Activities of "merdan"

Provide us with the following info:

ABP Studio solution configuration

  • Template: app-nolayers
  • Template Type: Modern
  • Created ABP Studio Version: 3.1.3
  • Current ABP Studio Version: 3.1.3
  • Multi-Tenancy: Yes
  • UI Framework: react
  • Theme: leptonx
  • Theme Style: system
  • Database Provider: ef
  • Database Management System: postgresql
  • Public Website: Yes
  • Social Login: Yes
  • Include Tests: Yes
  • Use Local References: No
  • Optional Modules: TextTemplateManagement, AuditLogging, OpenIddictAdmin, LowCode
  • Selected Languages: Türkmençe, English, Russian
  • Default Language: Türkmençe
  • Create Command: abp new Ak.Binyat -t app-nolayers --modern --modular --ui-framework react --database-provider ef --database-management-system postgresql --theme leptonx --tests --public-website --without-cms-kit --sample-crud-page --dont-run-install-libs --dont-run-bundling -no-gdpr -no-file-management -no-language-management -low-code

Business modules were then added with ABP Studio (13 modules, e.g. Ak.Binyat.MasterData, Ak.Binyat.Treasury). ABP Framework 10.6.1, .NET 10, macOS. Every defect below shows up on the untouched generated solution; we checked each one against the scaffold commit before changing anything. We have local workarounds for all of them and are reporting so the templates can be fixed.

One related defect is in the open-source template and is already filed on GitHub: abpframework/abp#26221 (the app-nolayers ru.json contains Romanian text).


1. Host tests: LowCode leaks a disposed container between test applications (9 of 10 tests fail)

Exception message and stack trace (every test after the first one in the process):

Volo.Abp.AbpInitializationException : An error occurred during the initialize Volo.Abp.Modularity.OnApplicationInitializationModuleLifecycleContributor phase of the module Volo.Abp.LowCode.AbpLowCodeDomainModule, Volo.Abp.LowCode.Domain, Version=10.6.1.0: Instances cannot be resolved and nested lifetimes cannot be created from this LifetimeScope as it (or one of its parent scopes) has already been disposed.
---- System.ObjectDisposedException : Instances cannot be resolved and nested lifetimes cannot be created from this LifetimeScope as it (or one of its parent scopes) has already been disposed.
   at Autofac.Core.Lifetime.LifetimeScope.ThrowDisposedException()
   at Autofac.Core.Lifetime.LifetimeScope.BeginLifetimeScope()
   at Autofac.Extensions.DependencyInjection.AutofacServiceScopeFactory.CreateScope()
   at Volo.Abp.EventBus.IocEventHandlerFactory.GetHandler()
   at Volo.Abp.EventBus.Local.LocalEventBus.GetHandlerFactories(Type eventType)
   ...
   at Volo.Abp.EventBus.Distributed.LocalDistributedEventBus.PublishAsync(Type eventType, Object eventData, Boolean onUnitOfWorkComplete, Boolean useOutbox)
   at Volo.Abp.LowCode.AbpLowCodeApplicationModule.<>c__DisplayClass4_1...MoveNext()
   at Volo.Abp.LowCode.Modeling.DynamicModelManager.NotifyModelChangedAsync()
   at Volo.Abp.LowCode.Modeling.DynamicModelManager.RemoveLayersAsync(Func`2 predicate)
   at Volo.Abp.LowCode.AbpLowCodeDomainModule.OnApplicationInitializationAsync(ApplicationInitializationContext context)
   at Volo.Abp.AspNetCore.TestBase.AbpWebApplicationFactoryIntegratedTest`1..ctor()
   at Ak.Binyat.BinyatTestBase..ctor()

Steps to reproduce: generate the solution with the command above, then run dotnet test Ak.Binyat.Tests. Result: Failed: 9, Passed: 1. Any single test passes when run alone.

Cause (as far as we can see):

  • DynamicModelManager.Instance is a process-wide singleton.
  • AbpLowCodeApplicationModule subscribes an OnModelChanged handler that captures its application's container, and never unsubscribes it on shutdown.
  • The next test application's AbpLowCodeDomainModule initialization calls the previous, disposed application's handler.

