Base solution for your next web application
Open Closed

Trying to secure MVC page with Standard [AbpAuthorize] #12446


User avatar
0
klpattison created

I would like to have some MVC pages served from the backend for reporting and a few popup windows but I can't get [AbpAuthorize] to work with them.

without the [AbpAuthorize] in the code the MVC page will load.

But when I add [AbpAuthorize("Admin")] or [[AbpAuthorize] it is redirecting to a login page that doesn't exist.

I can see the token is set in the cookie on both the client and server side and I am using HTTPS on both sides.

I understood there is supposed to be a middleware app.UseJwtTokenMiddleware(); that can take the cookie and make it part of the header automatically for MVC pages but it doesn't appear to work.

Any help would be appreciated.

Thanks,

Kevin

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

1 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @klpattison

    If you are using MVC Controllers, try using the [AbpMvcAuthorize] attribute instead of [AbpAuthorize]:

    using Abp.AspNetCore.Mvc.Authorization;
    
    [AbpMvcAuthorize("Pages.Report")]
    public class ReportController : MyProjectControllerBase
    {
        public IActionResult Index()
        {
            return View();
        }
    }
    

    The [AbpAuthorize] attribute is generally more suitable for Application Services. For MVC Controllers, you should use [AbpMvcAuthorize].

    This change should resolve your issue. Please let me know if you require any further assistance.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)