OK. should I delete these fixes once I upgrade to 10.7? I have already implemented
Add this to the ConfigureServices method of your *WebModule:
context.Services.ConfigureApplicationCookie(options => { var previousOnSigningOut = options.Events.OnSigningOut; options.Events.OnSigningOut = async signingOutContext => { if (signingOutContext.HttpContext.Request.Path.StartsWithSegments("/Account/LinkLogin")) { return; }
await previousOnSigningOut(signingOutContext);
};
}); This brings the switch flow back to the 10.4 behavior, where the previous session is kept instead of being revoked. We're tracking the AbpDbConcurrencyException separately.
For the Hangfire error on 10.6: RecurringJob.RemoveIfExists("HangfirePeriodicBackgroundWorkerAdapter<BackgroundJobWorker>.DoWorkAsync") is the correct cleanup for the stale recurring job persisted by the earlier versions.
hi, how do I know if the fixes for these are released? should I just wait for 10.7? thanks
Check the docs before asking a question: https://abp.io/docs/latest Check the samples to see the basic tasks: https://abp.io/docs/latest/samples The exact solution to your question may have been answered before, and please first use the search on the homepage.
Provide us with the following info:
🧐 Hint: If you are using the ABP Studio, you can see all the information about your solution from the configuration window, which opens when you right-click on the solution and click on the Solution Configuration button.
After upgrading past 10.4.0, identity sessions created by fresh cookie logins become invalid as soon as the user re-authenticates (sign-out + sign-in) a second time within the same browser session. The cookie still carries the SessionId claim, but IdentitySessionChecker cannot find that SessionId, and the dynamic-claims contributor force-logs the user out. Reproduces 100% of the time in our automated suite.
Note on patch versions: our commercial NuGet feed shows only 10.5.0 and 10.6.0 stable in this range (then 10.7.0-rc.2 / 10.8 previews, which our production policy excludes), so "upgrade to the latest patch" is not currently an available answer for us — hence the detailed report.
We deployed an identical application tree four times, changing only the ABP package set:
The verification suite is ~100 Playwright tests including dozens of tenant re-authentications. It passes fully on 10.4.0 and fails from the second re-authentication onward on 10.5.0/10.6.0, 100% reproducible.
Log signature at step 3 (Serilog):
[WRN] [Volo.Abp.Identity.Session.IdentitySessionChecker] Could not find SessionId(3f9dd7e8-4d24-47c8-bad8-a2fe0423926f) in the database.
[WRN] [IdentitySessionDynamicClaimsPrincipalContributor] SessionId(...) not valid for user: d4cb6ca4-..., log out.
[WRN] [IdentitySessionDynamicClaimsPrincipalContributor] The token is no longer valid because the user's session expired.
[ERR] [Volo.Abp.Account.Public.Web.AbpAccountPublicWebModule] SessionId is null. It's not possible to revoke the session during sign out.
During the failing sign-out/sign-in sequence we also see (may be cause or symptom — flagging for your attention):
[WRN] [Volo.Abp.EntityFrameworkCore.AbpDbContext] There is an entry which is not saved due to concurrency exception
Volo.Abp.Data.AbpDbConcurrencyException: The database operation was expected to affect 1 row(s), but actually affected 0 row(s)
(On 10.4.0 an occasional optimistic-concurrency warning appears on IdentityRoleStore during login and is benign; on 10.5.0 the session becomes unfindable.)
(If your process requires this as a separate ticket, please say so and we will split it.)
On 10.6.0 with the ABP Hangfire integration, this throws every ~15 seconds:
Hangfire.Common.JobLoadException: Could not load the job
---> System.TypeLoadException: GenericArguments[0], 'Volo.Abp.BackgroundJobs.BackgroundJobWorker', on 'HangfirePeriodicBackgroundWorkerAdapter`1[TWorker]' violates the constraint of type parameter 'TWorker'.
Root cause as we read the 10.6 sources: BackgroundJobWorker no longer implements IBackgroundWorker in 10.6 (it is now IBackgroundJobWorker with its own timer), but the recurring job persisted in Hangfire SQL storage by earlier versions still references HangfirePeriodicBackgroundWorkerAdapter
We are staying on 10.4.0 (fully stable for us) until this is resolved.
I found there are 4 ABP-owned workers: TokenCleanupBackgroundWorker IdentitySessionCleanupBackgroundWorker ExcelFileCleanupWorker ExpiredAuditLogDeleterWorker
I want to change all of them run nightly to make the system more stable.
thanks
We're seeing AppConnections (bound sockets metric) climb at ~120/minute during idle periods with zero incoming HTTP requests, peaking at 1,900+ before the worker process recycles. This eventually causes Win32 error 10055 (WSAENOBUFS — socket buffer exhaustion), which breaks outbound connections to SQL Server and Azure Blob Storage, App restart resets the count, then it starts climbing again immediately, At peak, new outbound connections fail with Win32Exception (10055): An operation on a socket could not be performed because the system lacked sufficient buffer space or because a queue was full
What we've tried: Removed Hangfire's SlidingInvisibilityTimeout Gave Hangfire a dedicated connection string with Max Pool Size=25 to isolate it from EF Core's pool
Questions:
Any guidance appreciated
in the host site, we didn't enable the File Management module, however, all tenants can see the Files in the left sidebar, why? how to fix it?
Impersonation works correctly (admin can log in as another user), but the “Back to my account” / “Back to admin” button no longer appears in the top toolbar, so we cannot revert easily. how to debug? thanks
I have implemented SSO in a Next.js site using ABP.io, but when I call the API endpoints, I get a 401. Is there any doc on how to call an endpoint with the SSO token? thanks
I created new applications under OpenID > Applications, and SSO is working correctly. For example, I can sign in to my Next.js application using abp.io accounts.
Now I’d like to update the flow so that when users click the SSO sign-in button from the Next.js application, the abp.io site automatically switches to a specific tenant—for example, the tenant “NextJs”—when the user lands on the /Account/Register page.
I noticed that the Next.js app invokes /connect/authorize?client_id=Next_app. So I’m wondering: can we add server-side logic in abp.io to automatically switch to the “NextJs” tenant when client_id equals Next_app?
Is this a good solution? If so, how should it be implemented? Or is there a better recommended approach for tenant resolution in this case?
but how can I use it here, or can you give me the full file? can't find the namespaces
*You can try to override the GetSelectedStyleAsync method of ILeptonXStyleProvider service always to return LeptonXStyleNames.Light?
public override Task<string> GetSelectedStyleAsync() { return Task.FromResult(LeptonXStyleNames.Light); } Thanks.*