Our workaround resets the private Func<Task> backing field of OnModelChanged on DynamicModelManager.Instance to a no-op in the test module's OnApplicationShutdown, using reflection. Setting it to null throws a NullReferenceException instead, because the delegate is invoked without a null check. A supported fix would be to unsubscribe on application shutdown, or to make the manager per-application.

2. Sample CRUD test violates a foreign key (--sample-crud-page)

Microsoft.Data.Sqlite.SqliteException : SQLite Error 19: 'FOREIGN KEY constraint failed'.
   at Ak.Binyat.Books.BookAppService_Tests.Should_Create_A_Valid_Book()

(Visible once #1 is worked around.) Book has a required FK to Author, but the test's CreateUpdateBookDto sets no AuthorId. Fix: use a seeded author's id. The generated file name also contains a space: Books/BookAppService_Tests .cs.

3. Module template: sample controller test uses a non-kebab URL for multi-word module names

For a module named MasterData, the route is [Route("api/master-data/example")], but ExampleController_Tests.GetAsync requests api/MasterData/example, so it fails with Shouldly.ShouldAssertException : response.StatusCode. Single-word modules (e.g. Treasury) pass.

4. React (--modern) app

a) Test files cannot load: @testing-library/dom is missing.

src/pages/books/BooksPage.test.tsx(2,35): error TS2305: Module '"@testing-library/react"' has no exported member 'fireEvent'.
src/pages/home/HomePage.test.tsx(2,18): error TS2305: Module '"@testing-library/react"' has no exported member 'screen'.

npx vitest run → Test Files 10 failed (10), no tests. @testing-library/react v16 needs the peer dependency @testing-library/dom, which is not in package.json.

b) tsc -b error:

src/lib/api/books.ts(8,13): error TS1294: This syntax is not allowed when 'erasableSyntaxOnly' is enabled.

export enum BookType is not allowed under erasableSyntaxOnly. The fix is a const object plus a type alias.

c) Eight tests fail once (a) is fixed, because they are out of date with the components:

  • Authors/Books page tests: they look for "Edit"/"Delete" text, but the actions are now in a Radix "Actions" dropdown, rendered only when usePermissions().isGranted(...) is true, and delete goes through a ConfirmDialog.
  • Delete assertions: they expect deleteBook('1'), but TanStack Query v5 passes a second context argument to mutationFn.
  • HomePage test: it expects "Dashboard", which the page no longer renders.
  • axios tests:
    • The 401-retry test's mock never stores the renewed user.
    • The 403 test asserts window.location.href === '/403', which jsdom never changes.

d) Users page: real UI bug. Changing the sort changes the query key, so isLoading turns true and the whole table is replaced by "Please wait…" on every header click. placeholderData: keepPreviousData fixes it. Separately, AppUserAppService.GetListAsync ignores input.Sorting, so the order never changes at all.

e) Localization never loads from the server for a culture that has a static bundle. In src/components/layout/Header.tsx, the effect skips fetchAppLocalization when i18n.hasResourceBundle(currentCulture, 'translation') is true. Because en.json is bundled statically, English never receives server-side resources (e.g. module resources), and adding static bundles for other cultures hides their server strings permanently. The same pattern is in react-public-web.

f) react/Dockerfile cannot build. It runs COPY package*.json + RUN npm ci, but the app is locked with yarn.lock and has no package-lock.json. There is also no .dockerignore, so the host's node_modules is copied into the image.

5. Public website (react-public-web, Next.js 16)

a) next build fails on the generated project:

.next/types/validator.ts(89,31): error TS2344: Type 'typeof import(".../react-public-web/src/pages/home/HomePage")' does not satisfy the constraint 'PagesPageConfig'.
  Property 'default' is missing in type 'typeof import(".../src/pages/home/HomePage")' but required in type 'PagesPageConfig'.
Failed to type check.

