.NET portfolio project

RoyalVilla

A versioned Web API with a real MVC client.

An end-to-end ASP.NET Core project covering API design, authentication, PostgreSQL persistence, a Razor client, documentation, containers, and VPS deployment.

Deployed and available
Focus
Backend / API
Runtime
.NET 10
Data
PostgreSQL
Delivery
Docker + VPS
30-second overview

What I built and what it demonstrates.

Designed for reviewers who want the purpose, ownership, and technical depth without digging through the repository first.

Project goal

Build the complete delivery path around an ASP.NET Core Web API.

RoyalVilla manages villas and amenities through REST endpoints. A separate MVC application consumes those endpoints, so the API is exercised by a real client rather than existing only as an OpenAPI demo.

My scope covered the API, shared contracts, data access, authentication flow, MVC integration, container setup, health checks, documentation, and deployment.

Project type
End-to-end portfolio application
Core use case
Villa and amenity management
API style
Versioned REST + OpenAPI
Client
ASP.NET Core MVC + Razor
Deployment
Docker Compose on a VPS
Architecture

Three projects with clear responsibilities.

The MVC client and API share DTO contracts but remain independently deployable applications.

01 Client

RoyalVillaWeb

MVC controllers and Razor views call the API through a named HttpClient. Browser sessions use cookie authentication.

02 Application

RoyalVilla_API

Versioned controllers own CRUD behavior, JWT issuance, mapping, response envelopes, and OpenAPI documents.

03 Contracts + data

DTO library and PostgreSQL

Shared request and response types keep both apps aligned; EF Core handles persistence, relationships, seed data, and migrations.

How a villa request moves through the system

  1. 01Browser → MVC

    A Razor page sends the request to an MVC controller.

  2. 02MVC → API

    The service calls /api/v1/villa and forwards the session JWT as a Bearer token.

  3. 03API → database

    The controller queries PostgreSQL asynchronously through EF Core.

  4. 04Response → UI

    AutoMapper creates a DTO, wrapped in ApiResponse<T>, for the Razor view.

Engineering highlights

The implementation choices that matter.

A concise view of the backend, client integration, data layer, and delivery work represented in the repository.

API DESIGN

RESTful CRUD

Villa and amenity resources use typed inputs, appropriate status codes, async handlers, and a consistent response envelope.

VERSIONING

Side-by-side contracts

URL-based v1 and v2 routing generates separate OpenAPI documents and demonstrates API evolution.

AUTH FLOW

JWT plus cookies

The API issues claims in a JWT; the MVC app signs users into a cookie session and forwards the token to API calls.

DATA

EF Core + PostgreSQL

Entity relationships, seed data, migrations, and asynchronous queries are isolated behind the API boundary.

CONTRACTS

Shared DTO library

Request models, response models, and ApiResponse<T> are shared without exposing persistence entities to the client.

DELIVERY

Containerized deployment

Multi-stage images, Compose networks, persistent volumes, health checks, HTTPS domains, and Dokploy support the live deployment.

Live demo

The client and API are both available to review.

Use the MVC application for the user flow or Scalar to inspect endpoints, schemas, and example requests.

Technology

The stack and its role.

Each tool has a specific place in the request path or delivery workflow.

Platform
.NET 10, ASP.NET Core Web API, MVC, Razor
Data
EF Core, Npgsql, PostgreSQL migrations
API
JWT Bearer, AutoMapper, API Versioning, OpenAPI, Scalar
Delivery
Docker, Compose, health checks, Dokploy, VPS
Intentional scope

Focused on Web API development

RoyalVilla is an educational engineering project, not a commercial booking platform. The following limitations are intentional and documented; a production version would address them before release.

Production hardening

  • Password security: replace plain-text storage with PasswordHasher<TUser> or BCrypt.
  • Role assignment: public registration should always assign the Customer role instead of accepting Admin from the request.
  • API v2: complete the GET behavior or temporarily remove the unfinished version.
  • Automated tests: add unit or integration coverage for authentication and villa CRUD operations.