Open Closed

OpenIDDict RedirectUris Not editable via UI #10596


User avatar
0
brauerj@gc.adventist.org created

Am I missing something? How are we supposed to be able to edit mutliple RedirectUris in the OpenIDDictApplications table via the UI? Don't we pay significant money to have these front-end User Interfaces? The database seems to store them as ["https://url1","https://url2"] type format but the OpenIdDict Applications page only shows the first RedirectURI?!!

Jonathan

Markdown supported.
Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)

7 Answer(s)
  • User Avatar
    0
    brauerj@gc.adventist.org created

    This should be fixed!

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    brauerj@gc.adventist.org created

    Am I incorrect to say that it will actually throw away your RedirectURIs except the first one if I actually use this (commercial) UI?

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    AI-Bot created
    Support Team ABP Agent
    • In ABP 10.2.0 (Blazor Server UI), the OpenIddict Application Management UI does not provide a multi-value editor for RedirectUris. That’s why you only see (and can effectively edit) a single Redirect URI in the modal/page, even though the database stores RedirectUris as a JSON array (e.g. ["https://url1","https://url2"]).
    • With the current UI behavior, yes: if you edit/save an application from that UI, it can overwrite the stored JSON array with whatever the UI sends back (typically a single value), which means you can lose all redirect URIs except the first/edited one.

    What you should do to avoid losing RedirectUris (safe options):

    1. Do not use the UI edit form for applications that require multiple redirect URIs.
    2. Manage OpenIddict applications using one of these instead:
      • Database-level update (manually maintain the JSON array in the RedirectUris column), or
      • A custom admin page/component (recommended) that binds to a List<string> and serializes/deserializes properly, or
      • A custom application service endpoint in your solution that updates the redirect URI list without dropping existing values.

    Related (often confused) setting:

    • RedirectAllowedUrls in appsettings.json is a separate deployment concern (ABP side) and not the per-client OpenIddict redirect URI list (OpenIddict side). It won’t solve the “multiple redirect URIs per client” editing problem.

    If you want this to be fixed in the commercial UI, please report it to ABP Commercial support with a minimal reproduction; that’s how it gets tracked and patched.

    • https://abp.io/docs/10.2/modules/openiddict-pro
    • https://abp.io/docs/10.2/solution-templates/layered-web-application/deployment/openiddict-deployment
    • https://abp.io/contact

    This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    brauerj@gc.adventist.org created

    That's not right! AT LEAST just put the json in that field so we can edit it!!!

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    AI-Bot created
    Support Team ABP Agent
    • You’re not missing anything: in ABP 10.2.0, the OpenIddict Applications UI (Blazor Server) doesn’t expose a proper multi-value editor for RedirectUris (which is stored as a JSON array in the DB). So the UI ends up behaving like a single Redirect URI field.

    • And yes: if you open an application in that UI and save it, you can overwrite the JSON array with only what the UI sends (often just one URI). So it can effectively “throw away” the additional redirect URIs.

    Solution

    1. Do not edit/save OpenIddict Applications from the built-in UI if the application has multiple redirect URIs you need to preserve.

    2. Use one of these safe approaches instead:

      • Seed/manage via DbMigrator config (preferred in ABP): put the correct RootUrls / RedirectUris in the OpenIddict.Applications section so they’re consistently generated/updated by the seeder (and you’re not hand-editing UI data).
      • Direct DB edit (short-term): update the RedirectUris JSON array in OpenIddictApplications manually.
      • Build a small custom admin UI that binds to List<string> and serializes/deserializes to the JSON array correctly (recommended if you want it editable from UI).
    3. If your goal is “at least show raw JSON so we can edit it”:

      • That would require customizing/replacing the application management modal/page (the built-in one doesn’t offer that in 10.2.0).
      • Practically: implement your own page/component for OpenIddict application CRUD and include a textarea for the JSON (or a chips/tag editor). This avoids losing data and gives you the UX you want.

    Sources

    • https://abp.io/docs/10.2/solution-templates/layered-web-application/deployment/openiddict-deployment
    • https://abp.io/docs/10.2/modules/openiddict-pro
    • https://abp.io/contact

    This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    brauerj@gc.adventist.org created

    This should be fixed. For how much money a commercial license costs... this should be an EASY fix!

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    Hi

    Sorry about this issue — it's a bug on our side. We've refunded the support credits for this question.

    The RedirectUris field in the edit modal does support multiple URIs (one per line in the textarea). However, there's a line-ending bug when the application runs on Windows: the browser sends \n but the server-side code splits by \r\n, which causes the URIs to get corrupted on save.

    We've already fixed this and it will be included in an upcoming release.

    Quick fix to unblock yourself now:

    Add this single class to your Blazor Server project to override the built-in mappers:

    using System;
    using System.Collections.Generic;
    using System.Linq;
    using Volo.Abp.DependencyInjection;
    using Volo.Abp.OpenIddict.Applications.Dtos;
    using Volo.Abp.OpenIddict.Pro.Blazor;
    using Volo.Abp.OpenIddict.Pro.Blazor.Pages;
    
    [Dependency(ReplaceServices = true)]
    public class FixedApplicationCreateMapper : ApplicationModalViewToCreateApplicationInputMapper
    {
        public override void AfterMap(ApplicationModalView source, CreateApplicationInput destination)
        {
            base.AfterMap(source, destination);
            destination.RedirectUris = SplitByNewLine(source.RedirectUris);
            destination.PostLogoutRedirectUris = SplitByNewLine(source.PostLogoutRedirectUris);
        }
    
        public static HashSet<string> SplitByNewLine(string? value)
        {
            if (string.IsNullOrWhiteSpace(value))
            {
                return new HashSet<string>();
            }
            return value.Trim()
                .Split(new[] { "\r\n", "\n" }, StringSplitOptions.RemoveEmptyEntries)
                .Select(x => x.Trim())
                .Where(x => !string.IsNullOrEmpty(x))
                .Distinct()
                .ToHashSet();
        }
    }
    
    [Dependency(ReplaceServices = true)]
    public class FixedApplicationUpdateMapper : ApplicationModalViewToUpdateApplicationInputMapper
    {
        public override void AfterMap(ApplicationModalView source, UpdateApplicationInput destination)
        {
            base.AfterMap(source, destination);
            destination.RedirectUris = FixedApplicationCreateMapper.SplitByNewLine(source.RedirectUris);
            destination.PostLogoutRedirectUris = FixedApplicationCreateMapper.SplitByNewLine(source.PostLogoutRedirectUris);
        }
    }
    

    Just drop this file in your Blazor Server project — ABP will automatically pick it up and replace the original mappers. The UI will then correctly handle multiple redirect URIs. You can remove this file once you upgrade to the version with the official fix.

    Thanks

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on September 28, 2026, 11:44
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.