The app uses the App Router (src/app/), but keeps a plain component under src/pages/, which Next reserves for Pages-Router routes. Moving it (e.g. to src/views/) fixes the build.

b) yarn lint fails after a build. eslint.config.js ignores only dist, so it lints .next/ output:

.next/server/chunks/ssr/[turbopack]_runtime.js: Definition for rule '@typescript-eslint/no-unused-vars' was not found

c) Every next build rewrites the committed tsconfig.json and next-env.d.ts. It is probably simplest to commit Next's required tsconfig.json values and ignore next-env.d.ts / *.tsbuildinfo, as create-next-app does.

6. Multi-tenancy gaps in generated code (security)

  • AppUser: AppIdentityUserEto (the projection of IdentityUser events into AppUser) carries no TenantId, and AppUser is not IMultiTenant. A tenant administrator calling the users endpoint therefore receives host users and other tenants' users.
  • Sample entities: Book and Author are not IMultiTenant, and their permissions have no MultiTenancySides restriction, so any tenant granted them reads and edits every tenant's data.

7. Docker / scripts (etc/)

  • etc/docker/docker-compose.yml build contexts:
    • The API services use context: ../../, while Dockerfile.local does COPY bin/Release/net10.0/publish/ app/, a path relative to the host project.
    • The web service uses context: ../../../, which is outside the repository.
    • docker compose build fails for both.
  • Wrong environment variables:
    • App_CorsOrigins has a single underscore, so it never binds to App:CorsOrigins.
    • App__HealthCheckUrl=http://binyat:8080/... uses a host that does not exist (the service is binyat-api).
  • PostgreSQL data is lost when the container is recreated: the volume is mounted at /var/opt/postgres, but the official image stores data in /var/lib/postgresql/data.
  • etc/docker/run-docker.ps1: certificate generation is nested inside the certs/ folder-exists check, so a missing localhost.pfx is never regenerated.
  • etc/build/build-images-locally.ps1: it runs npm install / npm run build for React, ignoring yarn.lock and leaving a package-lock.json. The Dockerfile builds the app again anyway.

Steps to reproduce (summary):

  1. Run the create command above (optionally add a module named MasterData in ABP Studio).
  2. dotnet test Ak.Binyat.Tests → 9/10 fail (#1).
  3. In react/: yarn install, then npx tsc -b --noEmit and npx vitest run → #4a/#4b, then #4c.
  4. In react-public-web/: yarn install && yarn build → #5a.
  5. docker build react → #4f. docker compose -f etc/docker/docker-compose.yml build → #7.

We are happy to provide the generated solution or our patches for any of these.

Manually downloading Microsoft.ClearScript.V8.Native.win-arm64 nuget package and extracting ClearScriptV8.win-arm64.dll to the ..\volo.abp.suite\10.0.0\tools\net10.0\any\runtimes\win-arm64\native folder fixed the issue.

While this workaround works, still keeping this issue open so that an ABP developer can fix this in future releases.

ABP Suite starts and runs on Windows ARM, but throws an exception when opening a project. Tried opening it directly from a terminal and from the ABP Studio, getting the same results.

The stack trace:

