The "Could not find localization source" errors (AMS, AbpUi, AbpIdentity) indicate that the required localization resources are missing or not properly registered after your upgrade. This is a common issue when upgrading major ABP versions, especially from v4.x to v9.x, due to changes in the localization system and resource file structure.
ConfigureServices method using the new ABP v9 syntax.The Uncaught TypeError: id.replace is not a function error is likely caused by a JavaScript code expecting a string id, but receiving an object or another type. This can happen if the structure of data returned from the backend has changed after the upgrade, or if a localization key is missing and returns an object instead of a string.
id variable is always a string before calling .replace.The UI issues (e.g., "PagerShowMenuEntries" and "ProcessingWithThreeDot" showing as raw keys) are also related to missing or unregistered localization resources.
Recommended Steps:
Source:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
If the problem persists, you can contact ABP support directly at info@abp.io with the details of the email address and registration attempt.
Sources:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
This error, "Validating access_token failed, wrong state/nonce," typically occurs in ABP Angular applications when multiple tabs are open and the session expires or the access_token is deleted. The root cause is that the OAuth2/OIDC state and nonce values are stored in browser storage (localStorage/sessionStorage), and having multiple tabs can cause these values to become out of sync, especially after a session timeout or manual token removal. Chrome and Edge are more aggressive in synchronizing storage across tabs, which is why the issue is more visible there compared to Firefox.
Single Tab Recommendation:
This is a known limitation of SPA OAuth2/OIDC flows. Advise users to avoid logging in again in multiple tabs simultaneously after session expiration.
Custom State/Nonce Storage:
Consider customizing the storage mechanism for state/nonce to be tab-specific (e.g., using sessionStorage instead of localStorage, or using a unique key per tab).
Session Management Module:
ABP Commercial provides a Session Management feature to help prevent concurrent login/session issues. See the documentation for more details.
Logout Handling:
Ensure that your logout implementation clears all relevant tokens and state in all tabs, possibly by broadcasting a logout event using localStorage or another mechanism.
Reference Issues:
This is a common scenario in OAuth2/OIDC SPAs and is discussed in the community and GitHub issues. See the following for more details and possible workarounds:
Sources:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
ABP Framework does not provide a built-in LastLogin field in the default Users table (AbpUsers). However, ABP does offer a way to track user login events through the Security Log feature, which records login and logout activities.
Use Security Logs to Track Logins
AbpSecurityLogs (or similar, depending on your version).Custom LastLogin Property (Recommended for Direct Access)
Example:
// 1. Add property to user entity (see ABP docs for entity extension)
ObjectExtensionManager.Instance
.MapEfCoreProperty<IdentityUser, DateTime?>("LastLoginTime");
// 2. Update LastLoginTime after successful login
user.SetProperty("LastLoginTime", DateTime.UtcNow);
SignalR/Active User Tracking (Optional)
Sources:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
This error typically occurs when your Angular build process tries to load a .js.map file as a JavaScript module, which is not correct. This is usually caused by an incorrect import or a misconfiguration in your project.
Check for Incorrect Imports
.js.map files anywhere in your codebase. You should only import JavaScript or TypeScript files, not source maps.Clean and Reinstall Node Modules
node_modules folder and yarn.lock file:
rm -rf node_modules yarn.lock
yarn install
Check Angular and ABP Versions
@angular/* and @abp/* package versions are compatible and consistent. For ABP v9.1.0, you should use Angular 17.x and matching ABP Angular packages.Check tsconfig and angular.json
tsconfig.json and angular.json do not include or reference .js.map files in the files, include, or assets sections.Check for Custom Webpack Configurations
.js.map files as entry points or modules.Restart the Angular Development Server
yarn start
If you follow these steps, the error should be resolved. This issue is not specific to ABP, but rather to the Angular/Webpack build process.
Sources:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
In ABP v9.2.0, the SaaS module validates the tenant connection string before saving it. If you are storing the connection string encrypted, the framework will attempt to validate the encrypted value, which will fail because it is not a valid SQL Server connection string in plain text.
The correct approach is to ensure that the connection string is decrypted before validation. Overriding CheckConnectionStringAsync is the right idea, but you must also ensure that the decrypted connection string is passed to the base method and to the framework's validation logic.
In your CreateAsync override, you are encrypting the connection string before assigning it to input.ConnectionStrings.Default. However, the SaaS module expects the connection string in plain text for validation, and only after validation should it be encrypted for storage.
