Maarten Balliauw {blog}
RSS FeedRecent Posts
-
System.Text.Json Polymorphic Deserialization
Updated:Deserialize JSON into derived or abstract types: $type discriminators, [JsonPolymorphic] in .NET 7+, and a custom JsonConverter for legacy payloads.
-
Mastodon on your own domain without hosting a server
Updated:I wanted a Mastodon address on my own domain without running a server. The trick is WebFinger: serve your Mastodon instance’s WebFinger JSON at /.well-known/webfinger on your domain, and @you@yourdomain resolves to your existing account. I use it as a forwarding address that survives switching servers. Updated October 2026: Mastodon and the instances running it have changed since 2022, so the UI may not match what you see in the screenshots or my descriptions. The WebFinger part works the same way.
-
Fix CS8618 Nullable Warnings in C# JSON Models
Updated:Fix CS8618 non-nullable property warnings in C# JSON DTOs: compare nullable properties, constructors, default values and required, and why default! is risky.
-
What is IdentityServer and When Do You Need it?
Updated:IdentityServer is a .NET SDK for building an OpenID Connect and OAuth 2.0 identity provider on ASP.NET Core, issuing tokens to multiple clients and APIs. You need it for several apps or APIs, single sign-on, federation, or standards-based tokens. A single app with local users doesn’t; ASP.NET Core Identity suffices.
-
Run a .NET App as a Linux Service with systemd
Updated:Run a .NET app as a Linux service: add Microsoft.Extensions.Hosting.Systemd, call UseSystemd(), write a Type=notify unit file, and read logs via journald.
-
Rate limiting in ASP.NET Core: a practical guide (updated for .NET 10)
Updated:A practical guide to the ASP.NET Core rate limiting middleware: fixed window, sliding window, token bucket and concurrency limiters, per-IP limits, and returning a 429.
-
Using ASP.NET Core Passkeys for Second Factor Authentication
You can use passkeys as a second factor after password login in ASP.NET Core Identity on .NET 10. Register a two-factor token provider for users who have a passkey, then add two endpoints: one creates passkey request options for the user who passed the password check, and the other verifies the passkey before completing sign-in. Store the user id from the password step in a short-lived cookie, and compare it with the passkey’s user before signing in.
-
Device Bound Session Credentials in ASP.NET Core
A session cookie is a bearer token, which is a polite way of saying that whoever holds it is you. Copy the cookie, replay it from another machine, and the server happily serves your account. Nothing about the request proves which device it came from, so a cookie lifted by malware, an XSS payload, or a stray database backup keeps working until it expires. For a long-lived session, that can be weeks.
-
Building a Supply Chain Attack with .NET and NuGet
Every time npm has a supply chain incident, it’s tempting to think “haha, npm had yet another supply chain attack!” and feel safe in .NET land. But the tools to do the same thing in .NET, or at least similar things, are all there. Module initializers, source generators, MSBuild targets, startup hooks. A number of techniques exist to smuggle code into someone’s codebase, and most of them run before your application’s Main method is even called.
-
Hosting the .NET Aspire Dashboard as a Standalone Container in Azure Web Apps
Sometimes you just want a simple way to look at your traces, metrics, and logs without setting up a full observability stack. Just a UI where you can see what your applications are doing, without having to setup Azure Monitor, Grafana, Prometheus, Jaeger, etc. You don’t always need durability or complex infrastructure.