Base solution for your next web application
Open Closed

Users lose all permissions until permissions cache is cleared #12515


User avatar
0
hra created

Hi,

We have recently upgraded from ANZ (.Net Core + Angular) v10 to v 13.4.0. and the product has been in production for a couple of months. We are receiving periodic reports from users that after logging in, they have no permissions to do anything. They have no side-bar menu, just access to the "notifications" screen. They had no issues just minutes prior.

In each case, I have checked the users account, and I can see they are are privileged enough (sometimes they are actually an Admin) - yet queries to the API endpoint lists no permissions for them. The solution is to clear the AbpZeroUserPermisions cache - immediately the API starts returning their correct permissions.

I have looked into the logs, nothing unusual - but it might correlate with a "Refresh Token is not valid!" warning. Please note, however, that logging out and logging back in to obtain a new token does NOT resolve the issue.

Clearly the cache is somehow involved, but I don't know how. My suspicion is that there has been a change in the way that Caching handles User Permissions (or vice versa), between v10 and v13 - and maybe that change was missed when we ported across all the changes.

Some direction would be appreciated.

Thank you

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

1 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @hra

    Thank you again for the detailed information you've provided. To help us pinpoint the root cause more quickly and accurately, we'd like to ask a few additional questions about your environment and configuration. Your answers will help us understand the conditions under which the problem occurs and will clarify the path to a solution.

    Could you please check the following points?

    • Which caching provider are you using? Is the default In-Memory Cache active in your project, or have you configured a distributed cache mechanism like Redis?

    • If you are using Redis, do you see any warnings in your logs related to Redis connection errors, disruptions, or timeouts?

    • Is your application running behind a load balancer across multiple server instances? If so, are you using "sticky sessions"?

    • Have you made any customizations to the TokenAuthController class, specifically in the Authenticate method or the refresh token logic?

    • Do you have any custom code anywhere in your system that modifies user, role, or permission assignments (e.g., UserRoles, Permissions) directly through an IRepository or DbContext instead of using the provided manager classes (UserManager, RoleManager)? Such code could bypass the cache invalidation mechanism.

    • Is there a common characteristic among the users experiencing the issue? For example, do they all belong to a specific role, or does the problem usually occur within a particular tenant? Do host users (non-tenant users) ever experience this issue?

    • Capturing the moment the issue occurs is critical. Could you provide more detail on the scenario when the "Refresh Token is not valid!" warning is logged? Does this typically happen after a user has been inactive for a long time, or does it occur suddenly during an active session?

    The answers to these questions will significantly speed up the process of finding the root cause. Thank you in advance for providing this information.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)