Base solution for your next web application
Open Closed

Random Errors - Current User did not login to the application And Requested Permission is not granted #12565


User avatar
0
kansoftware created

Hi,

I am facing few warnings in the log file frequently and randomly it get visible on UI as well. Could you please help me figure out the root cause of this issue.

WARN  2025-08-02 00:57:54,653 [orker] Mvc.Authorization.AbpAuthorizationFilter - Abp.Authorization.AbpAuthorizationException: Required permissions are not granted. At least one of these permissions must be granted: Dashboard
   at Abp.Authorization.PermissionCheckerExtensions.AuthorizeAsync(IPermissionChecker permissionChecker, Boolean requireAll, String[] permissionNames)
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
   at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
   at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)
Abp.Authorization.AbpAuthorizationException: Required permissions are not granted. At least one of these permissions must be granted: Dashboard
   at Abp.Authorization.PermissionCheckerExtensions.AuthorizeAsync(IPermissionChecker permissionChecker, Boolean requireAll, String[] permissionNames)
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
   at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
   at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)

WARN  2025-02-03 18:22:51,519 [orker] Mvc.Authorization.AbpAuthorizationFilter - Abp.Authorization.AbpAuthorizationException: Current user did not login to the application!
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
   at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
   at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)
Abp.Authorization.AbpAuthorizationException: Current user did not login to the application!
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
   at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
   at Abp.AspNetCore.Mvc.Authorization.AbpAuthorizationFilter.OnAuthorizationAsync(AuthorizationFilterContext context)

ERROR 2025-07-25 16:10:42,939 [orker] nostics.DeveloperExceptionPageMiddleware - An unhandled exception has occurred while executing the request.
Abp.Authorization.AbpAuthorizationException: Current user did not login to the application!
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(IEnumerable`1 authorizeAttributes)
   at Abp.Authorization.AuthorizationHelper.CheckPermissionsAsync(MethodInfo methodInfo, Type type)
   at Abp.Authorization.AuthorizationHelper.AuthorizeAsync(MethodInfo methodInfo, Type type)
   at Abp.Authorization.AuthorizationInterceptor.InternalInterceptAsynchronous[TResult](IInvocation invocation)
   at CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox.AppActiveUserDelegationsComboboxViewComponent.<>c__DisplayClass4_0.<<InvokeAsync>b__0>d.MoveNext() in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Shared\Components\AppActiveUserDelegationsCombobox\AppActiveUserDelegationsComboboxViewComponent.cs:line 33
--- End of stack trace from previous location ---
   at Abp.Domain.Uow.UnitOfWorkManagerExtensions.WithUnitOfWorkAsync[TResult](IUnitOfWorkManager manager, Func`1 action, UnitOfWorkOptions options)
   at CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox.AppActiveUserDelegationsComboboxViewComponent.InvokeAsync(String logoSkin, String logoClass, String cssClass) in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Shared\Components\AppActiveUserDelegationsCombobox\AppActiveUserDelegationsComboboxViewComponent.cs:line 31
   at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsyncCore(ObjectMethodExecutor executor, Object component, ViewComponentContext context)
   at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsync(ViewComponentContext context)
   at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentInvoker.InvokeAsync(ViewComponentContext context)
   at Microsoft.AspNetCore.Mvc.ViewComponents.DefaultViewComponentHelper.InvokeCoreAsync(ViewComponentDescriptor descriptor, Object arguments)
   at AspNetCore.Areas_App_Views_Layout_default__Layout.ExecuteAsync() in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Areas\App\Views\Layout\default\_Layout.cshtml:line 76
   at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderPageCoreAsync(IRazorPage page, ViewContext context)
   at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderPageAsync(IRazorPage page, ViewContext context, Boolean invokeViewStarts)
   at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderLayoutAsync(ViewContext context, ViewBufferTextWriter bodyWriter)
   at Microsoft.AspNetCore.Mvc.Razor.RazorView.RenderAsync(ViewContext context)
   at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ViewContext viewContext, String contentType, Nullable`1 statusCode)
   at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ViewContext viewContext, String contentType, Nullable`1 statusCode)
   at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewExecutor.ExecuteAsync(ActionContext actionContext, IView view, ViewDataDictionary viewData, ITempDataDictionary tempData, String contentType, Nullable`1 statusCode)
   at Microsoft.AspNetCore.Mvc.ViewFeatures.ViewResultExecutor.ExecuteAsync(ActionContext context, ViewResult result)
   at Microsoft.AspNetCore.Mvc.ViewResult.ExecuteResultAsync(ActionContext context)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResultFilterAsync>g__Awaited|30_0[TFilter,TFilterAsync](ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResultExecutedContextSealed context)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.ResultNext[TFilter,TFilterAsync](State& next, Scope& scope, Object& state, Boolean& isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.InvokeResultFilters()
--- End of stack trace from previous location ---
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeNextResourceFilter>g__Awaited|25_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResourceExecutedContextSealed context)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeFilterPipelineAsync>g__Awaited|20_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
   at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker)
   at Microsoft.AspNetCore.Routing.EndpointMiddleware.<Invoke>g__AwaitRequestTask|7_0(Endpoint endpoint, Task requestTask, ILogger logger)
   at Microsoft.AspNetCore.Localization.RequestLocalizationMiddleware.Invoke(HttpContext context)
   at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context)
   at CDP.Web.Startup.AuthConfigurers.Auth0JwtMiddleware.InvokeAsync(HttpContext context) in D:\Dimple Khathuria\CDP 13.0\src\CDP.Web.Mvc\Startup\AuthConfigurers\Auth0JwtMiddleware.cs:line 33
   at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)
   at Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddlewareImpl.Invoke(HttpContext context)

