Activities of "berkansasmaz"

Answer

In order to reproduce your question, I created a project in the following configuration and sent a request to the HttpApi.Host project.

  • Template: app
  • Created ABP Studio Version: 0.9.25
  • Current ABP Studio Version: 0.9.25
  • Tiered: Yes
  • Multi-Tenancy: Yes
  • UI Framework: mvc
  • Theme: leptonx
  • Theme Style: system
  • Run Install Libs: Yes
  • Database Provider: ef
  • Database Management System: postgresql
  • Separate Tenant Schema: No
  • Create Initial Migration: Yes
  • Run Db Migrator: Yes
  • Mobile Framework: none
  • Public Website: No
  • Include Tests: Yes
  • Kubernetes Configuration: Yes
  • Distributed Event Bus: none
  • Use Local References: No
  • Optional Modules:
    • GDPR
    • TextTemplateManagement
    • LanguageManagement
    • AuditLogging
    • OpenIddictAdmin

I updated appsettings.json as follows:

Since you created a tiered application, so did I, and therefore the following CORS setting is already available in HttpApiHost's module:

Result:


Can you control them in your case? Also, can you share the logs of your application (log.txt) located under the Logs folder?

Hi,

If you're implementing a distributed event handler like this:

public class RecurringJobCreatedOrUpdatedEventHandler 
    : IDistributedEventHandler, ITransientDependency

It won’t work because IDistributedEventHandler must be generic. You need to specify the event type it handles, like this:

public class RecurringJobCreatedOrUpdatedEventHandler 
    : IDistributedEventHandler<RecurringJobCreatedOrUpdatedEto>, ITransientDependency

Also, make sure your Web module depends on AbpEventBusRabbitMqModule. Otherwise, the event bus infrastructure won't be properly initialized, and your event handler won’t get triggered even if the event is published successfully. See: https://abp.io/docs/latest/framework/infrastructure/event-bus/distributed/rabbitmq#installation

Hi,

Thanks to the information you provided, I was able to reproduce the problem. The problem does not occur in the Application Layered template, but in the Microservice solution, so I could not reproduce it the first time. I will create an internal issue, and we will keep you informed about the progress. Thank you for your patience.

Hi,

Would you consider to use RabbitMQ or HangFire provider for background jobs? It is possible to process messages in parallel with them. See: https://github.com/abpframework/abp/issues/5217 and https://abp.io/docs/latest/framework/infrastructure/background-jobs/hangfire

Hi

To understand the problem better, could you please try creating a new ABP solution (with the same version and configration), and test if the same issue happens when Redis is enabled?

This will help us see if the problem is in your current project or something more general.

Answer

Hi,

Can you share the logs of your application (log.txt) located under Logs folder to make sure it's a CORS error.

Hi,

Is the content of your NuGet.config file as follows?

Because there seems to be an extra slash in the place where he requests to get the packages.

Also, the packages mentioned are already open-source, that is, they are not hosted on nuget.abp.io but on nuget.org. See:

Hi,

Can you try run the abp install-libs command to restore the NPM packages?

We have tested one scenario, where we will intercept the backend request and they are changing the file content from image to some other file like .aspx or any malware content. Will it still be able to block it.

Right now, the default implementation doesn't really check if the uploaded file is actually an image. So yeah, technically someone could upload something like a .jpg file that’s actually a renamed .aspx or some other non-image content.

That said, in most cases this isn't really a security issue — as long as:

  • The file isn’t executed or rendered by the server
  • It’s not served with an unsafe MIME type
  • And users can only access their own files

But, if you’d like to apply your own security rules or validation logic, you can override the SetProfilePictureAsync method in AccountAppService and handle the checks there.

Hi,

If I understood correctly, you're looking for a way to check the user's permissions (or features), and based on that, control which UI components should be visible or accessible. Is that right?

If so, here's a common and recommended approach:

For menu items:

{
  path: '/authors',
  name: '::Menu:Authors',
  parentName: '::Menu:BookStore',
  layout: eLayoutType.application,
  requiredPolicy: 'BookStore.Authors',
}

For UI components:

  <button *abpPermission="'BookStore.Authors.Create'" id="create" class="btn btn-primary" type="button" (click)="createAuthor()">
            <i class="fa fa-plus me-1"></i>
            <span>{{ '::NewAuthor' | abpLocalization }}</span>
          </button>

If you want to check whether a specific feature is enabled or disabled and render something accordingly, you can check this document.

For AppService methods:

[Authorize(BookStorePermissions.Authors.Delete)] 
public async Task DeleteAsync(Guid id)
{
    //continue to the normal flow...
}

or

public async Task CreateAsync(CreateAuthorDto input)
{
    var result = await AuthorizationService
        .AuthorizeAsync("Author_Management_Create_Books");
    if (result.Succeeded == false)
    {
        //throw exception
        throw new AbpAuthorizationException("...");
    }

    //continue to the normal flow...
}

If I misunderstood your question or you're trying to do something else, feel free to give a bit more detail.

Showing 111 to 120 of 745 entries
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on September 28, 2026, 11:44
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.