Activities of "DominaTang"

The ABP version is 10.1.1 Micro Service Template Angular UI, I don't find code that call end-session end point.

Here is AI analyze to Angular code: Current logout.component.ts: revokeTokenAndLogout() already does the right thing:

  1. Calls /connect/revoke to revoke the access + refresh tokens
  2. Then calls logOut() which redirects to /connect/endsession?id_token_hint=...
  3. OpenIddict removes the IdentitySession record → ABP's IdentitySessionChecker rejects any subsequent request with that token's sid

The one missing piece — postLogoutRedirectUri is registered in OpenIddict seeder for the Angular client, but it's not in app.config.json, so angular-oauth2-oidc never sends it. Without it, after the auth server processes the logout, the user is left stranded on the auth server's logout page instead of being redirected back to Angular:

Our security team find an issue with ABP application, after user logout, the access token before logout is still valid for make API call etc. How to invalid the access token once user logout?

The 404 error is it because angular 21, the index.html is under browser subfolder now. modify the CICD. these two lines must be removed options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signin-oidc"); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signout-callback-oidc");

Let me clarify this way, we have another project which is currently with ABP 9, both projects doesn't follow ABP's multi-tenant document page.

Project A (ABP 8 -> ABP 10 in progress): implemented in this way.

  1. In Auth Server , it has this code: In PreConfigureServices() method: //Configurate Wild Card Domain options for OpenIddict only on non-local environments if (!hostingEnvironment.IsDevelopment() && !string.IsNullOrWhiteSpace(configuration["App:OpenIddictWildcardDomainsFormat"])) { PreConfigure<AbpOpenIddictWildcardDomainOptions>(options => { options.EnableWildcardDomainSupport = true; //options.WildcardDomainsFormat.Add("https://{0}.ess:4200/"); options.WildcardDomainsFormat.Add(configuration["App:OpenIddictWildcardDomainsFormat"]); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signin-oidc"); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signout-callback-oidc"); }); } In ConfigServices method, it call resolver bolow:

private void ConfigureTenantResolver(IWebHostEnvironment hostingEnvironment, IConfiguration configuration) { if (hostingEnvironment.IsDevelopment() || string.IsNullOrWhiteSpace(configuration["App:AuthDomainTenantResolverFormat"])) { Configure<AbpTenantResolveOptions>(options => { options.TenantResolvers.Clear(); options.TenantResolvers.Add(new HeaderTenantResolveContributor()); options.TenantResolvers.Add(new QueryStringTenantResolveContributor()); options.TenantResolvers.Add(new CookieTenantResolveContributor()); options.TenantResolvers.Add(new CurrentUserTenantResolveContributor()); //resolve tenant based on current user's tenant }); } else //Non-Development environments, use sub-domain tenant resolver { Configure<AbpTenantResolveOptions>(options => {

		options.AddDomainTenantResolver(configuration["App:AuthDomainTenantResolverFormat"]);
	});

	Configure&lt;OpenIddictServerOptions&gt;(options =>
	{
		options.TokenValidationParameters.IssuerValidator = TokenWildcardIssuerValidator.IssuerValidator;
		options.TokenValidationParameters.ValidIssuers = new[]
		{
			configuration["AuthServer:Authority"],
			$@"{configuration["App:AuthDomainTenantResolverFormat"] }/"
		};
	});
}

}

  1. In gateway it has this code: private void ConfigureTenantResolver(IWebHostEnvironment hostingEnvironment, IConfiguration configuration) { if (hostingEnvironment.IsDevelopment() || string.IsNullOrWhiteSpace(configuration["App:ApiDomainTenantResolverFormat"])) { Configure<AbpTenantResolveOptions>(options => { options.TenantResolvers.Clear(); options.TenantResolvers.Add(new HeaderTenantResolveContributor()); options.TenantResolvers.Add(new CookieTenantResolveContributor()); options.TenantResolvers.Add(new CurrentUserTenantResolveContributor()); }); } else { Configure<AbpTenantResolveOptions>(options => { options.AddDomainTenantResolver(configuration["App:ApiDomainTenantResolverFormat"]); }); } }

Project B (ABP 9) No matter which environment, it only uses this code in Gateway:

private void ConfigureTenantResolver() { Configure<AbpTenantResolveOptions>(options => { options.TenantResolvers.Clear(); options.TenantResolvers.Add(new HeaderTenantResolveContributor()); options.TenantResolvers.Add(new CookieTenantResolveContributor()); options.TenantResolvers.Add(new CurrentUserTenantResolveContributor()); //resolve tenant based on current user's tenant }); }

Now, it's project A has issue after upgrade to ABP 10: When with these two lines, angular will give a bad gateway exception options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signin-oidc"); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signout-callback-oidc");

When remove these two lines, it gives after login and try to navigate to angular site:

Please note, our Angular App is deployed to azure storage, AI says ABP's muti-tenant document page also need to be deployed to AKS.

ABP 9's OpenIdDict is version 6, ABP 10 is OpenIdDirect is 7. Also our CI/CD team did some AKS ingress upgrade. These are the difference between the two projects.

I am using ABP 10.1.1

Hi, After upgrade from ABP 8 to ABP 10, and deploy to AKS, after angular app login, it shows this error and browser address format is is: https://<tentant1>.<app domain>

The backend's sub domain setting is not like this: //Configurate Wild Card Domain options for OpenIddict only on non-local environments if (!hostingEnvironment.IsDevelopment() && !string.IsNullOrWhiteSpace(configuration["App:OpenIddictWildcardDomainsFormat"])) { PreConfigure<AbpOpenIddictWildcardDomainOptions>(options => { options.EnableWildcardDomainSupport = true; options.WildcardDomainsFormat.Add(configuration["App:OpenIddictWildcardDomainsFormat"]); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signin-oidc"); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signout-callback-oidc"); }); }

This piece of code is not changed, does OpenIdDict new version has changed related to WildChardDomain, the appsettings.json is: "OpenIddictWildcardDomainsFormat": "https://{0}.<app domain's value>/",

thanks, mongo:8.0 works

In the etc/docker folder, the compose file contains: mongo-db: container_name: mongodb image: mongodb/mongodb-enterprise-server:latest volumes: - mongodata:/data/db - mongoconfigdata:/data/configdb

In my local docker, the image file with 'latest' tag is actually 2 years ago, if connect it with NoSQLBooster, I can tell the image version is 7.0.14 Since I want to try MongoDb version 8, so I remove that image from docker, after run ./up.ps1, form docker, it seems the version is 8.2.7 .. however, the mongoDb instance is not started properly

thanks

I think the simple way is, don't use ObjectMapper.Map method, just using the relection copy a set of properties values to target class. Though need specially handling if properties list contains CurrencyObject

Showing 1 to 10 of 246 entries
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on October 08, 2026, 12:23
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.