Below is the code of AppActiveUserDelegationsComboboxViewComponent.cs

using System.Threading.Tasks;
using Abp.Domain.Uow;
using JetBrains.Annotations;
using Microsoft.AspNetCore.Mvc;
using CDP.Authorization.Delegation;
using CDP.Authorization.Users.Delegation;
using CDP.Web.Areas.App.Models.Layout;
using CDP.Web.Views;

namespace CDP.Web.Areas.App.Views.Shared.Components.
    AppActiveUserDelegationsCombobox
{
    public class AppActiveUserDelegationsComboboxViewComponent : CDPViewComponent
    {
        private readonly IUserDelegationAppService _userDelegationAppService;
        private readonly IUserDelegationConfiguration _userDelegationConfiguration;
        private readonly IUnitOfWorkManager _unitOfWorkManager;

        public AppActiveUserDelegationsComboboxViewComponent(
            IUserDelegationAppService userDelegationAppService,
            IUserDelegationConfiguration userDelegationConfiguration,
            IUnitOfWorkManager unitOfWorkManager)
        {
            _userDelegationAppService = userDelegationAppService;
            _userDelegationConfiguration = userDelegationConfiguration;
            _unitOfWorkManager = unitOfWorkManager;
        }

        public async Task<IViewComponentResult> InvokeAsync(string logoSkin = null, string logoClass = "", string cssClass = "d-flex align-items-center ms-1 ms-lg-3 active-user-delegations me-2")
        {
            return await _unitOfWorkManager.WithUnitOfWorkAsync(async () =>
            {
                var activeUserDelegations = await _userDelegationAppService.GetActiveUserDelegations();
                var model = new ActiveUserDelegationsComboboxViewModel
                {
                    UserDelegations = activeUserDelegations,
                    UserDelegationConfiguration = _userDelegationConfiguration,
                    CssClass = cssClass
                };

                return View(model);
            });
        }
    }
}

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

5 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    The UserDelegationAppService requires authentication: The class has [AbpAuthorize] attribute, meaning ALL methods require the user to be logged in.

    [AbpAuthorize]
    public class UserDelegationAppService : AbpZeroTemplateAppServiceBase, IUserDelegationAppService
    

    The ViewComponent doesn't check authentication: The AppActiveUserDelegationsComboboxViewComponent is being rendered in your layout, which can be called even when:

    • The user is not logged in
    • The user's session has expired
    • A user is accessing public/anonymous pages
    • A user doesn't have the required permissions

    GetActiveUserDelegations() uses AbpSession.GetUserId(): This will throw an exception if the user is not authenticated:

    public async Task<List<UserDelegationDto>> GetActiveUserDelegations()
    {
        var query = CreateActiveUserDelegationsQuery(AbpSession.GetUserId(), "username");
        query = query.Where(e => e.StartTime <= Clock.Now && e.EndTime >= Clock.Now);
        return await query.ToListAsync();
    }
    

