Base solution for your next web application
Open Closed

Same browser with multiple tabs of same application but for different tenant not identifying. #12613


User avatar
0
csona created

Using Asp.Net Zero Angular + .Net Core application.11.2.1 version.

If the user opens a new browser window and goes to a different tenant in Applicaton, they may think they are looking at 2 different tenants in the different windows, but they are not. This is a confusing authentication problem.

Requirements: Implement a solution such as the one used by QuickBooks as shown in the attached screen shot. This is what the user sees in "browser window A" if they authenticate differently in "browser window B". In this case, I was the same user, but just switched QB companies in "browser window B". What you see here is the message I got in "browser window A" when I went to "browser window B" and switched to a different company in QB.

Can we do this requirement with my current version of aspnet zero.!

Screenshot 2025-12-08 160637.png

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

1 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @csona

    ASP.NET Zero includes the “Allow one concurrent login per user” feature; however, this setting does not directly address the scenario you described. That feature is designed to prevent the same user from logging in simultaneously from different browsers or devices. It does not apply when the same user switches tenants in different tabs or windows within the same browser. Therefore, when a tenant is changed in one window, it is not expected behavior for the other window to automatically show a warning or invalidate itself.

    The behavior you observed in QuickBooks is not primarily related to the authentication mechanism itself, but rather to a client side session/tenant consistency check. When a tenant is switched in one window, the other window detects that the effective session has changed and displays a session has changed warning to the user.

    In ASP.NET Zero 11.2.1, this behavior is not available out of the box. However, the requirement can be fulfilled with a small and controlled customization on top of the existing version. A typical approach would be:

    • When the user logs in or switches tenants, store the active tenantId and userId on the client side (for example, in localStorage).
    • In each browser window or tab, periodically or during route/navigation changes call Session/GetCurrentLoginInformations to retrieve the current session information from the server.
    • Compare the server side tenant/user information with the values stored on the client.
    • If a mismatch is detected, display a modal/dialog informing the user that the session has changed in another window and prompt them to refresh or re authenticate.
    • Optionally, use the browser’s window.storage event to immediately notify other open windows when a tenant change occurs.

    In summary, this requirement cannot be met through a single configuration setting, but it can be implemented through a client side customization on the current ASP.NET Zero version.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)