Activities of "vmquang95"

Thank you so much for the detailed and insightful response!

Hi

Our team is currently building a medical data storage and management application using the ABP Framework. Given the highly sensitive nature of our domain, our data is primarily stored in two locations:

  • Physical Files: Stored via S3 (MinIO).
  • Relational Database: Stored in PostgreSQL.

Core Security Objectives:

  • Data Confidentiality: Ensure absolute security for Personally Identifiable Information (PII) at rest (Data at Rest).
  • Centralized Key Management: Ensure the lifecycle of encryption keys is strictly and securely managed, isolated from the application logic.

To achieve these goals, I would like to ask ABP for advice on the best practices and implementation strategies for data encryption within the ABP ecosystem for the following two issues:


Issue 1: Physical File Encryption (XML Files on S3/MinIO)

Our system currently stores medical records as XML files via S3 (MinIO).

  • ABP Modules/Packages: Does ABP provide any built-in modules, packages, or integrations (e.g., intercepting the BLOB Storing module) that support transparent encryption/decryption of these files before uploading them to S3?
  • Architecture Flow: What should the standard encryption/decryption flow look like to optimize performance?
  • Algorithms: Which encryption algorithms are recommended for this specific use case?
  • Key Management: How should we securely manage, store, and rotate encryption keys for this file system?

Issue 2: Field-Level Data Encryption in PostgreSQL

Our PostgreSQL database contains highly sensitive patient information such as: National ID/Health Insurance Numbers, Full Names, Addresses, Medical History, etc.

  • ABP Support Mechanisms: To what extent does the framework support encrypting these properties? (e.g., using EF Core Value Converters, or does ABP have specific Data Masking/Encryption features?).
  • Tokenization vs. Encryption: What built-in mechanisms does ABP offer regarding Encryption vs. Tokenization? What are the standard algorithms used?
  • Architecture Flow: How does the read/write flow work for encrypted data fields, especially when performing querying/searching operations on them?
  • Key Management: Similar to the file system, how should we set up the management of Master Keys or Data Encryption Keys (DEK) for the database in ABP?

I would greatly appreciate any real-world experience, insights, keywords, or related documentation you could share. Thank you!

Thank you.

I have a project integrated with another system (let’s call it System B). System B is responsible for managing user information and provides us with a sessionCode to identify users. When the sessionCode is valid, System B returns the full user information.

In our project, we plan to use this sessionCode for authentication by passing it through the request header. Technically, we can customize this behavior using Middleware or an ActionFilter to validate the sessionCode.

However, we would still like to leverage ABP’s built-in user context, specifically ICurrentUser, for use in Domain Services and other business logic.

So my question is: Is there a way to customize the authentication mechanism in ABP so that we can validate the sessionCode and still populate ICurrentUser properly?

Thank you.

Thank you.

I’m currently working on a project built with an ABP Microservice architecture, using Angular for the web UI. It has been working very well for the existing system.

Now, we need to develop a Mini App for mobile (essentially a webview embedded an existing mobile application). The project is reusing all existing backend services as the Mini App server.

The main question is about the frontend approach:

  • Reusing the existing Angular UI doesn’t seem suitable because it is not optimized for mobile interfaces.
  • Creating a new Angular project raises questions about how to best leverage existing ABP features and infrastructure while still ensuring a mobile-optimized UI.

What would be the recommended approach in this case to:

  • Reuse as much as possible from ABP (e.g., authentication, API integration, modules, etc.)
  • While building a UI that is properly optimized for mobile (Mini App / WebView context)?

Thank you!

I have built a microservice-based application with multi-tenancy, and it has already been deployed and is running in the Production environment.

Now, I would like to migrate all tenant-related data from the Production environment to a different Test environment. The goal is not to create new tenants, but to reuse the existing tenants from Production with all their original information.

What steps should I take to achieve this?

Thank you.

  • Template: microservice
  • Created ABP Studio Version: 1.3.3
  • Current ABP Studio Version: 2.1.3
  • Multi-Tenancy: Yes
  • UI Framework: blazor-server
  • Theme: leptonx
  • Theme Style: system
  • Theme Menu Placement: side
  • Run Install Libs: Yes
  • Database Provider: ef
  • Database Management System: sqlserver
  • Mobile Framework: none
  • Public Website: No
  • Social Login: Yes
  • Include Tests: Yes
  • Dynamic Localization: Yes
  • Kubernetes Configuration: Yes
  • Grafana Dashboard: Yes
  • Use Local References: No
  • Aspire: No
  • Optional Modules:
    • GDPR
    • FileManagement
    • TextTemplateManagement
    • AuditLogging
    • Chat
    • OpenIddictAdmin
  • Selected Languages: Vietnamese, English
  • Default Language: Vietnamese
  • Create Command: abp new demoKCB -t microservice --ui-framework blazor-server --database-provider ef --database-management-system sqlserver --theme leptonx --skip-migrator --without-cms-kit --dont-run-bundling -no-language-management -chat -file-management

I am deploying an ABP microservice–based project using Docker Compose, and the application encounters an error when running the AuthServer. The application returns an HTTP 500 (Internal Server Error) from the server side. After checking the logs, I found the following error:

  • Exception message and full stack trace:

I have checked the language-related tables in the database, with the following results. I would appreciate any assistance to help resolve this issue so the project can continue as soon as possible

[berkansasmaz] said: We have resolved this issue and will release a new version soon. Until then, you can continue using the previous version to create a new service. Thank you for your understanding.

Thanks.

[maliming] said: hi

I have fixed this in the Studio template; the next version will be no problem.

Thanks.

Thanks.

Showing 1 to 10 of 16 entries
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with ❤️ on ABP v10.8.0-preview. Updated on September 28, 2026, 11:44
1
ABP Assistant
🔐 You need to be logged in to use the chatbot. Please log in first.