We’ve encountered a recurring issue in Power Tools–generated pages when using foreign key lookups to populate related entity data via Get[Entity]ForView APIs. These lookups fail in context because the target entity belongs to another Application Service, and the required permission is not granted by default — or by domain rule should not be granted. In some cases, if the entity is defined as a host-only entity, there is no corresponding permission available at all for tenants.
Example Case: ContentAppService uses LocationAppService On the CreateOrEditContent page, Power Tools generates the following JS snippet:
var selectedEntityId = $('#Content_LocationId');
if (selectedEntityId && selectedEntityId.val()) { abp.ajax({ type: 'GET', url: '/api/services/app/Locations/GetLocationForView', data: { id: selectedEntityId.val() } }).done(function (data) { var option = new Option(data.location.name, data.location.id, true, true); typeaheadLocationId.append(option).trigger('change'); }); } This calls LocationsAppService.GetLocationForView, which is protected by:
[AbpAuthorize(AppPermissions.Pages_Locations)]
However, Content and Location belong to different application services. The current user may have permission for Content, but not for Locations, since:
The permission is defined in another service, and It is not granted by default, or by policy should not be granted to users
🔴 If Location is a host-only entity, there is no way to grant this permission to tenants — resulting in a hard failure.
3 Answer(s)
-
0
Hi @sailoper
Thank you for your feedback. I have created an issue regarding this. You can track the progress here. Best regards.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
By the way i can't reach your github?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @sailoper
After logging in with the user who has the plan on the aspnetzero.com website, clicking the manage button under the Account button, you can give permission to the github user you are trying to log in from the Github Members tab on the relevant page.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)