2025-11-28 11:21:19.175 +05:00 [ERR] An exception was thrown while activating Volo.Abp.Suite.Controllers.CrudPageGeneratorController -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Commands.CrudPageGenerator -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Services.CustomCodeFileNestingService -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Services.TemplateService -> λ:Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.ICodeFormatter -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.CodeFormatter -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.JavascriptPrettierFormatter.
Autofac.Core.DependencyResolutionException: An exception was thrown while activating Volo.Abp.Suite.Controllers.CrudPageGeneratorController -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Commands.CrudPageGenerator -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Services.CustomCodeFileNestingService -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Services.TemplateService -> λ:Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.ICodeFormatter -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.CodeFormatter -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.JavascriptPrettierFormatter.
 ---> Autofac.Core.DependencyResolutionException: An exception was thrown while invoking the constructor 'Void .ctor(Volo.Abp.VirtualFileSystem.IVirtualFileProvider)' on type 'JavascriptPrettierFormatter'.
 ---> System.TypeLoadException: Cannot load ClearScript V8 library. Load failure information for ClearScriptV8.win-arm64.dll:
C:\Users\merda\.dotnet\tools\.store\volo.abp.suite\10.0.0\volo.abp.suite\10.0.0\tools\net10.0\any\runtimes\win-arm64\native\ClearScriptV8.win-arm64.dll: Unable to load DLL 'C:\Users\merda\.dotnet\tools\.store\volo.abp.suite\10.0.0\volo.abp.suite\10.0.0\tools\net10.0\any\runtimes\win-arm64\native\ClearScriptV8.win-arm64.dll' or one of its dependencies: The specified module could not be found. (0x8007007E)
C:\Users\merda\.dotnet\tools\.store\volo.abp.suite\10.0.0\volo.abp.suite\10.0.0\tools\net10.0\any\ClearScriptV8.win-arm64.dll: Unable to load DLL 'C:\Users\merda\.dotnet\tools\.store\volo.abp.suite\10.0.0\volo.abp.suite\10.0.0\tools\net10.0\any\ClearScriptV8.win-arm64.dll' or one of its dependencies: The specified module could not be found. (0x8007007E)
   at Microsoft.ClearScript.V8.V8Proxy.LoadNativeLibrary(String baseName, String platform, String architecture, String extension)
   at Microsoft.ClearScript.V8.V8Proxy.LoadNativeAssembly()
   at Microsoft.ClearScript.V8.V8Proxy.OnEntityHolderCreated()
   at Microsoft.ClearScript.V8.SplitProxy.V8EntityHolder..ctor(String name, Func`1 acquireHandle)
   at Microsoft.ClearScript.V8.SplitProxy.V8IsolateProxyImpl..ctor(String name, V8RuntimeConstraints constraints, V8RuntimeFlags flags, Int32 debugPort)
   at Microsoft.ClearScript.V8.V8IsolateProxy.Create(String name, V8RuntimeConstraints constraints, V8RuntimeFlags flags, Int32 debugPort)
   at Microsoft.ClearScript.V8.V8Runtime..ctor(String name, V8RuntimeConstraints constraints, V8RuntimeFlags flags, Int32 debugPort)
   at Microsoft.ClearScript.V8.V8Runtime..ctor(String name, V8RuntimeConstraints constraints, V8RuntimeFlags flags)
   at Microsoft.ClearScript.V8.V8Runtime..ctor(String name, V8RuntimeConstraints constraints)
   at Microsoft.ClearScript.V8.V8ScriptEngine..ctor(V8Runtime runtime, String name, V8RuntimeConstraints constraints, V8ScriptEngineFlags flags, Int32 debugPort)
   at Microsoft.ClearScript.V8.V8ScriptEngine..ctor(String name, V8RuntimeConstraints constraints, V8ScriptEngineFlags flags, Int32 debugPort)
   at Microsoft.ClearScript.V8.V8ScriptEngine..ctor(V8ScriptEngineFlags flags, Int32 debugPort)
   at Microsoft.ClearScript.V8.V8ScriptEngine..ctor(V8ScriptEngineFlags flags)
   at Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.JavascriptPrettierFormatter..ctor(IVirtualFileProvider vfs)
   at lambda_method922(Closure, Object[])
   at Autofac.Core.Activators.Reflection.BoundConstructor.Instantiate()
   --- End of inner exception stack trace ---
   at Autofac.Core.Activators.Reflection.BoundConstructor.Instantiate()
