Base solution for your next web application
Open Closed

Get the real IP address and Computer Name #12602


User avatar
0
smartech created

Hello Support Team

We are using Angular and .netcore.

We have a security requirements to get the login details like IP Address , country , city and Computer Name. We checked Audit-log and Login attempt it displays Networkload balancer IP. How can I get the real IP address ? Computer Name ? For Country and City I can get it using Third party services but how can add it to the Login attempt table ?

Finally, we have request to allow the user to login from a specific geolocation , what is your recommendations to be implemented.

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

3 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @smartech

    Thank you for your question. Below is a consolidated and recommended approach for capturing real IP address, computer name, geolocation details, and enforcing geolocation based login restrictions in an ASP.NET Zero.

    Getting the Real Client IP Address

    ASP.NET Zero already supports forwarded headers, but this only works correctly if both sides are configured properly.

    Application side

    • Ensure ForwardedHeadersMiddleware is enabled early in the pipeline.
    • ASP.NET Zero already provides this via:
    app.UseAbpZeroTemplateForwardedHeaders();
    

    This middleware enables:

    • X-Forwarded-For
    • X-Forwarded-Proto

    Infrastructure side

    • Your Load Balancer / Reverse Proxy must forward the real client IP using X-Forwarded-For.

    • Examples:

      • Azure Application Gateway
      • Nginx
      • Cloudflare

    Once configured correctly, ClientIpAddress in Login Attempts and Audit Logs will contain the real client IP instead of the load balancer IP.

    Getting the Computer Name

    This is not something the server can obtain automatically.

    • HTTP does not include computer name information
    • Browsers block access to OS level identifiers for security reasons

    Option A Client side

    • Collect limited client info in Angular (e.g. browser hostname where available)
    • Send it explicitly as part of the login request
    • Store it in ClientName or a custom field

    Option B Reverse DNS Lookup

    • Attempt reverse DNS from IP address
    • Not reliable and not recommended for security critical scenarios

    Adding Country / City to Login Attempts

    The AbpUserLoginAttempts table belongs to the ASP.NET Boilerplate framework and should not be modified directly.

    Recommended Approach

    Create a separate table linked to login attempts

    1. Create a new entity, for example:

      • UserLoginAttemptGeolocation
      • FK -> UserLoginAttemptId
    2. Integrate a geolocation provider:

      • MaxMind GeoIP2
      • IPStack
      • IP2Location
    3. Override LogInManager.SaveLoginAttemptAsync:

      • Call the base method
      • Resolve country/city using the real IP
      • Save geolocation data into the custom table

    This approach:

    • Preserves ABP upgrade safety
    • Keeps audit and security data extensible
    • Avoids schema conflicts with framework tables

    Restricting Login by Geolocation

    This should be enforced before issuing tokens.

    Recommended Design

    1. Create an IGeolocationService

    2. Store allowed countries/cities:

      • Per User or
      • Per Tenant (via settings)
    3. During login (e.g. TokenAuthController):

      • Resolve client geolocation from IP
      • Validate against allowed locations
      • Reject login if not allowed

    If you have any further questions, please do not hesitate to contact us. We will be happy to assist you.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    smartech created

    Can I show here how long the session taken ? let's see user logged in 1:00:00 and logged out / session terminated 1:25:00.

    need to show the session period. How can I do ?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @smartech

    ASP.NET Zero records login time by default, but it does not track logout or session end time. Therefore, session duration must be implemented explicitly.

    Default Framework Behavior

    • AbpUserLoginAttempts

      • Stores login time
      • Does not store logout or session end
    • AbpAuditLogs

      • Can show user activity timestamps
      • Cannot reliably represent a session end

    Because of this, session duration cannot be calculated accurately using built in tables alone.

    Create a Custom Session Entity

    Do not modify framework tables. Instead, introduce a dedicated session entity.

    public class UserSession : FullAuditedEntity<long>
    {
        public long UserId { get; set; }
        public DateTime LoginTime { get; set; }
        public DateTime? LogoutTime { get; set; }
        public string IpAddress { get; set; }
    
        public TimeSpan? SessionDuration =>
            LogoutTime.HasValue ? LogoutTime.Value - LoginTime : null;
    }
    

    Record Login Time

    After a successful authentication, create a new UserSession record and persist the login timestamp and client IP address.

    Record Logout / Session End

    Explicit Logout

    When the logout endpoint is called:

    • Locate the active session for the user
    • Set the logout timestamp

    Token Expiration / Session Timeout

    In JWT based authentication, session termination is not triggered automatically.

    Recommended approach:

    • Determine session validity based on token lifetime

    • Use a background worker or scheduled job to:

      • Identify sessions without a logout timestamp
      • Mark them as ended once the token validity period has passed

    This covers scenarios such as:

    • Browser close
    • Token expiration
    • Network interruption

    If you need further guidance, please let us know.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)