MicroService template.
The Auth Service has the Themes/LeptonX folder under AuthService. I believe there was customize code there which copy the source code of theme. However, after upgrade to ABP 10 from ABP8.
There is compile error, the Mobilenavbar is not a valid any more @using Volo.Abp.AspNetCore.Mvc.UI.Theme.LeptonX.Themes.LeptonX.Components.SideMenu.MobileNavbar And Default.cshtml @model MobileNavbarViewModel is also not valid
I want to download the source code of LeptonX 5.1.1, but seems the abp list-modules, can don't find LeptonX's module except Lite and BasicTheme.
If I remove the Themes folder. The Login page UI is totally changed (not the customized login in page we used to have)
Hi, For the project that I am upgrading from Ocelot (with ABP 8) to Yarp (ABP 10) The gateway module has this code:
app.UseSwagger();
app.UseSwaggerUI(options =>
{
...
});
app.UseAbpSerilogEnrichers();
**app.MapWhen(
ctx => ctx.Request.Path.ToString().StartsWith("/api/abp/api-definition") ||
ctx.Request.Path.ToString().TrimEnd('/').Equals(""),
app2 =>
{
app2.UseRouting();
app2.UseConfiguredEndpoints();
}
);**
//For signalR
app.UseWebSockets();
app.UseOcelot().Wait();
new code: app.UseSwagger(); app.UseAbpSwaggerUI(options => { ConfigureSwaggerUI(proxyConfig, options, configuration); }); app.UseAbpSerilogEnrichers(); app.UseRewriter(CreateSwaggerRewriteOptions()); app.UseWebSockets(); app.UseEndpoints(endpoints => endpoints.MapReverseProxy());
Did I miss anything about the app.MapWhen in new code?
Figured out the reason, We have same micro service, controllers end with "-public", we want to available to public gateway. Here is AI's answer:
Ocelot uses MMLib.SwaggerForOcelot which downloads all downstream swagger.json files and merges them into the gateway's own swagger.json. So when Swagger UI requests /swagger/v1/swagger.json, it gets a locally generated document that goes through the full SwaggerGen pipeline — including DocInclusionPredicate and DocumentFilter. Swagger UI → /swagger/v1/swagger.json (gateway's OWN doc) ↓ SwaggerGen pipeline runs ↓ DocInclusionPredicate ✅ fires DocumentFilter ✅ fires ↓ Merged & filtered result
YARP simply forwards the request to the downstream service and returns the raw response. The gateway's SwaggerGen pipeline is never involved. Swagger UI → /swagger-json/ClientService/swagger/v1/swagger.json ↓ YARP proxies request to https://localhost:44368/swagger/v1/swagger.json ↓ Raw downstream swagger.json returned directly ↓ DocInclusionPredicate ❌ never fires DocumentFilter ❌ never fires
The solution is add a SwaggerDoc to this MicroSerivce with name "public" and at public gateway yarp setting using: "Transforms": [ { "PathSet": "/swagger/public/swagger.json" } ]
Here is our settings:
"ReverseProxy": {
"Routes": {
"ClientServicePublic": {
"ClusterId": "ClientService",
"Match": {
"Path": "/api/client-service-public/{**catch-all}"
}
},
"ClientServiceSwagger": {
"ClusterId": "ClientService",
"Match": {
"Path": "/swagger-json/ClientService/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/ClientService" }
]
},
"IdentityPublic": {
"ClusterId": "Identity",
"Match": {
"Path": "/api/identity-public/{**catch-all}"
}
},
"IdentitySwagger": {
"ClusterId": "Identity",
"Match": {
"Path": "/swagger-json/Identity/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Identity" }
]
},
"SignalRNegotiate": {
"ClusterId": "ClientServiceSignalR",
"Match": {
"Path": "/signalr/negotiate",
"Methods": [ "POST", "OPTIONS" ]
}
},
"SignalRHub": {
"ClusterId": "ClientServiceSignalR",
"Match": {
"Path": "/signalr/{**catch-all}",
"Methods": [ "GET", "POST", "PUT", "DELETE", "OPTIONS" ]
}
}
},
"Clusters": {
"ClientService": {
"Destinations": {
"ClientService": {
"Address": "https://localhost:44368/"
}
}
},
"ClientServiceSignalR": {
"Destinations": {
"ClientService": { "Address": "https://localhost:44368/" }
},
"SessionAffinity": {
"Enabled": true,
"Policy": "Cookie",
"AffinityKeyName": "ASP.NET_SessionId",
"Cookie": {
"Expiration": "00:30:00"
}
}
},
"Identity": {
"Destinations": {
"Identity": {
"Address": "https://localhost:44388/"
}
}
}
}
}
Before upgrade, our public gateway only expose controller end with '-public', during upgrade process, I see it keep the same. But I not sure, when it shows all APIs, it might because I 1) replace Ocelot with yarp 2) move yarp.json to appsettings.json 3) replace AddAbpSwaggerGenWithOAuth with AddAbpSwaggerGenWithOidc
Do I still need to AddYarp() call after I move yarp.json content to appsettings? I deleted the yarp file after content merge.
When migrate from Ocelet to yarp, by default, an separate yarp.json file is added. When I use yarp file and code has .AddYarp() statement, I noticed that public gateway micro service swagger would only expose those APIs I defined in yarp, however, because of our existing CI/CD, I put yarp.json content to appsettings.json, I noticed that gateway swagger can see all APIs from all micro-service.
Did I miss anything?
My bad, it is introduce by Microsoft.Graph 4.54.0 that the application use. There is another vulnerable package Volo.Abp.TextTemplating.Scriban 10.1.1 it depends on Scriban 6.3.0 which has high-severity vulnerabilities.