   at Autofac.Core.Activators.Reflection.ReflectionActivator.&lt;&gt;c__DisplayClass14_0.&lt;UseSingleConstructorActivation&gt;b__0(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Middleware.DelegateMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.&lt;&gt;c__DisplayClass14_0.&lt;BuildPipeline&gt;b__1(ResolveRequestContext context)
   at Autofac.Core.Resolving.Middleware.DisposalTrackingMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.<>c__DisplayClass14_0.<BuildPipeline>b__1(ResolveRequestContext context)
   at Autofac.Builder.RegistrationBuilder`3.&lt;&gt;c__DisplayClass41_0.&lt;PropertiesAutowired&gt;b__0(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Middleware.DelegateMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.&lt;&gt;c__DisplayClass14_0.&lt;BuildPipeline&gt;b__1(ResolveRequestContext context)
   at Autofac.Extensions.DependencyInjection.KeyedServiceMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.<>c__DisplayClass14_0.<BuildPipeline>b__1(ResolveRequestContext context)
   at Autofac.Core.Resolving.Middleware.ActivatorErrorHandlingMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   --- End of inner exception stack trace ---
   at Autofac.Core.Resolving.Middleware.ActivatorErrorHandlingMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.<>c__DisplayClass14_0.<BuildPipeline>b__1(ResolveRequestContext context)
   at Autofac.Core.Pipeline.ResolvePipeline.Invoke(ResolveRequestContext context)
   at Autofac.Core.Resolving.Middleware.RegistrationPipelineInvokeMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.&lt;&gt;c__DisplayClass14_0.&lt;BuildPipeline&gt;b__1(ResolveRequestContext context)
   at Autofac.Core.Resolving.Middleware.SharingMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.<>c__DisplayClass14_0.<BuildPipeline>b__1(ResolveRequestContext context)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.<>c__DisplayClass14_0.<BuildPipeline>b__1(ResolveRequestContext context)
   at Autofac.Core.Resolving.Middleware.CircularDependencyDetectorMiddleware.Execute(ResolveRequestContext context, Action`1 next)
   at Autofac.Core.Resolving.Pipeline.ResolvePipelineBuilder.&lt;&gt;c__DisplayClass14_0.&lt;BuildPipeline&gt;b__1(ResolveRequestContext context)
   at Autofac.Core.Pipeline.ResolvePipeline.Invoke(ResolveRequestContext context)
   at Autofac.Core.Resolving.ResolveOperation.GetOrCreateInstance(ISharingLifetimeScope currentOperationScope, ResolveRequest& request)
   at Autofac.Core.Resolving.ResolveOperation.ExecuteOperation(ResolveRequest& request)
   at Autofac.Core.Resolving.ResolveOperation.Execute(ResolveRequest& request)
   at Autofac.Core.Lifetime.LifetimeScope.ResolveComponent(ResolveRequest& request)
   at Autofac.Core.Lifetime.LifetimeScope.Autofac.IComponentContext.ResolveComponent(ResolveRequest& request)
   at Autofac.ResolutionExtensions.TryResolveService(IComponentContext context, Service service, IEnumerable`1 parameters, Object& instance)
   at Autofac.ResolutionExtensions.ResolveService(IComponentContext context, Service service, IEnumerable`1 parameters)
   at Autofac.ResolutionExtensions.Resolve(IComponentContext context, Type serviceType, IEnumerable`1 parameters)
   at Autofac.ResolutionExtensions.Resolve(IComponentContext context, Type serviceType)
   at Autofac.Extensions.DependencyInjection.AutofacServiceProvider.GetRequiredService(Type serviceType)
   at Microsoft.AspNetCore.Mvc.Controllers.ControllerFactoryProvider.<>c__DisplayClass6_0.<CreateControllerFactory>g__CreateController|0(ControllerContext controllerContext)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker.InvokeInnerFilterAsync()
--- End of stack trace from previous location ---
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextExceptionFilterAsync>g__Awaited|26_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
2025-11-28 11:21:19.208 +05:00 [ERR] ---------- Exception Data ----------
ActivatorChain = Volo.Abp.Suite.Controllers.CrudPageGeneratorController -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Commands.CrudPageGenerator -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Services.CustomCodeFileNestingService -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Services.TemplateService -> λ:Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.ICodeFormatter -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.CodeFormatter -> Volo.Abp.Suite.Areas.AbpSuite.CrudPageGenerator.Helpers.CodeFormatting.JavascriptPrettierFormatter

