Hi maliming,
Thank you for the details you provided.
You can consider this ticket closed.
Best regards, Stefano
Hi maliming,
Thanks for your reply.
Yesterday I tried making the change AI-Bot suggested:
options.SaveTokens = false;
and the app worked again.
Regarding your question #1 (Roughly how many roles is this user assigned to?), the issue is that **all **the application users (about a hundred) were unable to log in.
Regarding your question #2, it's possible that users were assigned roles and/or permissions, but only through the application interface.
It should be noted that the code for managing roles, permissions, and claims does not vary from the standard ABP template on which the application is built.
In any case, at the moment and with that change the application is back to working for all users.
Best regards, Stefano
Hi,
I have an ABP 9.3.6 application running on Azure that had no issues until a few days ago. This application uses Okta for authentication (a few months ago I opened the ticket #10171, but everything was resolved). From one day to the next, the application stopped working (on all environments where the application was installed: DEV, TEST, and PRODUCTION) without any changes to the application or the Okta configuration. The problem is that, once I've logged in to Okta and the application is redirected to the main page, I get a 502 error. Analyzing the Azure Log Stream , it appears the issue may be the size of the 8,890-byte session cookie generated by the ABP framework. Since we're in an Enterprise environment and it's not possible to change the Okta configuration (except at length), is there any way to reduce the cookie size programmatically?
I attach the module code to check if I used any options (e.g. app.UseDynamicClaims()) that might impact the size:
...
public class CalendarWebModule : AbpModule
{
public override void PreConfigureServices(ServiceConfigurationContext context)
{
var hostingEnvironment = context.Services.GetHostingEnvironment();
var configuration = context.Services.GetConfiguration();
context.Services.PreConfigure<AbpMvcDataAnnotationsLocalizationOptions>(options =>
{
options.AddAssemblyResource(
typeof(CalendarResource),
typeof(CalendarDomainModule).Assembly,
typeof(CalendarDomainSharedModule).Assembly,
typeof(CalendarApplicationModule).Assembly,
typeof(CalendarApplicationContractsModule).Assembly,
typeof(CalendarWebModule).Assembly
);
});
PreConfigure<OpenIddictBuilder>(builder =>
{
builder.AddValidation(options =>
{
options.AddAudiences("Calendar");
options.UseLocalServer();
options.UseAspNetCore();
});
});
if (!hostingEnvironment.IsDevelopment())
{
PreConfigure<AbpOpenIddictAspNetCoreOptions>(options =>
{
options.AddDevelopmentEncryptionAndSigningCertificate = false;
});
PreConfigure<OpenIddictServerBuilder>(serverBuilder =>
{
serverBuilder.AddProductionEncryptionAndSigningCertificate("openiddict.pfx", configuration["AuthServer:CertificatePassPhrase"]!);
serverBuilder.SetIssuer(new Uri(configuration["AuthServer:Authority"]!));
});
}
}
public override void ConfigureServices(ServiceConfigurationContext context)
{
var hostingEnvironment = context.Services.GetHostingEnvironment();
var configuration = context.Services.GetConfiguration();
if (!configuration.GetValue<bool>("App:DisablePII"))
{
Microsoft.IdentityModel.Logging.IdentityModelEventSource.ShowPII = true;
Microsoft.IdentityModel.Logging.IdentityModelEventSource.LogCompleteSecurityArtifact = true;
}
if (!configuration.GetValue<bool>("AuthServer:RequireHttpsMetadata"))
{
Configure<OpenIddictServerAspNetCoreOptions>(options =>
{
options.DisableTransportSecurityRequirement = true;
});
Configure<ForwardedHeadersOptions>(options =>
{
options.ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto | ForwardedHeaders.XForwardedHost;
});
}
context.Services.AddScoped<NotyfViewComponent>();
ConfigureBundles();
ConfigureUrls(configuration);
ConfigureHealthChecks(context);
ConfigurePages(configuration);
ConfigureImpersonation(context, configuration);
ConfigureExternalProviders(context);
ConfigureCookieConsent(context);
ConfigureAuthentication(context);
ConfigureAutoMapper();
ConfigureVirtualFileSystem(hostingEnvironment);
ConfigureNavigationServices();
