We have the following AbpAuthorize on an application service which works great:
[AbpAuthorize(AppPermissions.Teams_View)]
public class TeamsAppService : AppServiceBase, ITeamsAppService { }
If you try to enter it without the Teams_View permission or logged out, access is denied.
We have the same on a Manager class within the Core project:
[AbpAuthorize(AppPermissions.Teams_View)]
public class EntitySecurityManager : ITransientDependency { }
This does not work. It lets in users signed out and without the role. Please note we are finding this when unit testing our code. We are calling a method in EntitySecurityManager for a signed out user and expecting the user to be denied access.
Does AbpAuthorize not work in the Core project on Managers?
Thanks
2 Answer(s)
-
0
Hi @Astech
The
[AbpAuthorize]attribute only works automatically on Application Services or directly on Controllers, where the Abp authorization pipeline is active. That means the attribute is effective when Abp is in control of the method invocation, such as via dynamic proxies or through HTTP endpoints.However, in your case, EntitySecurityManager is a regular class in the Core layer and not part of the Abp application service pipeline. As a result, the
[AbpAuthorize]attribute does not have any effect there authorization is not checked when the method is called directly.Recommended Solution: You should perform permission checks manually using
IPermissionChecker. Here's an example:public class EntitySecurityManager : ITransientDependency { private readonly IPermissionChecker _permissionChecker; public EntitySecurityManager(IPermissionChecker permissionChecker) { _permissionChecker = permissionChecker; } public async Task SomeMethodAsync() { if (!await _permissionChecker.IsGrantedAsync(AppPermissions.Teams_View)) { throw new AbpAuthorizationException("You are not authorized to perform this action."); } //... } }This ensures that authorization is enforced even in non-application service classes.
Related Document
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Thank you oguzhanagir! That's really helpful, much appreciated
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)