UESTCO Certificate Verification API: Public Document Validity Lookup Service
A .NET 8 ASP.NET Core Web API that powers public certificate/document verification and internal certificate-registry management for UESTCO. External users can look up an issued certificate by document number and firm name through a public, rate-limited endpoint, while authenticated staff manage the full certificate lifecycle — issuance, validity windows, scope and expiry — through a permission-gated admin surface built on a hand-rolled endpoint-level RBAC layer.
Backend Developer — Document Verification & Identity API
- Public Verification Endpoint – Built an anonymous, input-guarded search endpoint (document number + firm name, minimum 3-character match) so external parties can verify certificate validity without authentication.
- Custom RBAC Middleware – Implemented endpoint-level permission checks via a custom PermissionMiddleware with an auth-endpoint whitelist bypass, layered on top of ASP.NET Core Identity.
- Hardened JWT Auth – Added refresh-token rotation with IP-address binding on tokens to mitigate session hijacking, tracked through a dedicated EF Core migration.
- Dual-Context Data Layer – Split business data (certificates, firms) and Identity data into two separate EF Core DbContexts with independent migration histories.
- Operational Hardening – Added global exception-handling middleware with a consistent JSON error envelope, Gzip response compression, and a locked-down CORS allow-list.
Features
- Public, anonymous certificate/document validity verification by document number + firm name
- Full authenticated CRUD lifecycle management for certificates (validity window, scope, expiry)
- Hand-rolled endpoint-level RBAC via custom PermissionMiddleware
- JWT access + IP-bound refresh token rotation
- Soft-delete pattern preserving certificate audit history
- Global exception handling with normalized JSON error responses
- Swagger/OpenAPI documentation with JWT bearer scheme
- Hosted as a native Windows Service on Kestrel
Technologies
- .NET 8 Web API
- C#
- Entity Framework Core 9
- PostgreSQL (Npgsql)
- ASP.NET Core Identity
- JWT + Refresh Tokens (IP-bound)
- Swashbuckle / Swagger
- Windows Service Hosting