- The DELETE endpoint removes the requested record.
- A successful deletion returns HTTP 204 with no response body.
- A subsequent query confirms the record is absent.
12.5 Assignment - Securing API With JWT
In this assignment you will be adding the ability to delete an entity by invoking an HttpDelete request to your web service application from the 12.4 assignment. You will also be securing your application using a JSON Web Token.
Work through the stories in order. Use the acceptance criteria to check each feature, and complete the nested tasks using the specified names, values, and scenarios.
| Operation | Checkpoint response |
|---|---|
| GET | 200 OK with the requested data. |
| POST | 200 OK with the created result, as required here. |
| PUT (12.4 onward) | 200 OK after the update. |
| DELETE (12.5) | 204 No Content after deletion. |
Add the JWTSigningKey and User properties and their values to the appsettings.json file. Ensure the User object contains username and password properties with values.
Configure the appsettings.json file.
Add authentication settings to the JWTSigningKey.
Map the appsettings.json file to the AppSettings class.
Add an HttpPost attribute with a route at the method level.
Authenticate the user.
If user authentication is successful, generate the JWT Token using the JWTSigningKey and User credentitals.
Add the newly created calls to the document of API calls created in the 12.4 assignment. Be sure to indicate the username and password values needed to request a token.
Add the newly created calls to the document of API calls created in the 12.4 assignment. Be sure to indicate the username and password values needed to request a token.
Submit a zipped folder of a copy of your application containing your completed application and the Word document, and with the node_modules folder removed.
Submit a zipped folder of a copy of your application containing your completed application and the Word document, and with the node_modules folder removed.
Return to each story and verify its acceptance criteria. Preserve the submission format and destination stated in the activity; a reading, setup guide, lab, video demonstration, and oral final may require different evidence.
Delete a record Issue and validate JSON Web Tokens Protect and verify the API endpoints Deploy and document the secured service