We have enabled multi-tenancy in our AspNetZero application with the subdomain format: {tenancy_name}.mydomain.xyz We need to accomplish two things:
1. Change Host Subdomain Change the default host subdomain from host.mydomain.xyz to my.mydomain.xyz
2. Handle Invalid Tenant Subdomains Currently, when a user accesses a non-existent tenant subdomain (e.g., nonexistent.mydomain.xyz), they are automatically redirected to the host login. We need to prevent this behavior and instead: - Show an error message indicating the tenant doesn't exist - Redirect to a custom "tenant not found" page Or prevent access entirely with a 404 page
How can we implement both of these changes?
3 Answer(s)
-
0
Hi @smartech
To achieve both requirements in an ASP.NET Zero application using subdomain based multi tenancy, you can proceed as follows:
Change the Host Subdomain (host → my)
ASP.NET Zero determines the host tenant by bypassing specific subdomains in
DomainTenantCheckMiddleware.Configuration
Update your root address configuration to use your desired subdomain format:
Web.Host/appsettings.json
{ "App": { "ServerRootAddress": "https://{TENANCY_NAME}.mydomain.xyz/" } }Web.Mvc/appsettings.json
{ "App": { "WebSiteRootAddress": "https://{TENANCY_NAME}.mydomain.xyz/" } }Middleware Update
In
DomainTenantCheckMiddleware.cs(*.Web.Core/MultiTenancy/DomainTenantCheckMiddleware.cs), add your custom host subdomain (my) to the bypass list:if (string.Equals(tenancyName, "www", StringComparison.OrdinalIgnoreCase)) { await next(context); return; } if (string.Equals(tenancyName, "my", StringComparison.OrdinalIgnoreCase)) { await next(context); return; }This ensures
my.mydomain.xyzis treated as the host tenant.Handle Invalid Tenant Subdomains
By default, ASP.NET Zero redirects non-existing tenant subdomains to the host. To prevent this behavior:
Enable Invalid Tenant Protection
In
YourProjectNameConsts.cs(*.Core.Shared/YourProjectNameConsts.cs), set:public const bool PreventNotExistingTenantSubdomains = true;When enabled,
DomainTenantCheckMiddlewarewill detect invalid tenants instead of silently redirecting to the host.Custom Error Handling
If you prefer showing a custom page instead of the default redirect, update the middleware logic:
if (tenantInfo == null) { context.Response.Redirect("/Error/TenantNotFound"); return; }Then add a corresponding action in
ErrorController:[Route("/Error/TenantNotFound")] public ActionResult TenantNotFound() { return View("TenantNotFound"); }Alternatively, you may return a plain 404 response if you want to block access entirely.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
How can we stop "host" to be used ? I mean if the user entered host.mydomain.xyz we need to response with an error instead of showing tenant not found
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @smartech
In ASP.NET Zero, If you want to completely disable
host.mydomain.xyzand return an error instead, you must explicitly block it in the tenant resolution middleware.Block
hostexplicitly inDomainTenantCheckMiddlewareAdd the following check at the very beginning of
DomainTenantCheckMiddleware.cs, before any bypass logic:*.Web.Core/MultiTenancy/DomainTenantCheckMiddleware.csif (string.Equals(tenancyName, "host", StringComparison.OrdinalIgnoreCase)) { context.Response.StatusCode = StatusCodes.Status404NotFound; await context.Response.WriteAsync("This subdomain is not allowed."); return; }This ensures that
host.mydomain.xyzis never resolved as the Host Tenant.Allow only your custom host subdomain (
my)Keep the bypass logic only for your custom host subdomain:
if (string.Equals(tenancyName, "my", StringComparison.OrdinalIgnoreCase)) { await next(context); return; }Enable invalid tenant protection
Make sure this flag is enabled to prevent fallback to the host tenant:
YourProjectNameConsts.cs
public const bool PreventNotExistingTenantSubdomains = true;(Optional) Redirect to a custom error page
Instead of returning a plain 404, you can redirect to a custom page:
if (string.Equals(tenancyName, "host", StringComparison.OrdinalIgnoreCase)) { context.Response.Redirect("/Error/SubdomainNotAllowed"); return; }Block host at DNS / Reverse Proxy level as well
Application level blocking is necessary, but for security and performance reasons, you can also implement host subdomain blocking at the DNS or reverse proxy layer.
Prevents unnecessary requests from ever reaching your application Improves performance by short circuiting invalid traffic early
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)