Solution:
input.ConnectionStrings.Default before calling base.CreateAsync(input).Example:
public override async Task<SaasTenantDto> CreateAsync(SaasTenantCreateDto input)
{
var servers = await _availableSqlServerAppService.GetListAsync(new GetAvailableSqlServersInput {AvailableForTenantDatabase = true});
var first = servers.Items.OrderBy(i => i.NrOfTenants).First();
var defaultConnectionString = new SqlConnectionStringBuilder(DbConnectionOptions.ConnectionStrings.Default);
var baseDBName = string.Join('.', defaultConnectionString.InitialCatalog.Split(".").SkipLast(1));
var connectionString = new SqlConnectionStringBuilder
{
InitialCatalog = $"{baseDBName}.Tenant.{input.Name}",
DataSource = first.SqlServerName,
UserID = first.LoginUser,
Password = _stringEncryptionService.Decrypt(first.EncryptedPassword),
TrustServerCertificate = true
};
await CreateAzureDatabaseIfNotExists(connectionString);
// Assign the plain connection string for validation
input.ConnectionStrings.Default = connectionString.ConnectionString;
var result = await base.CreateAsync(input);
// Optionally, encrypt the connection string after creation for storage
// (Requires customizing the storage logic, not just the input)
return result;
}
References:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
For ABP Commercial applications, the license key is required in production. You must provide the ABP license key either in your appsettings.secrets.json or as an environment variable for your deployed application to function. This is confirmed in the referenced support post:
The ABP Commercial license is time-based. If your license expires, deployed applications that require license validation (including those in production) will stop functioning. The license check is enforced at runtime, regardless of whether the key is stored in appsettings.secrets.json or provided via environment variables.
According to the official FAQ:
For critical deployments, ensure your license is always valid to avoid service interruptions.
Sources:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
This issue is likely related to missing or misconfigured localization resources for the zh-hans language, which can cause permission checks or menu rendering to fail in ABP's navigation system. When a required localization key or permission display name is missing for a specific language, ABP may not render the related menu items, or permission checks may not work as expected.
To resolve this:
zh-Hans.json) exist for every module and contain all necessary keys, especially for permissions and menu items.culture property inside the JSON files.If the problem persists, check for any custom permission providers or menu contributors that may have language-specific logic or missing translations.
For more details, see:
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
To achieve subdomain-based tenant resolution in a tiered ABP Blazor Server environment with a static AuthServer domain (no wildcard), you need to ensure that the tenant context is consistently and securely passed from the Blazor app (which uses subdomains) to the AuthServer (which does not use subdomains). Your approach is mostly correct, but there are some ABP-recommended practices and built-in features that can simplify and standardize this process.
Configure<AbpTenantResolveOptions>(options =>
{
options.AddDomainTenantResolver("{0}.uat.domain.io");
});
Since your AuthServer is at a static domain (auth.uat.domain.io), you cannot resolve the tenant from the subdomain. The recommended approach is to pass the tenant name as a query string parameter (e.g., ?tenant=tenant1) when redirecting to the AuthServer.
In your Blazor app, when redirecting to the AuthServer for login, append the tenant name to the return URL:
var tenantName = currentTenant.Name;
var returnUrl = $"/signin-oidc?tenant={tenantName}";
// Use this returnUrl in your OIDC configuration
On the AuthServer, use the built-in QueryStringTenantResolveContributor:
Configure<AbpTenantResolveOptions>(options =>
{
options.TenantResolvers.Clear();
options.TenantResolvers.Add(new QueryStringTenantResolveContributor());
options.TenantResolvers.Add(new CookieTenantResolveContributor());
options.TenantResolvers.Add(new HeaderTenantResolveContributor());
});
This will resolve the tenant from the tenant query string parameter.
{0} placeholder:
"RootUrl": "https://{0}.uat.domain.io"
ABP provides a sample for subdomain tenant resolution:
This approach is standard for ABP multi-tenancy in tiered environments with a static AuthServer domain.
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
The error "The SSL connection could not be established" when logging in to ABP Studio or using the ABP CLI is typically caused by an issue with the SSL/TLS certificate validation on your machine, even though the URL is accessible in your browser.
Here are the steps to resolve this issue:
Check System Date and Time
Update Root Certificates
Check for Network Interception
Test with .NET
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Invoke-WebRequest https://account.abp.io/.well-known/openid-configuration
Update .NET SDK
Trusted Root CA
Reboot and Retry
For more information, see the official ABP Studio installation guide:
If the problem persists after these steps, please provide details about your network environment (proxy, VPN, etc.) and .NET version.
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.