I want to enable both okta and auth0 for a single tenant as some users may login through okta and some through auth0. I am having a multitenant application. Do I need to custom the code or there is a functionality in the base code. Could you please help me out how can I achieve that
145 Answer(s)
-
0
hi
Can you find a way to reproduce it locally?
Then I will know the actual cause.
Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: hi
Can you find a way to reproduce it locally?
Then I will know the actual cause.
Thanks.
Even I am not able to replicate. Though I have added IgnoreAntiforgeryToken above function public virtual async Task<ActionResult> ExternalLoginCallbackV2
Is that seems ok for the issue I am facing?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
hi
There’s no problem with using IgnoreAntiforgeryToken.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: hi
There’s no problem with using IgnoreAntiforgeryToken.
It didn’t work.
You suggested adding the code in Startup of CDP.Web.Host, but instead I added it in Startup of CDP.Web.Mvc. Will this fix the issue, or does it need to be added in CDP.Web.Host only?
context.Services.AddRazorPages(options => { options.Conventions.AddPageApplicationModelConvention("/Account/Login", model => { model.Filters.Add(new IgnoreAntiforgeryTokenAttribute()); }); });
Also will this piece works for /signin-oidc
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
hi
You can add to any project that you want to disable Antiforgey.
Also will this piece works for /signin-oidc
It only works for
/Account/Loginpage. butsignin-oidcwill not check theAntiforgeyThanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: hi
You can add to any project that you want to disable Antiforgey.
Also will this piece works for /signin-oidc
It only works for
/Account/Loginpage. butsignin-oidcwill not check theAntiforgeyThanks.
Sorry, I am little confused now. Actually I am getting error on page - qa.fyndev.com/signin-oidc after login through openid. Now to avoid this the code you suggested the code which has page Account/Login, how it will fix this on signin-odic page?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
hi
Can you share the full logs? Include HTTP requests.
Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: hi
Can you share the full logs? Include HTTP requests.
Thanks.
I have shared the file over email
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
hi
The logs you shared don't contain the
HTTP requests? Which means I can't see the wrong HTTP request.Can you share the full logs?
Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
-
0
-
0
ok. : )
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: ok. : )
This solution also did not work. Also I am facing below few warnings in log.txt file, why this is so?
WARN 2025-08-02 00:57:54,653 [orker] Mvc.Authorization.AbpAuthorizationFilter - Abp.Authorization.AbpAuthorizationException: Required permissions are not granted. At least one of these permissions must be granted: Dashboard at Abp.Authorization.PermissionCheckerExtensions.AuthorizeAsync(IPermissionChecker permissionChecker, Boolean requireAll, String[] permissionNames) at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes) at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type) at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type) at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context) Abp.Authorization.AbpAuthorizationException: Required permissions are not granted. At least one of these permissions must be granted: Dashboard at Abp.Authorization.PermissionCheckerExtensions.AuthorizeAsync(IPermissionChecker permissionChecker, Boolean requireAll, String[] permissionNames) at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes) at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type) at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type) at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)WARN 2025-02-03 18:22:51,519 [orker] Mvc.Authorization.AbpAuthorizationFilter - Abp.Authorization.AbpAuthorizationException: Current user did not login to the application! at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes) at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type) at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type) at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context) Abp.Authorization.AbpAuthorizationException: Current user did not login to the application! at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes) at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type) at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type) at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)ERROR 2025-07-25 16:10:42,939 [orker] nostics.DeveloperExceptionPageMiddleware - An unhandled exception has occurred while executing the request. Abp.Authorization.AbpAuthorizationException: Current user did not login to the application! at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes) at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type) at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type) at Abp.Authorization.AuthorizationInterceptor.InternalInterceptAsynchronous[TResult](IInvocation invocation) at CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox.AppActiveUserDelegationsComboboxViewComponent.<>c__DisplayClass4_0.