Hello Support Team
We are using Angular and .netcore.
We have a security requirements to get the login details like IP Address , country , city and Computer Name. We checked Audit-log and Login attempt it displays Networkload balancer IP. How can I get the real IP address ? Computer Name ? For Country and City I can get it using Third party services but how can add it to the Login attempt table ?
Finally, we have request to allow the user to login from a specific geolocation , what is your recommendations to be implemented.
3 Answer(s)
-
0
Hi @smartech
Thank you for your question. Below is a consolidated and recommended approach for capturing real IP address, computer name, geolocation details, and enforcing geolocation based login restrictions in an ASP.NET Zero.
Getting the Real Client IP Address
ASP.NET Zero already supports forwarded headers, but this only works correctly if both sides are configured properly.
Application side
- Ensure
ForwardedHeadersMiddlewareis enabled early in the pipeline. - ASP.NET Zero already provides this via:
app.UseAbpZeroTemplateForwardedHeaders();This middleware enables:
X-Forwarded-ForX-Forwarded-Proto
Infrastructure side
Your Load Balancer / Reverse Proxy must forward the real client IP using
X-Forwarded-For.Examples:
- Azure Application Gateway
- Nginx
- Cloudflare
Once configured correctly,
ClientIpAddressin Login Attempts and Audit Logs will contain the real client IP instead of the load balancer IP.Getting the Computer Name
This is not something the server can obtain automatically.
- HTTP does not include computer name information
- Browsers block access to OS level identifiers for security reasons
Option A Client side
- Collect limited client info in Angular (e.g. browser hostname where available)
- Send it explicitly as part of the login request
- Store it in
ClientNameor a custom field
Option B Reverse DNS Lookup
- Attempt reverse DNS from IP address
- Not reliable and not recommended for security critical scenarios
Adding Country / City to Login Attempts
The
AbpUserLoginAttemptstable belongs to the ASP.NET Boilerplate framework and should not be modified directly.Recommended Approach
Create a separate table linked to login attempts
Create a new entity, for example:
UserLoginAttemptGeolocation- FK ->
UserLoginAttemptId
Integrate a geolocation provider:
- MaxMind GeoIP2
- IPStack
- IP2Location
Override
LogInManager.SaveLoginAttemptAsync:- Call the base method
- Resolve country/city using the real IP
- Save geolocation data into the custom table
This approach:
- Preserves ABP upgrade safety
- Keeps audit and security data extensible
- Avoids schema conflicts with framework tables
Restricting Login by Geolocation
This should be enforced before issuing tokens.
Recommended Design
Create an
IGeolocationServiceStore allowed countries/cities:
- Per User or
- Per Tenant (via settings)
During login (e.g.
TokenAuthController):- Resolve client geolocation from IP
- Validate against allowed locations
- Reject login if not allowed
If you have any further questions, please do not hesitate to contact us. We will be happy to assist you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) - Ensure
-
0
Can I show here how long the session taken ? let's see user logged in 1:00:00 and logged out / session terminated 1:25:00.
need to show the session period. How can I do ?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @smartech
ASP.NET Zero records login time by default, but it does not track logout or session end time. Therefore, session duration must be implemented explicitly.
Default Framework Behavior
AbpUserLoginAttempts
- Stores login time
- Does not store logout or session end
AbpAuditLogs
- Can show user activity timestamps
- Cannot reliably represent a session end
Because of this, session duration cannot be calculated accurately using built in tables alone.
Create a Custom Session Entity
Do not modify framework tables. Instead, introduce a dedicated session entity.
public class UserSession : FullAuditedEntity<long> { public long UserId { get; set; } public DateTime LoginTime { get; set; } public DateTime? LogoutTime { get; set; } public string IpAddress { get; set; } public TimeSpan? SessionDuration => LogoutTime.HasValue ? LogoutTime.Value - LoginTime : null; }Record Login Time
After a successful authentication, create a new
UserSessionrecord and persist the login timestamp and client IP address.Record Logout / Session End
Explicit Logout
When the logout endpoint is called:
- Locate the active session for the user
- Set the logout timestamp
Token Expiration / Session Timeout
In JWT based authentication, session termination is not triggered automatically.
Recommended approach:
Determine session validity based on token lifetime
Use a background worker or scheduled job to:
- Identify sessions without a logout timestamp
- Mark them as ended once the token validity period has passed
This covers scenarios such as:
- Browser close
- Token expiration
- Network interruption
If you need further guidance, please let us know.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)