A production-oriented ASP.NET Core application template for .NET 10. Routed endpoints require an authenticated user by default, anonymous access is explicit and regression-tested, and the generated scaffold ships with structured logging, security headers, forwarded-header validation, rate limiting, centralized Problem Details error handling, EF Core data access and auditing patterns, health checks, telemetry, and CI validation.
Install it:
dotnet new install NetCoreApplicationTemplate
dotnet new netcoreapp-template -n ContosoSecurityPortalTagged releases publish a durable, hashed evidence bundle for the exact NuGet package and OCI image — separate SPDX SBOMs, provenance, the signed image digest, and tested verification commands. See Container Release Publishing. NuGet author signing is tracked separately by ADR-0005.
Current release: Release 2.9.0
Tag: v2.9.0
The 2.x line is feature-complete. NCAT is actively maintained for security
fixes, dependency servicing, and documentation corrections. New template
options, configuration surfaces, and runtime capabilities are out of scope for
this line.
Generated projects are not modified by later releases. Applications scaffolded
from any 2.x version continue to build and run independently of the template's
release cadence.
See SUPPORT.md for the complete support policy and version lifecycle.
The default scaffold enables cookie authentication as the session handler. It does not include local user accounts, a credential form, a seeded user, or an enabled external provider. Cookie authentication stores an identity after a sign-in flow succeeds; it does not verify credentials or provide a login path by itself.
Authorization determines whether that identity may access an endpoint or operation. NCAT configures a fallback authorization policy requiring an authenticated user for routed endpoints without authorization metadata. Intentionally public routes use explicit anonymous metadata such as [AllowAnonymous] or .AllowAnonymous().
With the default provider configuration, /Account/Login therefore explains that no sign-in provider is configured, and protected routes remain unavailable to anonymous users. Before testing protected application routes, enable and configure an external provider or add a host-owned identity flow. Use --authProvider none only when an intentionally unauthenticated scaffold is appropriate.
The template also includes named policies for authenticated-user, administrator-role, and manage-application-permission requirements. These policy-based authorization controls layer stronger requirements beyond the authenticated-user baseline.
The phrase secure baseline in this project refers to concrete controls—closed-by-default routed endpoints, explicit anonymous exceptions, startup validation, request protection, secure headers, rate limiting, and centralized error handling. Deployment-specific trust boundaries, provider registrations, credentials, network exposure, and business authorization remain the consuming application's responsibility.
--authProvider none is an explicit architectural opt-out. It disables application authentication, cookie authentication, and the authenticated fallback policy in generated configuration. Unannotated routed endpoints are public in that variant until the consuming application adds another authentication mechanism and authorization posture.
git clone https://github.com/AsiBackbone/NetCoreApplicationTemplate.git
cd NetCoreApplicationTemplate
dotnet restore
dotnet build --configuration Release
dotnet test --configuration Release
dotnet run --project src/ProjectTemplate.WebRun with Docker Compose:
docker compose up --buildThe Docker-hosted application is available at http://localhost:8080.
Health endpoints:
http://localhost:8080/health
http://localhost:8080/health/ready
http://localhost:8080/health/live
Health routes are explicitly anonymous at the application layer for infrastructure probes. Production deployments should restrict their reachability through ingress, firewall, reverse-proxy, load-balancer, or service-mesh policy.
Install the published package:
dotnet new install NetCoreApplicationTemplate::2.9.0For local package validation, install the packed package directly:
dotnet new install ./artifacts/template-package/NetCoreApplicationTemplate.2.9.0.nupkgGenerate the default cookie-authenticated scaffold:
dotnet new netcoreapp-template -n ContosoSecurityPortalGenerate the explicit authentication-disabled variant:
dotnet new netcoreapp-template `
--name ContosoNoAuthSqlServer `
--authProvider none `
--dbProvider sqlserverTemplate options:
| Option | Default | Supported values | Behavior |
|---|---|---|---|
--authProvider |
cookie |
cookie, none |
Selects either the cookie session handler with authenticated fallback access, or the explicit authentication-disabled opt-out. The cookie option still requires a configured sign-in provider or host-owned identity flow. |
--dbProvider |
sqlite |
sqlite, sqlserver, none |
Selects the generated EF Core data access mode. |
--skipRestore |
false |
true, false |
Skips the post-create restore action. |
SQL Server scaffolds omit the SQLite-specific migration history. Generate a fresh SQL Server migration before applying database updates; see Data Access.