<<InvokeAsync>b__0>d.MoveNext() in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Shared\Components\AppActiveUserDelegationsCombobox\AppActiveUserDelegationsComboboxViewComponent.cs:line 33 --- End of stack trace from previous location --- at Abp.Domain.Uow.UnitOfWorkManagerExtensions.WithUnitOfWorkAsync[TResult](IUnitOfWorkManager manager, Func`1 action, UnitOfWorkOptions options) at CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox.AppActiveUserDelegationsComboboxViewComponent.InvokeAsync(String logoSkin, String logoClass, String cssClass) in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Shared\Components\AppActiveUserDelegationsCombobox\AppActiveUserDelegationsComboboxViewComponent.cs:line 31 at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsyncCore(ObjectMethodExecutor executor, Object component, ViewComponentContext context) at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsync(ViewComponentContext context) at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsync(ViewComponentContext context) at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentHelper.InvokeCoreAsync(ViewComponentDescriptor descriptor, Object arguments) at AspNetCore.Areas_App_Views_Layout_default__Layout.ExecuteAsync() in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Layout\default\_Layout.cshtml:line 76 at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderPageCoreAsync(IRazorPage page, ViewContext context) at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderPageAsync(IRazorPage page, ViewContext context, Boolean invokeViewStarts) at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderLayoutAsync(ViewContext context, ViewBufferTextWriter bodyWriter) at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderAsync(ViewContext context) at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ViewContext viewContext, String contentType, Nullable`1 statusCode) at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ViewContext viewContext, String contentType, Nullable`1 statusCode) at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ActionContext actionContext, IView view, ViewDataDictionary viewData, ITempDataDictionary tempData, String contentType, Nullable`1 statusCode) at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewResultExecutor.ExecuteAsync(ActionContext context, ViewResult result) at Microsoft.AspNetCore.Mvc.ViewResult.ExecuteResultAsync(ActionContext context) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResultFilterAsync>g__Awaited|30_0[TFilter,TFilterAsync](ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResultExecutedContextSealed context) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.ResultNext[TFilter,TFilterAsync](State& next, Scope& scope, Object& state, Boolean& isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.InvokeResultFilters() --- End of stack trace from previous location --- at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResourceFilter>g__Awaited|25_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResourceExecutedContextSealed context) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeFilterPipelineAsync>g__Awaited|20_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker) at Microsoft.AspNetCore.Routing.EndpointMiddleware.<Invoke>g__AwaitRequestTask|7_0(Endpoint endpoint, Task requestTask, ILogger logger) at Microsoft.AspNetCore.Localization.RequestLocalizationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context) at CDP.Web.Startup.AuthConfigurers.Auth0JwtMiddleware.InvokeAsync(HttpContext context) in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Startup\AuthConfigurers\Auth0JwtMiddleware.cs:line 33 at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddlewareImpl.Invoke(HttpContext context)Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
hi
This is a new problem. Can you create a new question and share the
log.txtand code ofAppActiveUserDelegationsComboboxViewComponent?Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: AppActiveUserDelegationsComboboxViewComponent
Here it is - https://support.aspnetzero.com/QA/Questions/12565/Random-Errors---Current-User-did-not-login-to-the-application-And-Requested-Permission-is-not-granted
But what about the signin-oidc error, still we are facing this randomly.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
hi
But what about the signin-oidc error, still we are facing this randomly.
What is the error? Still
AntiforgeryValidationException?Can you share the full logs?
Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: hi
But what about the signin-oidc error, still we are facing this randomly.
What is the error? Still
AntiforgeryValidationException?Can you share the full logs?
Thanks.
ERROR 2025-10-28 07:01:07,523 [169 ] e.Diagnostics.ExceptionHandlerMiddleware - An unhandled exception has occurred while executing the request. Microsoft.AspNetCore.Authentication.AuthenticationFailureException: An error was encountered while handling the remote login. ---> Microsoft.AspNetCore.Authentication.AuthenticationFailureException: Correlation failed. --- End of inner exception stack trace --- at Microsoft.AspNetCore.Authentication.RemoteAuthenticationHandler`1.HandleRequestAsync() at CDP.Web.Authentication.OpenIdConnect.AbpOpenIdConnectHandler.HandleRequestAsync() in /home/ec2-user/actions-runner/_work/web/web/src/CDP.Web.Mvc/Startup/AuthConfigurers/OpenIdConnect/AbpOpenIdConnectHandler.cs:line 136 at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context) at StackExchange.Profiling.MiniProfilerMiddleware.Invoke(HttpContext context) in C:\projects\dotnet\src\MiniProfiler.AspNetCore\MiniProfilerMiddleware.cs:line 94 at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddlewareImpl.
