I try to login from winfrom using IIdentityModelAuthenticationService it works fine on host but how can I set the tenant? How can get tenat Id from name?
using (var cs = _provider.CreateScope())
_tenant.Change(myTenantGuid, txtTenant.Text);
AsyncHelper.RunSync(() =>
_tokenManager.ObtainAccessToken(txtUser.Text, txtPassword.Text, txtUrl.Text));
var q = AsyncHelper.RunSync(() => _appService.GetAsync());
from my side it not works but I found this post and I remove
responseType: 'code',
After that my login on angular side work I dont redirect me to IDS login page.
The issue still exists on API if I try to login from swagger the app redirect me to base auth and not to tenant auth
I've configure my app in multi tenant (with tenant resolver) and replace login component with local Angular UI the problem is that when I click login I'll be redirect to IDS (mvc page in place to my local Angular UI).
My App.Component.Ts is set to:
ngOnInit() {
key: eAccountComponents.Login,
component: LoginComponent,
key: eAccountComponents.Register,
component: RegisterComponent,
key: eThemeLeptonComponents.AccountLayout,
component: AccountLayoutComponent,
It works fine if I don't use tenantResolver but when I switch to tenant roselver (using {0} for placeholder) local login not work
I see the same and it works but redirect me to IDS page e not to my local login in angular why?
I re check all configuration on my module and work (partially on Angular).
I need to add to environment.ts
skipIssuerCheck: true
After Add this my app will be redirect to correct Auth Server (es Tenant 1 (t1) -> https://t1.auth.mydomain.com) but I use the custom login into angular with customize Login/register page
This work fine if I don't use a normal tenant selector but in tenant rosolve by name when I click login I'll be redirect to Auth (Mvc page and not to angular route). I doesn't work on tenant/host side
I look into the call /.well-known/openid-configuration and I see that and i console I read an error that
main.fbfd4e772f61baa1.js:1 invalid issuer in discovery document expected: https://t1.mydomain.com current: https://auth.mydomain.com
"issuer": "https://auth.mydomain.com",
"jwks_uri": "https://t1.auth.mydomain.com/.well-known/openid-configuration/jwks",
"authorization_endpoint": "https://t1.auth.mydomain.com/connect/authorize",
"token_endpoint": "https://t1.auth.mydomain.com/connect/token",
"userinfo_endpoint": "https://t1.auth.mydomain.com/connect/userinfo",
"end_session_endpoint": "https://t1.auth.mydomain.com/connect/endsession",
"check_session_iframe": "https://t1.auth.mydomain.com/connect/checksession",
"revocation_endpoint": "https://t1.auth.mydomain.com/connect/revocation",
"introspection_endpoint": "https://t1.auth.mydomain.com/connect/introspect",
"device_authorization_endpoint": "https://t1.auth.mydomain.com/connect/deviceauthorization",
"frontchannel_logout_supported": true,
"frontchannel_logout_session_supported": true,
"backchannel_logout_supported": true,
"backchannel_logout_session_supported": true,
I think the problem is related to auth. This is the information the API try to use to authorize.
oauth2 (OAuth2, authorizationCode) Authorization URL: https://auth.mydomain.com/connect/authorize Token URL: https://auth.mydomain.com/connect/token Flow: authorizationCode
Is it correct?
About the git repo, your request is to clone the repo and reproduce the issue?
I can't because not existing this configuration.
The NG has identity server is not separated
I try to use this scenario in multi tenant env: Angular IDS API
We follow the guide https://support.abp.io/QA/Questions/1552/Better-Documentation-for-Multi-Tenant-Subdomain-Resolver but not work.
We are able to login in IDS tenant (es t1.auth.mydomain.com) and open Api in tenant (t1.api.mydomain.com) but when I try to authorize my api client the auth login url is auth.mydomain.com and not t1.auth.mydomain.com so the authentication move to host and not to correct tenant.
on appsettings.json
"SelfUrl": "https://{0}.auth.mydomain.com",
"TenantResolver": "https://{0}.auth.maydomain.com"
"SelfUrl": "https://api.mydomain.com",
"TenantResolver": "https://{0}.api.maydomain.com"
"AuthServer": {
"Authority": "https://auth.maydomain.com",
"RequireHttpsMetadata": "true",
"SwaggerClientId": "client_Swagger",
"SwaggerClientSecret": "1234567"
on IDS ConfigService we put on top of module
Configure<AbpTenantResolveOptions>(options =>
Configure<IdentityServerOptions>(options =>
options.IssuerUri = configuration["App:SelfUrl"];
and on HttpApiHost
Configure<AbpTenantResolveOptions>(options =>
Any update?
Hi I try but miss a lot of function like saas. It s not complete solution for test module in saas