Our security team find an issue with ABP application, after user logout, the access token before logout is still valid for make API call etc. How to invalid the access token once user logout?
Hi,
After upgrade from ABP 8 to ABP 10, and deploy to AKS, after angular app login, it shows this error and browser address format is is: https://<tentant1>.<app domain>

The backend's sub domain setting is not like this: //Configurate Wild Card Domain options for OpenIddict only on non-local environments if (!hostingEnvironment.IsDevelopment() && !string.IsNullOrWhiteSpace(configuration["App:OpenIddictWildcardDomainsFormat"])) { PreConfigure<AbpOpenIddictWildcardDomainOptions>(options => { options.EnableWildcardDomainSupport = true; options.WildcardDomainsFormat.Add(configuration["App:OpenIddictWildcardDomainsFormat"]); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signin-oidc"); options.WildcardDomainsFormat.Add($@"{configuration["App:OpenIddictWildcardDomainsFormat"]}signout-callback-oidc"); }); }
This piece of code is not changed, does OpenIdDict new version has changed related to WildChardDomain, the appsettings.json is: "OpenIddictWildcardDomainsFormat": "https://{0}.<app domain's value>/",
In the etc/docker folder, the compose file contains: mongo-db: container_name: mongodb image: mongodb/mongodb-enterprise-server:latest volumes: - mongodata:/data/db - mongoconfigdata:/data/configdb
In my local docker, the image file with 'latest' tag is actually 2 years ago, if connect it with NoSQLBooster, I can tell the image version is 7.0.14
Since I want to try MongoDb version 8, so I remove that image from docker, after run ./up.ps1, form docker, it seems the version is 8.2.7 .. however, the mongoDb instance is not started properly 
When Migrate from Auto Mapper to Mapperly, we have current existing code: used in AutoMapper profile, how to migrate this code:
CreateMap<UploadedSurveyData, SurveyData>()
.IgnoreNotInListMembers (...);
public static class AutoMapperProfileExtension
{
public static IMappingExpression<TSource, TDestination> IgnoreNotInListMembers<TSource, TDestination>(this IMappingExpression<TSource, TDestination> expr, List<string> requiredProperties)
where TDestination : class
{
var destinationType = typeof(TDestination);
if (requiredProperties == null || requiredProperties.Count == 0)
{
return expr;
}
foreach (var property in from property in destinationType.GetProperties()
where !requiredProperties.Contains(property.Name)
select property)
{
expr.ForMember(property.Name, opt => opt.Ignore());
}
return expr;
}
}
When I do ABP upgrade from 8 to 10 (Micro Service template), I noticed that in new ABP code template that created by ABP legacy Cli, in the yarp, it is "AccountAdmin": { "ClusterId": "AuthServer", "Match": { "Path": "/api/account-admin/{**catch-all}" } }, However in our existing code base (Ocelot), it is: { "ServiceKey": "Identity Service", "DownstreamPathTemplate": "/api/account-admin/{everything}", "DownstreamScheme": "https", "DownstreamHostAndPorts": [ { "Host": "localhost", "Port": 44388 } ], "UpstreamPathTemplate": "/api/account-admin/{everything}", "UpstreamHttpMethod": [ "Put", "Delete", "Get", "Post" ] },
Since in this upgrade, we also ugrade Ocelot to Yarp, shall we change Yarp per ABP template? Is there any backend code changes need to in Auth Server?
Mongo Driver 3.0 change the GUID format, however, we need to make GUID using old format, no matter for insert new or reading existing, include ABP's entity Id column.
We used this code, but it seems have problem to reading existing Entity's Id
var conventionPack = new ConventionPack { new LegacyGuidConvention() };
ConventionRegistry.Register(
"LegacyGuidConvention",
conventionPack,
t => true); // Apply to all types
Our Angular app.component.ts has code call, but actually now we got a blank header and Abp's default footer. It seems the replacement not working anymore this.replaceableComponents.add({ component: BreadcrumbComponent, key: eThemeLeptonXComponents.Breadcrumb, }); ... this.replaceableComponents.add({ component: AppSettingsComponent, key: eThemeLeptonXComponents.Footer, });
yarn install v1.22.22 info No lockfile found. [1/4] Resolving packages... error Couldn't find package "@abp/ng.components" on the "npm" registry.
package version is ~9.1.1
I did run abp login command first.
After upgrade and deploy the application (EF core, Micro serivce) , the app data access layer throw timeout exception, here is one of example:
(@p6 uniqueidentifier,@p7 nvarchar(40),@p4 nvarchar(40),@p5 datetime2(7))UPDATE [Agents] SET [ConcurrencyStamp] = @p4, [LastModificationTime] = @p5 OUTPUT 1 WHERE [Id] = @p6 AND [ConcurrencyStamp] = @p7
The agents table has 900+ records only. Azure SQL server's compatible level is SQL Server 2019.
MicroService template.
The Auth Service has the Themes/LeptonX folder under AuthService. I believe there was customize code there which copy the source code of theme. However, after upgrade to ABP 10 from ABP8.
There is compile error, the Mobilenavbar is not a valid any more @using Volo.Abp.AspNetCore.Mvc.UI.Theme.LeptonX.Themes.LeptonX.Components.SideMenu.MobileNavbar And Default.cshtml @model MobileNavbarViewModel is also not valid
I want to download the source code of LeptonX 5.1.1, but seems the abp list-modules, can don't find LeptonX's module except Lite and BasicTheme.
If I remove the Themes folder. The Login page UI is totally changed (not the customized login in page we used to have)