Hi,
I am facing few warnings in the log file frequently and randomly it get visible on UI as well. Could you please help me figure out the root cause of this issue.
WARN 2025-08-02 00:57:54,653 [orker] Mvc.Authorization.AbpAuthorizationFilter - Abp.Authorization.AbpAuthorizationException: Required permissions are not granted. At least one of these permissions must be granted: Dashboard
at Abp.Authorization.PermissionCheckerExtensions.AuthorizeAsync(IPermissionChecker permissionChecker, Boolean requireAll, String[] permissionNames)
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)
Abp.Authorization.AbpAuthorizationException: Required permissions are not granted. At least one of these permissions must be granted: Dashboard
at Abp.Authorization.PermissionCheckerExtensions.AuthorizeAsync(IPermissionChecker permissionChecker, Boolean requireAll, String[] permissionNames)
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)
WARN 2025-02-03 18:22:51,519 [orker] Mvc.Authorization.AbpAuthorizationFilter - Abp.Authorization.AbpAuthorizationException: Current user did not login to the application!
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)
Abp.Authorization.AbpAuthorizationException: Current user did not login to the application!
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)
ERROR 2025-07-25 16:10:42,939 [orker] nostics.DeveloperExceptionPageMiddleware - An unhandled exception has occurred while executing the request.
Abp.Authorization.AbpAuthorizationException: Current user did not login to the application!
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
at Abp.Authorization.AuthorizationInterceptor.InternalInterceptAsynchronous[TResult](IInvocation invocation)
at CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox.AppActiveUserDelegationsComboboxViewComponent.<>c__DisplayClass4_0.<<InvokeAsync>b__0>d.MoveNext() in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Shared\Components\AppActiveUserDelegationsCombobox\AppActiveUserDelegationsComboboxViewComponent.cs:line 33
--- End of stack trace from previous location ---
at Abp.Domain.Uow.UnitOfWorkManagerExtensions.WithUnitOfWorkAsync[TResult](IUnitOfWorkManager manager, Func`1 action, UnitOfWorkOptions options)
at CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox.AppActiveUserDelegationsComboboxViewComponent.InvokeAsync(String logoSkin, String logoClass, String cssClass) in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Shared\Components\AppActiveUserDelegationsCombobox\AppActiveUserDelegationsComboboxViewComponent.cs:line 31
at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsyncCore(ObjectMethodExecutor executor, Object component, ViewComponentContext context)
at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsync(ViewComponentContext context)
at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsync(ViewComponentContext context)
at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentHelper.InvokeCoreAsync(ViewComponentDescriptor descriptor, Object arguments)
at AspNetCore.Areas_App_Views_Layout_default__Layout.ExecuteAsync() in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Layout\default\_Layout.cshtml:line 76
at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderPageCoreAsync(IRazorPage page, ViewContext context)
at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderPageAsync(IRazorPage page, ViewContext context, Boolean invokeViewStarts)
at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderLayoutAsync(ViewContext context, ViewBufferTextWriter bodyWriter)
at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderAsync(ViewContext context)
at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ViewContext viewContext, String contentType, Nullable`1 statusCode)
at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ViewContext viewContext, String contentType, Nullable`1 statusCode)
at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ActionContext actionContext, IView view, ViewDataDictionary viewData, ITempDataDictionary tempData, String contentType, Nullable`1 statusCode)
at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewResultExecutor.ExecuteAsync(ActionContext context, ViewResult result)
at Microsoft.AspNetCore.Mvc.ViewResult.ExecuteResultAsync(ActionContext context)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResultFilterAsync>g__Awaited|30_0[TFilter,TFilterAsync](ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResultExecutedContextSealed context)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.ResultNext[TFilter,TFilterAsync](State& next, Scope& scope, Object& state, Boolean& isCompleted)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.InvokeResultFilters()
--- End of stack trace from previous location ---
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResourceFilter>g__Awaited|25_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResourceExecutedContextSealed context)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeFilterPipelineAsync>g__Awaited|20_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
at Microsoft.AspNetCore.Routing.EndpointMiddleware.<Invoke>g__AwaitRequestTask|7_0(Endpoint endpoint, Task requestTask, ILogger logger)
at Microsoft.AspNetCore.Localization.RequestLocalizationMiddleware.Invoke(HttpContext context)
at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context)
at CDP.Web.Startup.AuthConfigurers.Auth0JwtMiddleware.InvokeAsync(HttpContext context) in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Startup\AuthConfigurers\Auth0JwtMiddleware.cs:line 33
at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)
at Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddlewareImpl.Invoke(HttpContext context)
Below is the code of AppActiveUserDelegationsComboboxViewComponent.cs
using System.Threading.Tasks;
using Abp.Domain.Uow;
using JetBrains.Annotations;
using Microsoft.AspNetCore.Mvc;
using CDP.Authorization.Delegation;
using CDP.Authorization.Users.Delegation;
using CDP.Web.Areas.App.Models.Layout;
using CDP.Web.Views;
namespace CDP.Web.Areas.App.Views.Shared.Components.
