Movie.API is an ASP.NET Core Web API built using Domain-Driven Design (DDD) principles, focused on managing movie ratings and reviews with proper authentication, authorization, and reporting capabilities. Users can create accounts, authenticate, and perform full CRUD operations on movies. Certain features, such as report generation, are restricted to privileged users via role-based authorization.
- User registration and authentication
- JWT-based authentication with ASP.NET Core Identity
- Role-based authorization (e.g. VIP users)
- CRUD operations for movies
- PDF and Excel report generation (VIP only)
- Swagger UI configured with JWT Authorization
- Clean and layered architecture (DDD-oriented)
POST /api/Loginβ Authenticate and receive a JWT token β
POST /api/Usersβ Create a new user βDELETE /api/Usersβ Delete user βPUT /api/Usersβ Update user data βPATCH /api/Users/Passwordβ Update User Password βPATCH /api/Usersβ Update user as VIP βGET /api/Usersβ Get all logged user data β
GET(ALL Movies) /api/MoviesβGET /api/Movies/{id}βPOST /api/MoviesβPUT /api/Movies/{id}βDELETE /api/Movies/{id}β
-
GET /api/Reports/movies-pdfβ- With query params:
GET /api/Reports/movies-pdf?stars=3
- With query params:
-
GET /api/Reports/movies-excelβ- With query params:
GET /api/Reports/movies-excel?stars=5
- With query params:
This API uses ASP.NET Core Identity combined with JWT Bearer Tokens to provide a secure authentication.
- User logs in via
/api/Login - A JWT token is generated and returned
- The token must be sent in the
Authorizationheader.
Swagger (OpenAPI 3.0) is enabled and fully configured to support JWT authentication.
- Create an user through
/api/users - Call
/api/Loginto obtain a token - Click Authorize in Swagger UI
- Paste the token using the
Bearer YoUrAw3s0m3T0k3nJWTscheme - Access secured endpoints directly from Swagger.
- ASP.NET Core β API development.
- MySQL β Database for persistence.
- Entity Framework Core β Modern ORM for .NET, used for database access, migrations, and data management.
- MySql - DB
- xUnit β Unit and integration testing.
- Shoudly - Tests assertion.
- MOQ - Tests assertion.
- EF Core SQLite In-Memory. - In Memory DB for integration testing
- Bogus β Fake data generation for testing scenarios.
- ClosedXML - Generates a custom Excel.
- QuestPDF - Generates a custom PDF.
- JWT Bearer Authentication
- Swagger
- Domain β Entities, aggregates, and business rules.
- Application β Use cases and application services.
- Infrastructure β Concrete implementations (repositories, persistence, MySQL integration).
- Presentation (API) β Controllers, middlewares, and endpoints.
- Communication β Defines DTOs (Data Transfer Objects) for handling input (requests) and output (responses), ensuring separation between API contracts and domain models.
- Exception Handling β Centralized management of errors, including exception filters, standardized error messages, and resource files for multi-language support.
- Claims and roles are embedded in the JWT
- Endpoints are protected using
[Authorize] - Role-based access is enforced using
[Authorize(Roles = "Vip")]No cookies or sessions are used.
- Centralized error handling with standardized responses.
- Improves API consumer experience by avoiding inconsistent error messages.
- Error and validation messages in multiple languages.
- Based on the
Accept-Languageheader, allowing support for different cultures.
- Unit Tests: validated with xUnit, ensuring business rules work in isolation.
- Bogus: generates fake data to simulate real-world scenarios.
Testing improvements include:
- Unit tests using in-memory providers
- Integration tests with in-memory sqlite database
- Coverage for:
- Application services
- Authentication and authorization flows
- API controllers
Login:
- Login Use Case - User Login. β
Users:
- Add User Use Case β Creates a new user. β
- Delete User Use Case β Delete user β
- Get All User Data Use Case β Returns all logged user data β
- Patch Vip User Use Case β Updates user role to VIP β
- Update User Use Case β Updates user data β
- Update User Password Use Case β Update user Password β
- Add User Validator β Validates user request body params. β
- Password Validator β Validates user password body params. β
Movies:
- Add Movie Use Case β Create a new movie. β
- Delete Movie Use Case - Delete a movie. β
- Get All Movies Retrieve all movies. β
- Get Movie By ID Use Case β Retrieve a movie and validate localized not-found errors. β
- Update Movie Use Case β Update and commit movie data; validate localized errors without committing invalid changes. β
- MoviesValidator - Validates movie request body params. β
Reports:
- Generate Movies PDF Use Case β Verify non-empty or empty results and forwarding of user and star filter to the repository. β
- Generate Movies Excel Use Case β Verify non-empty or empty results and forwarding of user and star filter to the repository. β
Users:
POST /api/Usersβ Creates a new user βDELETE /api/Usersβ Delete the logged user and their movies, preserving other users' data βPUT /api/Usersβ Update the logged user's name; validate localized errors and unchanged data on failure βPATCH /api/Users/passwordβ Update the password, verify hashing and login; validate localized password rules βPATCH /api/Usersβ Upgrade to VIP and verify the new token grants report access βGET /api/Usersβ Retrieve only the logged user's public account data β
Login:
POST /api/Loginβ Authenticate and receive a JWT token βPOST /api/Loginβ Unregistered email returns 400 with EMAIL_OR_PASSWORD_INVALID βPOST /api/Loginβ Incorrect password returns 400 with EMAIL_OR_PASSWORD_INVALID β
Movies:
POST /api/Moviesβ Create a movie with authenticated user βGET /api/Moviesβ Retrieve only the user's movies; return 204 when empty βGET /api/Movies/{id}β Retrieve a movie; validate localized errors for missing or other users' movies βPUT /api/Movies/{id}β Update a movie; validate localized input and ownership errors βDELETE /api/Movies/{id}β Delete a movie; validate localized errors for missing or other users' movies β
Reports (VIP Only):
GET /api/Reports/movies-pdfβ Verify success with non-empty content, empty results and VIP access βGET /api/Reports/movies-excelβ Verify success with non-empty content, empty results and VIP access β
Follow these steps to run the API locally with automatic migrations/seed data:
-
Install prerequisites:
- .NET 8.0 SDK
- MySQL Server 8.0.42 (or compatible)
- Docker (Optional)
-
Installing/Connecting to MySQL Server using Docker (OPTIONAL):
- Download the Oficial MYSQL Docker Image: mysql
- Create a Docker container for MySQL, use the following command to run the container with MySQL 8.0 (Debian) and map the default port:
docker run --name mySqlApp -e MYSQL_ROOT_PASSWORD=YOURPASSWORD -p 3306:3306 -d mysql:8.0-debian
-
Update the
appsettings.Development.jsonfile (insidesrc/RateMovie.Api/appsettings.Development.json) with your local MySQL credentials.
{
"ConnectionStrings": {
"ConnectionMYSQL": "server=localhost;user=root;password=YOURPASSWORD;database=CashFlowDB"
}
}- Execute through the startup project RateMovie.Api
