Mid
From PDF
ASP.NET Core
ASP.NET Core
Securing routes with [Authorize] and [AllowAnonymous]?
Short answer: [Authorize]: Requires authenticated user [Authorize(Roles = "Admin")]: Requires role [AllowAnonymous]: Allows access without login
Example code
[Authorize] public IActionResult Dashboard() { } [AllowAnonymous] public IActionResult Login() { }
Real-world example (ShopNest)
A ShopNest checkout request flows through middleware, hits a minimal API or controller, uses scoped services, and returns ProblemDetails on errors.
Say this in the interview
- Define — one clear sentence (the short answer above).
- Example — relate it to a project like ShopNest or your real work.
- Trade-off — when you would not use it.
Share this Q&A
Share preview image: https://www.toolliyo.com/images/toolliyo-logo.png