DevHouse is a RESTful ASP.NET Core Web API designed to manage software development resources such as developers, teams, projects, roles, and project types. It includes secure JWT authentication, clean separation using DTOs, and full CRUD functionality.
- JWT Authentication (all Create/Update/Delete endpoints protected with
[Authorize]) - Developer/Project/Team/Role Management
- Entity Framework Core with MySQL
- Swagger UI for testing endpoints
- DTO-based response optimization
This project is built using the following NuGet packages:
| Package | Version | Description |
|---|---|---|
Microsoft.AspNetCore.Authentication.JwtBearer |
8.0.0 | JWT token-based authentication |
Microsoft.EntityFrameworkCore.Design |
8.0.10 | EF Core design-time tools (used for migrations) |
MySQL.EntityFrameworkCore |
8.0.10 | EF Core provider for MySQL |
Swashbuckle.AspNetCore |
6.4.0 | Swagger/OpenAPI integration for .NET APIs |
System.IdentityModel.Tokens.Jwt |
8.0.0 | Token handling for JWT |
Install these using:
dotnet add package Microsoft.AspNetCore.Authentication.JwtBearer --version 8.0.0
dotnet add package Microsoft.EntityFrameworkCore.Design --version 8.0.10
dotnet add package MySQL.EntityFrameworkCore --version 8.0.10
dotnet add package Swashbuckle.AspNetCore --version 6.4.0
dotnet add package System.IdentityModel.Tokens.Jwt --version 8.0.0- Clone the repository
git clone https://github.com/devrimsavas/DevHouse4.git
cd DevHouse4- Update
appsettings.json(seeappsettingsample.txtfor the template)
"ConnectionStrings": {
"DefaultConnection": "Server=localhost;Database=devhouse;user=root;password=YOUR_PASSWORD"
},
"JWTSettings": {
"SecretKey": "<your-generated-secret>",
"Issuer": "MyIssuer",
"Audience": "MyAudience",
"ExpiryMinutes": 60
}Generate a secret key:
node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"- Create Database Migrations
dotnet ef migrations add InitialCreate
dotnet ef database update- Run the Application
dotnet runNavigate to Swagger UI:
https://localhost:<port>/swagger
/api/Auth/token— Generate JWT token/api/Developer— Manage developers/api/Project— Manage projects/api/ProjectType— Manage project types/api/Team— Manage teams/api/Role— Manage roles
All endpoints are documented in Swagger.
DTOs (Data Transfer Objects) are used to:
- Simplify response structure
- Avoid circular references
- Hide unnecessary fields
- Return related names instead of just IDs (e.g., RoleName, TeamName)
JWT Authentication is used to secure all sensitive endpoints (Create, Update, Delete) via the [Authorize] attribute. Only authorized requests with a valid token are allowed to modify data.
Pass the token in the header:
Authorization: Bearer <your_token>
Note: authorization is currently all-or-nothing (any valid token grants access) — role-based policies (e.g. Admin vs. User) are on the roadmap, see below.
The API is fully documented using Swagger/OpenAPI.
The system is built on MySQL with Entity Framework Core migrations.
Entities:
- Developer
- Team
- Project
- ProjectType
- Role
- Add unit and integration tests with xUnit + Moq
- Add role-based authorization policies (e.g., Admin vs. User) — currently any valid JWT grants full access
- Implement refresh tokens for JWT authentication
- Add logging & monitoring (Serilog + Seq)
- Deploy to Azure App Service or AWS Elastic Beanstalk with CI/CD
The app includes a multi-stage Dockerfile (.NET 8 SDK build → ASP.NET runtime image):
docker build -t devhouse-api .
docker run -d -p 5000:80 devhouse-apiOr with the included docker-compose.yml:
version: '3.8'
services:
api:
build: .
ports:
- "5000:80"
depends_on:
- db
db:
image: mysql:8.0
environment:
MYSQL_ROOT_PASSWORD: rootpassword
MYSQL_DATABASE: devhouseRun with:
docker-compose up --build