Build and test generated output:
cd ContosoSecurityPortal
dotnet restore
dotnet build --configuration Release
dotnet test --configuration Release- Production-oriented ASP.NET Core startup and middleware organization.
- Cookie authentication and authenticated-by-default routed endpoints in the default scaffold.
- Explicit anonymous endpoint exceptions with regression coverage.
- Named role and permission authorization policies.
- Structured application and request logging.
- Centralized exception, status-code, and Problem Details handling.
- Reverse-proxy, security-header, rate-limiting, health-check, and telemetry foundations.
- EF Core provider and auditing patterns.
- Automated build, test, coverage, template smoke-test, CodeQL, and documentation workflows.
- Package-based
dotnet newscaffold support.
- Authentication establishes identity.
- Authorization determines permitted access.
- The default authorization policy applies when authorization is requested without a named policy.
- The fallback authorization policy applies to routed endpoints with no authorization metadata.
- Explicit anonymous access intentionally exempts a route from authorization.
- Policy-based authorization applies role, permission, claim, or custom requirements.
DefaultPolicy and FallbackPolicy are distinct ASP.NET Core concepts and are not used interchangeably in NCAT documentation.
- Published documentation
- Getting Started
- Authentication
- Production Authentication Hardening
- Authorization
- Runtime Readiness
- Production Deployment Checklist
- Health Checks
- Template Packaging
- Data Access
Build documentation locally:
dotnet tool restore
dotnet tool run docfx -- docs/docfx.jsonThe repository contains source projects, tests, Docker support, DocFX documentation, CI workflows, release and governance files, template configuration, and package metadata.
Generated projects include application source, tests, Docker support, configuration examples, license and asset notices, and a consumer-oriented README. Repository-maintainer workflows, ADRs, community and governance policies, contribution policy, security policy, and release-management files are excluded from generated output.
NCAT is self-contained. It has no dependency on any other AsiBackbone project and requires no external governance, audit, or policy product.
-
ASI Backbone Learning — the organization's educational site for ASP.NET Core architecture, terminology, labs, and secure-by-default guidance. NCAT links to Learning for broader teaching rather than duplicating it. Learning does not define NCAT runtime behavior; this repository and its published documentation remain authoritative for NCAT's options, defaults, and contracts. See the documentation ownership contract.
-
AsiBackbone — an optional .NET library for application-level policy decisions, acknowledgments, scoped capability grants, and decision audit records around protected operations. It complements but does not replace ASP.NET Core authentication or endpoint authorization, and NCAT does not require it.
- Use GitHub Discussions for setup and usage questions, design or extension guidance, and community feedback.
- Use GitHub Issues for reproducible bugs, documentation gaps, and focused feature requests.
- Report suspected vulnerabilities through the private process in SECURITY.md.
- Participate under the repository Code of Conduct and Community Standards.
- See Governance and Maintainers for decision authority and operational ownership.
See SUPPORT.md for the complete support policy and version lifecycle.
This project follows Semantic Versioning. Version metadata is managed centrally for assemblies, packages, and releases.
Suggested citation:
Cavell, Christopher D. NetCoreApplicationTemplate. Version 2.9.0. Zenodo. MIT License. https://doi.org/10.5281/zenodo.20373042
This project is licensed under the MIT License. See LICENSE.txt and ASSETS-LICENSES.md.
