Hi Team,
We are currently using the CMS Kit PRO module in a multi-tenant setup and facing an issue in the production environment.
Issue Summary
In the local environment, everything works as expected:
- Creating pages, blogs, and menus
- Setting a page as the home page for a tenant via the admin dashboard
- All content is visible correctly on the public website
However, in the production environment:
- Menus are not visible unless the user is logged in
- The home page configured from the admin dashboard is not visible publicly
- Content seems restricted to authenticated users only
Expected Behavior
- Menus and home page content should be visible to anonymous users (public access), same as local setup
Questions
- Is there any configuration we might be missing for production?
- Are there any permissions, caching, or environment-specific settings required for public visibility?
- Anything specific to multi-tenancy or CMS Kit PRO that behaves differently in production?
Additional Info
- Local environment: Working correctly
- Production environment: Issue persists consistently
Would appreciate your guidance on what could be causing this.
19 Answer(s)
-
0
This behavior (content visible only after login) is almost always caused by production-only authentication/authorization requirements being applied to the Public Website, not by CMS Kit Pro itself. CMS Kit menus/pages are designed to be publicly renderable; if they disappear for anonymous users, something in the pipeline is treating anonymous requests as unauthorized (and the UI ends up showing nothing / redirects).
Apply the following production checks/fixes (these are safe and common causes in multi-tenant + public website deployments):
- Ensure your Public Website endpoints allow anonymous
- Verify you did not add a global authorization requirement in production (common in
ConfigureServices/OnApplicationInitialization) such as:options.FallbackPolicy = options.DefaultPolicy;RequireAuthenticatedUser()applied globally- A reverse proxy rule that forces auth for all paths
- If you did, you must explicitly allow anonymous for the CMS/public routes (home page, dynamic pages, menu endpoints, etc.) or remove the fallback/global requirement for the Public Website app.
- Verify tenant resolution works for anonymous users in production
- In multi-tenancy, the public site must resolve the current tenant for anonymous requests (typically via domain/subdomain).
- In production, if the tenant cannot be resolved for anonymous users, the app may fall back to host context (or hit an authorization/caching branch), causing “missing home page / missing menu”.
- Make sure the production domain/subdomain mapping is correct and consistent with what you use locally.
- Clear/distribute caches in production (especially if you use Redis / distributed cache)
- If production uses a distributed cache and local does not, cached “not found / unauthorized / empty menu” results can persist across requests and instances.
- Clear the distributed cache after setting the home page / changing menus, and ensure all instances share the same cache configuration.
- Verify CMS Kit features are enabled in the production build
- Ensure CMS Kit and CMS Kit Pro global features are enabled in
GlobalFeatureConfigurator(and the same code is deployed to production). Otherwise some UI pieces can disappear depending on feature flags.
- Verify the Public Website is using the correct environment settings for AuthServer / OpenIddict
- A misconfigured AuthServer in production can result in the app thinking it must challenge even for anonymous pages, which then makes public content appear “restricted”.
- Double-check production
appsettings.Production.jsonvalues for auth-related endpoints and the public web’s self URL.
Links (verified)
- https://abp.io/docs/latest/modules/cms-kit/menus
- https://docs.abp.io/en/abp/latest/Modules/Cms-Kit/Index
- https://docs.abp.io/en/commercial/latest/modules/cms-kit/index
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
Hi,
To help diagnose the issue, could you please provide some more details?
When you say "local environment works", did you verify the menus and home page are visible while not logged in (anonymous/incognito browser)? Or was the testing done while still authenticated?
How does your production public website resolve the tenant for anonymous visitors? (e.g., subdomain like
tenant.yourdomain.com, a separate domain, query string?__tenant=, or something else?)Could you open the browser developer tools (Network tab) on your production public website while not logged in, and check what response is returned for
/api/cms-kit-public/menu-items? Please share the HTTP status code and response body.If possible, could you share the URL of your production public website so we can check directly?
Thanks
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
-
0
We can't, considering policies, but we will be available for remote troubleshooting based on your calender
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
Hi,
Thanks for testing that. Since the local Production mode works fine, the issue is definitely something specific to your deployed environment.
We confirmed the
/api/cms-kit-public/menu-itemsendpoint returns a 302 redirect to the OIDC login page, so something is forcing authentication on all requests. Could you share a few code snippets to help us find the cause?The
Program.csorStartup.csof your public website project — mainly the auth-related parts.The main module class of the public website (e.g.,
YourPublicWebModule.cs) — theConfigureServicesandOnApplicationInitializationmethods.Could you also do a quick search in your public website project for
FallbackPolicy,RequireAuthenticatedUser,DefaultPolicy, andAddAuthorization? Just paste any matches you find.The
appsettings.Production.jsonfrom the deployed server (just redact any secrets/connection strings).
No need to share the full project — just these parts should be enough for us to spot the problem.
Thanks
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
https://docs.google.com/document/d/1fS_wG1uZhVi99sYsYiRerRwmMpKW7qL0tsE6-qyulHY/edit?tab=t.0 - update in the same docs. Once check and if anything else you required, do let me know.
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
Hi,
A few more things that would help us pinpoint the exact cause:
Local anonymous test — Could you open an incognito/private browser window (completely logged out) and try accessing your local public website? Check if the menus and home page are visible. This is important because the issue might actually also exist locally but was never tested anonymously.
Production logs — Please enable Debug-level logging by following this guide: https://abp.io/support/questions/8622/How-to-enable-Debug-logs-for-troubleshoot-problems
Then reproduce the issue and share the logs.txt. We're looking for
Warningentries around the time the anonymous request hits/api/cms-kit-public/menu-items— the log message will contain the exact feature name that failed, which will tell us the root cause directly.More code — Could you also share the full
TriArchPublicModuleclass, including the[DependsOn]attributes and the completePreConfigureServicesmethod? Also, a quick search in your public website project for any usage ofGlobalFeatureManagerwould be helpful.
Thanks
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
- I tested this - it works fine in local when i open in incognito browser.
- will try this too.
- have updated it in the https://docs.google.com/document/d/1fS_wG1uZhVi99sYsYiRerRwmMpKW7qL0tsE6-qyulHY/edit?tab=t.0
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
hi
We've gone through your module code carefully and everything looks correct — the CMS Kit public APIs don't have any authorization restrictions, the GlobalFeature configuration follows the standard template pattern, and the middleware setup looks fine. We can't spot any code-level issue that would cause the 302 redirect.
To move forward, we need a bit more information:
Debug logs — Please enable Debug-level logging following this guide: https://abp.io/support/questions/8622/How-to-enable-Debug-logs-for-troubleshoot-problems, reproduce the issue, and share the logs. The logs should tell us exactly what exception is being thrown and why the redirect is triggered.
Try publishing locally — Could you publish the public website to your local machine (or a staging environment) with the same production configuration? This would help us confirm whether the issue is specific to your production server/environment rather than the application code itself.
Minimal reproduction — If possible, could you create a fresh ABP project with the same setup and see if the issue reproduces? This would help us isolate whether it's something unique to your codebase or a more general configuration problem.
Thanks
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
Upon digging deeper into the code, we figured out the issue was due to middleware introduction for custom / forced routing. We have reverted it and are able to make it work. Apologies for the confusion.
Please close the ticket.
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