And this is what I have in that folder:

I think some DLLs are not packed correctly as Windows x64 version has the missing DLL:

Fixed, Thanks a lot!

I had a wrong configuration for the RemoteService BaseUrl. It was pointing to the API project. The issue was fixed after updating it to the WebApp website's URL.

Hi @maliming! sent you an email with url and credentials.Thanks

I have checked all of this, and everything seems to be configured correctly, but still not working. You can give url of the application to the support team if needed.

Description

Authentication state is lost when Blazor Web App transitions from Server-side rendering to WebAssembly (Interactive Auto render mode) in production environment with Docker + nginx reverse proxy. The issue does NOT occur in development environment.

Environment

  • ABP Framework Version: 9.x (Commercial)
  • .NET Version: 9.0
  • UI Framework: Blazor Web App
  • Render Mode: Interactive Auto (@rendermode="InteractiveAuto")
  • Authentication: OpenIdConnect + Cookie Authentication
  • Deployment: Docker containers behind nginx reverse proxy
  • Data Protection: Redis (shared across containers)
  • Database: PostgreSQL

Project Structure

  • Auth Server: Separate container running OpenIddict
  • Blazor App: Main application with Interactive Auto render mode
  • API: Separate API container
  • All containers use Redis for Data Protection keys
  • nginx reverse proxy handles SSL termination and routing

Steps to Reproduce

  1. Deploy Blazor Web App with Interactive Auto render mode to Docker with nginx reverse proxy
  2. Configure ForwardedHeaders, cookie settings as per ABP documentation
  3. Login successfully (first visit - Server-side rendering works)
  4. Navigate between pages (subsequent visits switch to WebAssembly)
  5. Result: User appears authenticated on first page load, but loses authentication after WebAssembly hydration

Expected Behavior

  • User remains authenticated when transitioning from Server to WebAssembly render mode
  • Authentication state should persist across render mode switches
  • Works correctly in development (IIS Express) Actual Behavior
  • Authentication works on first visit (Server-side)
  • After transition to WebAssembly (on subsequent navigations), authentication is lost
  • User is redirected to login page
  • Cookies appear to be present in browser but not recognized by WebAssembly side

Configuration Details

App.razor

<Routes @rendermode="InteractiveAuto" />
<HeadOutlet @rendermode="InteractiveAuto" />

XxxBlazorModule.cs (Server)

// ConfigureServices
context.Services.Configure<ForwardedHeadersOptions>(options =>
{
    options.ForwardedHeaders = ForwardedHeaders.XForwardedFor | 
                              ForwardedHeaders.XForwardedProto | 
                              ForwardedHeaders.XForwardedHost;
    options.KnownNetworks.Clear();
    options.KnownProxies.Clear();
});

context.Services.AddRazorComponents()
    .AddInteractiveServerComponents()
    .AddInteractiveWebAssemblyComponents();

// Cookie configuration
.AddCookie("Cookies", options =>
{
    options.ExpireTimeSpan = TimeSpan.FromDays(365);
    options.IntrospectAccessToken();
    
    if (!hostingEnvironment.IsDevelopment())
    {
        options.Cookie.SameSite = SameSiteMode.Lax;
        options.Cookie.SecurePolicy = CookieSecurePolicy.Always;
        options.Cookie.HttpOnly = true;
    }
})

// OnApplicationInitialization
if (!env.IsDevelopment())
{
    app.UseForwardedHeaders();
}

XxxBlazorClientModule.cs (WebAssembly)

private static void ConfigureAuthentication(WebAssemblyHostBuilder builder)
{
    builder.Services.AddBlazorWebAppServices();
}

nginx Configuration

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header Host $host;

What We've Tried

  1. ✅ Added AddAuthenticationStateSerialization() on server (didn't help)
  2. ✅ Configured ForwardedHeaders properly
  3. ✅ Set cookie SameSite=Lax and SecurePolicy=Always
  4. ✅ Verified Redis Data Protection is working (keys are shared)
  5. ✅ Configured nginx to forward all required headers
  6. ✅ Set OIDC correlation and nonce cookies to Lax/Always
  7. ✅ Verified cookies are present in browser DevTools
  8. ✅ Cleared browser cache/cookies multiple times

Questions

  1. Does ABP's Interactive Auto mode require additional configuration for production beyond what's documented?
  2. Is there a special authentication state provider needed for Docker + nginx scenarios?
  3. Should AddAuthenticationStateSerialization() be used for ABP's OpenIdConnect setup?
  4. Are there any known issues with cookie-based authentication in Interactive Auto mode behind reverse proxy?