using System; using System.Collections.Concurrent; using System.Collections.Generic; using System.Linq; using System.Reflection; using System.Text.Encodings.Web; using System.Threading.Tasks; using Abp.Collections.Extensions; using Abp.Dependency; using Abp.Domain.Uow; using Abp.Extensions; using Abp.Runtime.Session; using CDP.Configuration; using CDP.Web.Startup.AuthConfigurers; using CDP.Web.Startup.AuthConfigurers.OpenIdConnect; using JetBrains.Annotations; using Microsoft.AspNetCore.Authentication; using Microsoft.AspNetCore.Authentication.OpenIdConnect; using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.Logging; using Microsoft.Extensions.Options; using Microsoft.IdentityModel.Protocols; using Microsoft.IdentityModel.Protocols.OpenIdConnect; namespace CDP.Web.Authentication.OpenIdConnect; public class AbpOpenIdConnectHandler : OpenIdConnectHandler { public IAbpSession AbpSession { get; set; } public AbpOpenIdConnectHandler([NotNull] [ItemNotNull] IOptionsMonitor<OpenIdConnectOptions> options, [NotNull] ILoggerFactory logger, [NotNull] HtmlEncoder htmlEncoder, [NotNull] UrlEncoder encoder, [NotNull] ISystemClock clock, IAbpSession abpSession, IAppConfigurationAccessor configurationAccessor ) : base(options, logger, htmlEncoder, encoder, clock) { AbpSession = abpSession; } public AbpOpenIdConnectHandler([NotNull] [ItemNotNull] IOptionsMonitor<OpenIdConnectOptions> options, [NotNull] ILoggerFactory logger, [NotNull] HtmlEncoder htmlEncoder, [NotNull] UrlEncoder encoder, IAbpSession abpSession , IAppConfigurationAccessor configurationAccessor) : base( options, logger, htmlEncoder, encoder) { AbpSession = abpSession; } protected override async Task HandleChallengeAsync(AuthenticationProperties properties) { await TryAddTenantInfoAsync(properties); await base.HandleChallengeAsync(properties); } protected override async Task HandleForbiddenAsync(AuthenticationProperties properties) { await TryAddTenantInfoAsync(properties); await base.HandleForbiddenAsync(properties); } public override async Task<bool> HandleRequestAsync() { int? tenantId = null; var properties = await GetAuthenticationPropertiesOrNullAsync(); if (properties == null) { return false; } var scheme = properties.Items["zero_scheme"]; tenantId = properties.Items["TenantId"].To<int>(); var auth0ClientId = properties.Items["Auth0ClientId"]; var auth0Secret = properties.Items["Auth0Secret"]; var auth0Domain = properties.Items["Auth0Domain"]; var auth0Organization = properties.Items["Auth0Organization"]; var auth0Connection = properties.Items["Auth0Connection"]; var openIdConnectOptions = Context.RequestServices.GetRequiredService<IOptionsMonitor<OpenIdConnectOptions>>(); var options = openIdConnectOptions.Get("OpenIdConnect"); var clientId = ""; var secretKey =""; var authority = ""; var connection = ""; var organization = ""; var iocResolver = Context.RequestServices.GetRequiredService<IIocResolver>(); using (var scope = iocResolver.CreateScope()) { var uowManager = scope.Resolve<IUnitOfWorkManager>(); using (var uow = uowManager.Begin()) { await uow.CompleteAsync(); clientId = auth0ClientId; secretKey = auth0Secret; authority = "https://" + auth0Domain; connection = auth0Connection; organization = auth0Organization; } } options.ClientId = clientId; options.ClientSecret = secretKey; options.Authority = authority; options.MetadataAddress = authority + "/.well-known/openid-configuration"; options.ResponseType = "code"; options.Scope.Clear(); options.Scope.Add("openid"); options.Scope.Add("profile"); options.Scope.Add("email"); options.ConfigurationManager = new ConfigurationManager<OpenIdConnectConfiguration>(options.MetadataAddress, new OpenIdConnectConfigurationRetriever(), new HttpDocumentRetriever(options.Backchannel) { RequireHttps = options.RequireHttpsMetadata }) { RefreshInterval = options.RefreshInterval, AutomaticRefreshInterval = options.AutomaticRefreshInterval, }; options.Events.OnRedirectToIdentityProvider = context => { if (!string.IsNullOrEmpty(connection)) context.ProtocolMessage.SetParameter("connection", connection); if (!string.IsNullOrEmpty(organization)) context.ProtocolMessage.SetParameter("organization", organization); context.ProtocolMessage.RedirectUri = $"https://{context.Request.Host}/signin-oidc"; return Task.CompletedTask; }; using (openIdConnectOptions.As<TenantBasedOpenIdConnectOptions>().Change(options)) { var authenticationHandlerProvider = Context.RequestServices.GetRequiredService<IAuthenticationHandlerProvider>().As<MyOpenIdAuthenticationHandlerProvider>(); authenticationHandlerProvider.HandlerMap.Remove("OpenIdConnect"); return await base.HandleRequestAsync(); } } protected virtual Task TryAddTenantInfoAsync(AuthenticationProperties properties) { if (AbpSession.TenantId.HasValue) { properties?.Items.TryAdd("TenantId", AbpSession.TenantId?.ToString()); } return Task.CompletedTask; } protected virtual async Task<AuthenticationProperties> GetAuthenticationPropertiesOrNullAsync() { var state = Context.Request.Query["state"]; if (state.IsNullOrEmpty() && Context.Request.HasFormContentType) { var formCollection = await Context.Request.ReadFormAsync(); state = formCollection["state"]; } if (state.IsNullOrEmpty()) { return null; } try { var secureDataFormat = await GetSecureDataFormatOrNullAsync(); if (secureDataFormat == null) { return null; } var authenticationProperties = secureDataFormat.Unprotect(state); if (authenticationProperties == null) { return null; } var tenantId = authenticationProperties.Items.FirstOrDefault(x => x.Key == "TenantId"); if (tenantId.Value.IsNullOrEmpty()) { return null; } authenticationProperties.Items["TenantId"] = tenantId.Value; return authenticationProperties; } catch (Exception e) { Logger.LogWarning(e, "Could not get tenant id from the state."); return null; } } protected readonly ConcurrentDictionary<Type, PropertyInfo> StateDataFormatPropertyInfoCache = new ConcurrentDictionary<Type, PropertyInfo>(); protected virtual Task<ISecureDataFormat<AuthenticationProperties>> GetSecureDataFormatOrNullAsync() { var propertyInfo = StateDataFormatPropertyInfoCache.GetOrAdd(Options.GetType(), type => type.GetProperty("StateDataFormat", BindingFlags.Instance | BindingFlags.Public | BindingFlags.NonPublic)); if (propertyInfo != null) { var secureDataFormat = propertyInfo.GetValue(Options) as ISecureDataFormat<AuthenticationProperties>; return Task.FromResult(secureDataFormat); } return Task.FromResult<ISecureDataFormat<AuthenticationProperties>>(null); } }Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
There should be a warning log before the error log, for example:
{CorrelationProperty} state property not found.'{CorrelationCookieName}' cookie not foundThe correlation cookie value '{CorrelationCookieName}' did not match the expected value '{CorrelationCookieValue}'Can you check which warning log in your case?
Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[maliming] said: There should be a warning log before the error log, for example:
{CorrelationProperty} state property not found.'{CorrelationCookieName}' cookie not foundThe correlation cookie value '{CorrelationCookieName}' did not match the expected value '{CorrelationCookieValue}'Can you check which warning log in your case?
Thanks.
Yes there is a warning WARN 2025-10-28 07:01:07,522 [169 ] on.OpenIdConnect.AbpOpenIdConnectHandler - '.AspNetCore.Correlation.ZcxD6ZeRHEWK5vOgV9OrUo3Dgcor5jo8Uf4ELDQGsqw' cookie not found.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
'.AspNetCore.Correlation.ZcxD6ZeRHEWK5vOgV9OrUo3Dgcor5jo8Uf4ELDQGsqw' cookie not found.
The user's browser may be blocking cookies due to their privacy settings. So you can ignore it, this is not a code problem.
You can try to override the
protected virtual bool ValidateCorrelationId(AuthenticationProperties properties)in yourAbpOpenIdConnectHandlerand add more logs or skip itThanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)
