-bound refresh token rotation
  5. Soft-delete pattern preserving certificate audit history
  6. Global exception handling with normalized JSON error responses
  7. Swagger/OpenAPI documentation with JWT bearer scheme
  8. Hosted as a native Windows Service on Kestrel

Technologies

  1. .NET 8 Web API
  2. C#
  3. Entity Framework Core 9
  4. PostgreSQL (Npgsql)
  5. ASP.NET Core Identity
  6. JWT + Refresh Tokens (IP-bound)
  7. Swashbuckle / Swagger
  8. Windows Service Hosting
Associated with
  • Company UESTCO Enerji Sistemleri
  • Duration Feb 2025 - May 2025
  • Role Title Backend Developer — Document Verification & Identity API
  • Company Site https://www.uestco.com/