Additional Context

  • The exact same code works perfectly in development (localhost with IIS Express)
  • Issue only occurs in production with Docker + nginx
  • ABP Framework's template uses AddBlazorWebAppServices() on client side
  • Server uses standard ABP OpenIdConnect configuration with cookie authentication Related Documentation
  • ABP Blazor Web App Documentation
  • Microsoft: Blazor Web App Authentication

Request

Please provide guidance on:

  1. Proper authentication state management for Interactive Auto mode in production
  2. Any ABP-specific configuration required for Docker + nginx deployments
  3. Whether authentication state serialization is needed/recommended for ABP's OpenIdConnect setup
  4. Any known workarounds or best practices for this scenario

Ok, thanks for the clarification. Am I right to think that startup templates don't change on patch releases (like in my case, between 9.1.1 and 9.1.3), so I can just update ABP packages and keep other files as is?

I have a strange problem, when I try to create a new project, it always uses version 9.1.1, but the current latest version is 9.1.3 Also tried to specify version with -v 9.1.3 and --version 9.1.3 with no luck. Also tried to uninstall and reinstall cli, still the same result. Also tried to create a project with ABP Studio, still the same result.

Is there an option to specify a version? Or how to force CLI/Studio to use the latest template version?

I get an error when trying to open a Docs Project with a FileSystem document source

Volo.Abp.AbpException: Missing path parameter value for version (version)
   at Volo.Abp.Http.Client.ClientProxying.ClientProxyUrlBuilder.ReplacePathVariablesAsync(StringBuilder urlBuilder, ActionApiDescriptionModel action, IReadOnlyDictionary`2 methodArguments, ApiVersionInfo apiVersion)
   at Volo.Abp.Http.Client.ClientProxying.ClientProxyUrlBuilder.GenerateUrlWithParametersAsync(ActionApiDescriptionModel action, IReadOnlyDictionary`2 methodArguments, ApiVersionInfo apiVersion)
   at Volo.Abp.Http.Client.ClientProxying.ClientProxyBase`1.GetUrlWithParametersAsync(ClientProxyRequestContext requestContext, ApiVersionInfo apiVersion)
   at Volo.Abp.Http.Client.ClientProxying.ClientProxyBase`1.RequestAsync(ClientProxyRequestContext requestContext)
   at Volo.Abp.Http.Client.ClientProxying.ClientProxyBase`1.RequestAsync[T](ClientProxyRequestContext requestContext)
   at Volo.Abp.Http.Client.ClientProxying.ClientProxyBase`1.RequestAsync[T](String methodName, ClientProxyRequestTypeValue arguments)
   at Volo.Docs.Projects.DocsProjectClientProxy.GetLanguageListAsync(String shortName, String version)
   at Volo.Docs.Pages.Documents.Project.IndexModel.SetLanguageList()
   at Volo.Docs.Pages.Documents.Project.IndexModel.SetPageAsync()
   at Volo.Docs.Pages.Documents.Project.IndexModel.OnGetAsync()
   at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.ExecutorFactory.GenericTaskHandlerMethod.Convert[T](Object taskAsObject)
   at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.ExecutorFactory.GenericTaskHandlerMethod.Execute(Object receiver, Object[] arguments)
   at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.InvokeHandlerMethodAsync()
   at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.InvokeNextPageFilterAsync()
   at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.Rethrow(PageHandlerExecutedContext context)
   at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
   at Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker.InvokeInnerFilterAsync()
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextExceptionFilterAsync>g__Awaited|26_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ExceptionContextSealed context)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResourceFilter>g__Awaited|25_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResourceExecutedContextSealed context)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeFilterPipelineAsync>g__Awaited|20_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
   at Microsoft.AspNetCore.Routing.EndpointMiddleware.<Invoke>g__AwaitRequestTask|7_0(Endpoint endpoint, Task requestTask, ILogger logger)
   at Volo.Abp.AspNetCore.Serilog.AbpSerilogMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
   at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context)
   at Volo.Abp.AspNetCore.Security.Claims.AbpDynamicClaimsMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
   at Volo.Abp.AspNetCore.MultiTenancy.MultiTenancyMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
   at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)
   at Volo.Abp.AspNetCore.Security.AbpSecurityHeadersMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
   at Microsoft.AspNetCore.Routing.EndpointRoutingMiddleware.<Invoke>g__AwaitMatch|10_1(EndpointRoutingMiddleware middleware, HttpContext httpContext, Task matchTask)
   at Volo.Abp.Studio.Client.AspNetCore.AbpStudioMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Volo.Abp.Studio.Client.AspNetCore.AbpStudioMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Volo.Abp.Studio.Client.AspNetCore.AbpStudioMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
   at Microsoft.AspNetCore.Localization.RequestLocalizationMiddleware.Invoke(HttpContext context)
   at Microsoft.AspNetCore.RequestLocalization.AbpRequestLocalizationMiddleware.InvokeAsync(HttpContext context, RequestDelegate next)
   at Microsoft.AspNetCore.Builder.UseMiddlewareExtensions.InterfaceMiddlewareBinder.<>c__DisplayClass2_0.<<CreateMiddleware>b__0>d.MoveNext()
--- End of stack trace from previous location ---
   at Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddlewareImpl.Invoke(HttpContext context)