ConfigureAutoApiControllers();
ConfigureSwaggerServices(context.Services);
ConfigureTheme();
Configure<PermissionManagementOptions>(options =>
{
options.IsDynamicPermissionStoreEnabled = true;
});
Configure<AbpLayoutHookOptions>(options =>
{
options.Add(
LayoutHooks.Head.Last, //The hook name
typeof(DevExtremeJsViewComponent) //The component to add
);
options.Add(
LayoutHooks.Head.Last,
typeof(ChanelJsViewComponent)
);
});
Configure<SettingManagementPageOptions>(options =>
{
options.Contributors.Add(new CalendarSettingsPageContributor());
options.Contributors.Add(new DeskReservationSettingsPageContributor());
options.Contributors.Add(new PlanningSettingsPageContributor());
options.Contributors.Add(new TradeSettingsPageContributor());
});
context.Services.AddSameSiteCookiePolicy(); // cookie policy to deal with temporary browser incompatibilities
context.Services.AddNotyf(config =>
{
config.DurationInSeconds = 8;
config.IsDismissable = true;
config.Position = NotyfPosition.TopCenter;
});
}
private void ConfigureCookieConsent(ServiceConfigurationContext context)
{
context.Services.AddAbpCookieConsent(options =>
{
options.IsEnabled = true;
options.CookiePolicyUrl = "/CookiePolicy";
options.PrivacyPolicyUrl = "/PrivacyPolicy";
});
}
private void ConfigureTheme()
{
Configure<LeptonXThemeOptions>(options =>
{
options.DefaultStyle = LeptonXStyleNames.System;
});
Configure<LeptonXThemeMvcOptions>(options =>
{
options.ApplicationLayout = LeptonXMvcLayouts.SideMenu;
});
}
private void ConfigureHealthChecks(ServiceConfigurationContext context)
{
//context.Services.AddCalendarHealthChecks();
}
private void ConfigureBundles()
{
Configure<AbpBundlingOptions>(options =>
{
options.StyleBundles.Configure(
LeptonXThemeBundles.Styles.Global,
bundle =>
{
bundle.AddFiles("/global-styles.css");
}
);
options.ScriptBundles.Configure(
LeptonXThemeBundles.Scripts.Global,
bundle =>
{
bundle.AddFiles("/global-scripts.js");
}
);
options
.StyleBundles
.Get(StandardBundles.Styles.Global)
.AddContributors(typeof(DevExtremeStyleContributor));
options
.StyleBundles
.Get(StandardBundles.Styles.Global)
.AddContributors(typeof(CalendarStyleContributor));
});
}
private void ConfigurePages(IConfiguration configuration)
{
Configure<RazorPagesOptions>(options =>
{
options.Conventions.AuthorizePage("/HostDashboard", CalendarPermissions.Dashboard.Host);
});
}
private void ConfigureUrls(IConfiguration configuration)
{
Configure<AppUrlOptions>(options =>
{
options.Applications["MVC"].RootUrl = configuration["App:SelfUrl"];
});
}
private void ConfigureAuthentication(ServiceConfigurationContext context)
{
context.Services.ForwardIdentityAuthenticationForBearer(OpenIddictValidationAspNetCoreDefaults.AuthenticationScheme);
context.Services.Configure<AbpClaimsPrincipalFactoryOptions>(options =>
{
options.IsDynamicClaimsEnabled = true;
});
}
private void ConfigureImpersonation(ServiceConfigurationContext context, IConfiguration configuration)
{
context.Services.Configure<AbpIdentityWebOptions>(options =>
{
options.EnableUserImpersonation = true;
});
context.Services.Configure<AbpAccountOptions>(options =>
{
options.TenantAdminUserName = "admin";
options.ImpersonationUserPermission = IdentityPermissions.Users.Impersonation;
});
}
private void ConfigureAutoMapper()
{
Configure<AbpAutoMapperOptions>(options =>
{
options.AddMaps<CalendarWebModule>();
});
}
private void ConfigureVirtualFileSystem(IWebHostEnvironment hostingEnvironment)
{
Configure<AbpVirtualFileSystemOptions>(options =>
{
options.FileSets.AddEmbedded<CalendarWebModule>();
if (hostingEnvironment.IsDevelopment())
{
options.FileSets.ReplaceEmbeddedByPhysical<CalendarDomainSharedModule>(Path.Combine(hostingEnvironment.ContentRootPath, string.Format("..{0}Chanel.Calendar.Domain.Shared", Path.DirectorySeparatorChar)));
options.FileSets.ReplaceEmbeddedByPhysical<CalendarDomainModule>(Path.Combine(hostingEnvironment.ContentRootPath, string.Format("..{0}Chanel.Calendar.Domain", Path.DirectorySeparatorChar)));
options.FileSets.ReplaceEmbeddedByPhysical<CalendarApplicationContractsModule>(Path.Combine(hostingEnvironment.ContentRootPath, string.Format("..{0}Chanel.Calendar.Application.Contracts", Path.DirectorySeparatorChar)));