    Modify your AppActiveUserDelegationsComboboxViewComponent.cs to check if the user is authenticated before calling the service:

    using System.Threading.Tasks;
    using Abp.Domain.Uow;
    using JetBrains.Annotations;
    using Microsoft.AspNetCore.Mvc;
    using CDP.Authorization.Delegation;
    using CDP.Authorization.Users.Delegation;
    using CDP.Web.Areas.App.Models.Layout;
    using CDP.Web.Views;
    using System.Collections.Generic;
    
    namespace CDP.Web.Areas.App.Views.Shared.Components.AppActiveUserDelegationsCombobox
    {
        public class AppActiveUserDelegationsComboboxViewComponent : CDPViewComponent
        {
            private readonly IUserDelegationAppService _userDelegationAppService;
            private readonly IUserDelegationConfiguration _userDelegationConfiguration;
            private readonly IUnitOfWorkManager _unitOfWorkManager;
    
            public AppActiveUserDelegationsComboboxViewComponent(
                IUserDelegationAppService userDelegationAppService,
                IUserDelegationConfiguration userDelegationConfiguration,
                IUnitOfWorkManager unitOfWorkManager)
            {
                _userDelegationAppService = userDelegationAppService;
                _userDelegationConfiguration = userDelegationConfiguration;
                _unitOfWorkManager = unitOfWorkManager;
            }
    
            public async Task<IViewComponentResult> InvokeAsync(string logoSkin = null, string logoClass = "", string cssClass = "d-flex align-items-center ms-1 ms-lg-3 active-user-delegations me-2")
            {
                // Check if user is authenticated before calling the service
                if (!AbpSession.UserId.HasValue)
                {
                    // Return empty model or empty view if user is not logged in
                    var emptyModel = new ActiveUserDelegationsComboboxViewModel
                    {
                        UserDelegations = new List<UserDelegationDto>(),
                        UserDelegationConfiguration = _userDelegationConfiguration,
                        CssClass = cssClass
                    };
                    return View(emptyModel);
                }
    
                return await _unitOfWorkManager.WithUnitOfWorkAsync(async () =>
                {
                    var activeUserDelegations = await _userDelegationAppService.GetActiveUserDelegations();
                    var model = new ActiveUserDelegationsComboboxViewModel
                    {
                        UserDelegations = activeUserDelegations,
                        UserDelegationConfiguration = _userDelegationConfiguration,
                        CssClass = cssClass
                    };
    
                    return View(model);
                });
            }
        }
    }
    

    Alternatively, you can modify your layout file to only render the component when the user is authenticated.

    @if (User.Identity.IsAuthenticated)
    {
        @await Component.InvokeAsync("AppActiveUserDelegationsCombobox", new { cssClass = "d-flex align-items-center ms-1 ms-lg-3 active-user-delegations me-2" })
    }
    
    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    [oguzhanagir] said: AppActiveUserDelegationsComboboxViewComponent

    I will verify your suggestions. But what about the first two warnings, are they two due this AppActiveUserDelegationsComboboxViewComponent class? Or will they also get fixed with the mentioned corrections

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @kansoftware

    The first two warnings are not directly caused by the AppActiveUserDelegationsComboboxViewComponent itself, but they occur for similar reasons. When an unauthenticated or unauthorized user accesses a component, controller, or view that requires permissions.

    Once you apply the suggested fix (checking authentication before invoking the service or rendering the component), those warnings should also stop appearing, as the same root cause unauthorized access will be handled properly.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    [oguzhanagir] said: Hi @kansoftware

    The first two warnings are not directly caused by the AppActiveUserDelegationsComboboxViewComponent itself, but they occur for similar reasons. When an unauthenticated or unauthorized user accesses a component, controller, or view that requires permissions.

    Once you apply the suggested fix (checking authentication before invoking the service or rendering the component), those warnings should also stop appearing, as the same root cause unauthorized access will be handled properly.

    Hey, I am still facing the warnings. We have identified the cause of the Required Permission issue. Randomly the role id getting set in the AbpZeroUserPermissions cache is wrong and due to that reason the permission getting cached in AbpZeroRolePermissions is wrong. Is there something which can cause this?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @kansoftware

    Sorry for the late reply. We haven't been able to replicate this on our end. Could you please email us the steps or your project to [email protected] so we can provide a more specific answer to your issue.

    Thank you.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)