AppActiveUserDelegationsCombobox
{
public class AppActiveUserDelegationsComboboxViewComponent : CDPViewComponent
{
private readonly IUserDelegationAppService _userDelegationAppService;
private readonly IUserDelegationConfiguration _userDelegationConfiguration;
private readonly IUnitOfWorkManager _unitOfWorkManager;
public AppActiveUserDelegationsComboboxViewComponent(
IUserDelegationAppService userDelegationAppService,
IUserDelegationConfiguration userDelegationConfiguration,
IUnitOfWorkManager unitOfWorkManager)
{
_userDelegationAppService = userDelegationAppService;
_userDelegationConfiguration = userDelegationConfiguration;
_unitOfWorkManager = unitOfWorkManager;
}
public async Task<IViewComponentResult> InvokeAsync(string logoSkin = null, string logoClass = "", string cssClass = "d-flex align-items-center ms-1 ms-lg-3 active-user-delegations me-2")
{
return await _unitOfWorkManager.WithUnitOfWorkAsync(async () =>
{
var activeUserDelegations = await _userDelegationAppService.GetActiveUserDelegations();
var model = new ActiveUserDelegationsComboboxViewModel
{
UserDelegations = activeUserDelegations,
UserDelegationConfiguration = _userDelegationConfiguration,
CssClass = cssClass
};
return View(model);
});
}
}
}
5 Answer(s)
-
0
The
UserDelegationAppServicerequires authentication: The class has[AbpAuthorize]attribute, meaning ALL methods require the user to be logged in.[AbpAuthorize] public class UserDelegationAppService : AbpZeroTemplateAppServiceBase, IUserDelegationAppServiceThe ViewComponent doesn't check authentication: The
AppActiveUserDelegationsComboboxViewComponentis being rendered in your layout, which can be called even when:- The user is not logged in
- The user's session has expired
- A user is accessing public/anonymous pages
- A user doesn't have the required permissions
GetActiveUserDelegations()usesAbpSession.GetUserId(): This will throw an exception if the user is not authenticated:public async Task<List<UserDelegationDto>> GetActiveUserDelegations() { var query = CreateActiveUserDelegationsQuery(AbpSession.GetUserId(), "username"); query = query.Where(e => e.StartTime <= Clock.Now && e.EndTime >= Clock.Now); return await query.ToListAsync(); }Modify your
AppActiveUserDelegationsComboboxViewComponent.csto check if the user is authenticated before calling the service:using System.Threading.Tasks; using Abp.Domain.Uow; using JetBrains.Annotations; using Microsoft.AspNetCore.Mvc; using CDP.Authorization.Delegation; using CDP.Authorization.Users.Delegation; using CDP.Web.Areas.App.Models.Layout; using CDP.Web.Views; using System.Collections.Generic; namespace CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox { public class AppActiveUserDelegationsComboboxViewComponent : CDPViewComponent { private readonly IUserDelegationAppService _userDelegationAppService; private readonly IUserDelegationConfiguration _userDelegationConfiguration; private readonly IUnitOfWorkManager _unitOfWorkManager; public AppActiveUserDelegationsComboboxViewComponent( IUserDelegationAppService userDelegationAppService, IUserDelegationConfiguration userDelegationConfiguration, IUnitOfWorkManager unitOfWorkManager) { _userDelegationAppService = userDelegationAppService; _userDelegationConfiguration = userDelegationConfiguration; _unitOfWorkManager = unitOfWorkManager; } public async Task<IViewComponentResult> InvokeAsync(string logoSkin = null, string logoClass = "", string cssClass = "d-flex align-items-center ms-1 ms-lg-3 active-user-delegations me-2") { // Check if user is authenticated before calling the service if (!AbpSession.UserId.HasValue) { // Return empty model or empty view if user is not logged in var emptyModel = new ActiveUserDelegationsComboboxViewModel { UserDelegations = new List<UserDelegationDto>(), UserDelegationConfiguration = _userDelegationConfiguration, CssClass = cssClass }; return View(emptyModel); } return await _unitOfWorkManager.WithUnitOfWorkAsync(async () => { var activeUserDelegations = await _userDelegationAppService.GetActiveUserDelegations(); var model = new ActiveUserDelegationsComboboxViewModel { UserDelegations = activeUserDelegations, UserDelegationConfiguration = _userDelegationConfiguration, CssClass = cssClass }; return View(model); }); } } }Alternatively, you can modify your layout file to only render the component when the user is authenticated.
@if (User.Identity.IsAuthenticated) { @await Component.InvokeAsync("AppActiveUserDelegationsCombobox", new { cssClass = "d-flex align-items-center ms-1 ms-lg-3 active-user-delegations me-2" }) }Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[oguzhanagir] said: AppActiveUserDelegationsComboboxViewComponent
I will verify your suggestions. But what about the first two warnings, are they two due this AppActiveUserDelegationsComboboxViewComponent class? Or will they also get fixed with the mentioned corrections
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
The first two warnings are not directly caused by the
AppActiveUserDelegationsComboboxViewComponentitself, but they occur for similar reasons. When an unauthenticated or unauthorized user accesses a component, controller, or view that requires permissions.Once you apply the suggested fix (checking authentication before invoking the service or rendering the component), those warnings should also stop appearing, as the same root cause unauthorized access will be handled properly.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
[oguzhanagir] said: Hi @kansoftware
The first two warnings are not directly caused by the
AppActiveUserDelegationsComboboxViewComponentitself, but they occur for similar reasons. When an unauthenticated or unauthorized user accesses a component, controller, or view that requires permissions.Once you apply the suggested fix (checking authentication before invoking the service or rendering the component), those warnings should also stop appearing, as the same root cause unauthorized access will be handled properly.
Hey, I am still facing the warnings. We have identified the cause of the Required Permission issue. Randomly the role id getting set in the AbpZeroUserPermissions cache is wrong and due to that reason the permission getting cached in AbpZeroRolePermissions is wrong. Is there something which can cause this?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @kansoftware
Sorry for the late reply. We haven't been able to replicate this on our end. Could you please email us the steps or your project to [email protected] so we can provide a more specific answer to your issue.
Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)