As I understand this happens because of the fact that project actually has no versions, so the call to Volo.Docs.Projects.DocsProjectClientProxy.GetLanguageListAsync(String shortName, String version) fails as no version is passed to this endpoint.

Steps to reproduce:

  • Create a new project with the provided solution info configuration,
  • and then import module Volo.Docs, install module, install Volo.Docs.Web package to Payhas.Billing.Web.Public
  • configure menu, and add project to the database

Example Projects

| Id | Name | ShortName | Format | DefaultDocumentName | NavigationDocumentName | ParametersDocumentName | MinimumVersion | DocumentStoreType | MainWebsiteUrl | LatestVersionBranchName | ExtraProperties | ConcurrencyStamp | | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | | 3a19c703-4cbc-fee6-4dd3-694aeec0db13 | Management (Technical) | management | md | index | docs-nav.json | docs-params.json | 2.0 | FileSystem | /Documents | null | {"Path":"D:\\dev\\Payhas\\Billing-v2\\docs\\technical\\management"} | 28d64b1dfffb472ebd707a8d1f35a3b3 | | 3a19c703-4cbb-0e40-fd67-6c052e0d9de2 | Internet (Technical) | internet | md | index | docs-nav.json | docs-params.json | 2.0 | FileSystem | /Documents | null | {"Path":"D:\\dev\\Payhas\\Billing-v2\\docs\\technical\\internet"} | 1726fa5c79194a0bb6a8129fad683c2b | | 3a19c703-4ca8-2fe3-3d5d-146a989e60ab | Common (Technical) | common | md | index | docs-nav.json | docs-params.json | 2.0 | FileSystem | /Documents | null | {"Path":"D:\\dev\\Payhas\\Billing-v2\\docs\\technical\\common"} | 91fa0ff35d6b425dae701efd32ed6d87 |

Solution info:

  • Template: app

  • Created ABP Studio Version: 0.9.26

  • Current ABP Studio Version: 0.9.26

  • Tiered: Yes

  • Multi-Tenancy: Yes

  • UI Framework: blazor

  • Theme: leptonx

  • Theme Style: system

  • Theme Menu Placement: side

  • Run Install Libs: No

  • Run Bundling: No

  • Progressive Web App: Yes

  • Run Progressive Web App Support: Yes

  • Database Provider: ef

  • Database Management System: postgresql

  • Separate Tenant Schema: No

  • Create Initial Migration: No

  • Run Db Migrator: No

  • Mobile Framework: maui

  • Public Website: Yes

  • Social Login: Yes

  • Include Tests: Yes

  • Kubernetes Configuration: Yes

  • Distributed Event Bus: none

  • Use Local References: No

  • Optional Modules:

    • GDPR
    • TextTemplateManagement
    • LanguageManagement * LanguageManagement
    • AuditLogging
    • OpenIddictAdmin
  • Create Command: abp new Payhas.Billing -t app --tiered --ui-framework blazor --mobile maui --database-provider ef --database-management-system postgresql --theme leptonx --skip-migration --skip-migrator --public-website --without-cms-kit --dont-run-install-libs --dont-run-bundling -no-file-management

Showing 1 to 10 of 14 entries
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on October 05, 2026, 11:32
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.