options.FileSets.ReplaceEmbeddedByPhysical<CalendarApplicationModule>(Path.Combine(hostingEnvironment.ContentRootPath, string.Format("..{0}Chanel.Calendar.Application", Path.DirectorySeparatorChar)));
options.FileSets.ReplaceEmbeddedByPhysical<CalendarHttpApiModule>(Path.Combine(hostingEnvironment.ContentRootPath, string.Format("..{0}..{0}src{0}Chanel.Calendar.HttpApi", Path.DirectorySeparatorChar)));
options.FileSets.ReplaceEmbeddedByPhysical<CalendarWebModule>(hostingEnvironment.ContentRootPath);
}
});
}
private void ConfigureNavigationServices()
{
Configure<AbpNavigationOptions>(options =>
{
options.MenuContributors.Add(new CalendarMenuContributor());
});
Configure<AbpToolbarOptions>(options =>
{
options.Contributors.Add(new CalendarToolbarContributor());
});
}
private void ConfigureAutoApiControllers()
{
Configure<AbpAspNetCoreMvcOptions>(options =>
{
options.ConventionalControllers.Create(typeof(CalendarApplicationModule).Assembly);
options.ConventionalControllers
.Create(typeof(CalendarApplicationModule).Assembly, opts =>
{
opts.UseV3UrlStyle = true;
});
});
}
private void ConfigureSwaggerServices(IServiceCollection services)
{
services.AddAbpSwaggerGen(
options =>
{
options.SwaggerDoc("v1", new OpenApiInfo { Title = "Calendar API", Version = "v1" });
options.DocInclusionPredicate((docName, description) => true);
options.CustomSchemaIds(type => type.FullName);
}
);
}
private void ConfigureExternalProviders(ServiceConfigurationContext context)
{
context.Services
.AddAuthentication()
.AddOpenIdConnect("Okta", options =>
{
options.Authority = "https://myauthentication.okta.com/oauth2/default";
options.ClientId = context.Configuration["AzureAd:ClientId"];
options.ClientSecret = context.Configuration["AzureAd:ClientSecret"];
options.CallbackPath = context.Configuration["AzureAd:CallbackPath"];
options.ResponseType = OpenIdConnectResponseType.Code;
options.SignInScheme = IdentityConstants.ExternalScheme;
options.SaveTokens = true;
options.MapInboundClaims = false;
options.Scope.Add("openid");
options.Scope.Add("profile");
options.Scope.Add("email");
options.ClaimActions.MapJsonKey(ClaimTypes.NameIdentifier, "sub");
options.Events = new OpenIdConnectEvents
{
OnRedirectToIdentityProvider = redirectContext =>
{
redirectContext.ProtocolMessage.RedirectUri = context.Configuration["AzureAd:RedirectToIdentityProviderUri"];
return Task.CompletedTask;
}
};
});
}
public override void OnApplicationInitialization(ApplicationInitializationContext context)
{
var app = context.GetApplicationBuilder();
var env = context.GetEnvironment();
app.UseForwardedHeaders();
if (env.IsDevelopment())
{
app.UseDeveloperExceptionPage();
}
app.UseAbpRequestLocalization();
if (!env.IsDevelopment())
{
app.UseErrorPage();
app.UseHsts();
}
app.UseAbpCookieConsent();
app.UseCorrelationId();
app.UseRouting();
app.MapAbpStaticAssets();
app.UseAbpStudioLink();
app.UseAbpSecurityHeaders();
app.UseAuthentication();
app.UseAbpOpenIddictValidation();
if (MultiTenancyConsts.IsEnabled)
{
app.UseMultiTenancy();
}
app.UseUnitOfWork();
app.UseDynamicClaims();
app.UseAuthorization();
app.UseSwagger();
app.UseAbpSwaggerUI(options =>
{
options.SwaggerEndpoint("/swagger/v1/swagger.json", "Calendar API");
});
app.UseAuditing();
app.UseAbpSerilogEnrichers();
app.UseNotyf();
app.UseConfiguredEndpoints();
}
}
f you need the log, let me know how to send it, as it's too large to paste here.
Best regards,
Stefano
Hi,
Unfortunately, I can't because the client environment is private and accessible with Okta authentication.
I can share sections of code with you or I can share the screen with you in a private call.
Stefano
Hi, my application, which runs in Azure, doesn't display icons on some pages Looking with Chrome's DevTools, I see these reports:
The same problem does not occur in development environment.
This is how it should look:
And this is what you see in Azure:
Please note that those icons are the free font awesome icons found in the ABP solution template
Can you tell me how to fix this? Thanks
Hi,
With this change, everything seems to work. Thanks for the support.
Stefano
Hi,
I sent you the files with WeTransfer.
I tried accessing the protected /Identity/Users page, which triggers a loop on the Okta login page.
Stefano