When a user switches to a linked account in another tenant, the browser should be redirected to that tenant's sub-domain so the application loads under the correct tenant URL.
The documentation and forum posts (for example, #7425) configure AbpAccountOptions:
Configure<AbpAccountOptions>(options =>
{
options.IsTenantMultiDomain = true;
options.GetTenantDomain = (httpContext, info) =>
Task.FromResult(/* tenant URL */);
});
In our Angular + OpenIddict setup, this had no effect. However, configuring AbpAccountOpenIddictOptions works:
Configure<AbpAccountOpenIddictOptions>(options =>
{
options.IsTenantMultiDomain = true;
options.GetTenantDomain = (httpContext, info) =>
Task.FromResult(/* tenant URL */);
});
We could not find any documentation for AbpAccountOpenIddictOptions.
After enabling IsTenantMultiDomain, the grant_type=LinkLogin request to /connect/token fails with HTTP 500:
The exception originates from LinkLoginExtensionGrantProcessJsonResponse. From debugging, it appears that:
Our workaround is:
PreConfigure<OpenIddictServerBuilder>(builder =>
{
builder.RemoveEventHandler(
LinkLoginExtensionGrantProcessJsonResponse.Descriptor
);
});
After removing the handler, tenant_domain is still included in the response and account switching works correctly.
For cross-sub-domain account switching, Angular's LinkLoginHandler redirects with the tokens embedded in the query string (single line, shown wrapped for readability):
https://tenant.mydomain.com?handler=linkLogin&token={"access_token":"...","refresh_token":"...","access_token_stored_at":...,"expires_at":...}
The destination application reads the token payload from the query parameters and stores it in localStorage.