Base solution for your next web application
Open Closed

Issue with Unauthorized Access and Infinite Login Loop #12331


User avatar
0
ufukyalcin created

Projemde ASP.NET Zero versiyon 11 kullanıyorum. Kullanıcı, yetkisi olmayan bir sayfaya tıkladığında çıkış yaparak login sayfasına yönlendiriliyor. Ancak, yönlendirilen login sayfasının URL’sinde returnUrl parametresi bulunduğu için kullanıcı, sonsuz bir döngüye giriyor ve giriş yapamıyor.

İstediğim şey şu: Eğer kullanıcının o sayfada yetkisi yoksa, "Yetkisiz erişim" mesajı gösterilip ana sayfaya yönlendirilmesi; eğer kullanıcının girişi yoksa, login sayfasına yönlendirilmesi gerekiyor. Bu konuda yardımcı olabilir misiniz?


I am using ASP.NET Zero version 11 in my project. When a user clicks on a page they do not have permission to access, they are logged out and redirected to the login page. However, since the login page URL contains the returnUrl parameter, the user enters an infinite loop and is unable to log in.

What I need is this: If the user doesn't have permission for that page, they should be shown a "Unauthorized Access" message and redirected to the homepage. If the user is not logged in, they should be redirected to the login page. Could you assist me with this?

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

2 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @ufukyalcin

    If your project is MVC, you can add permission control for the relevant page as a parameter to the menu item defined in YourProjectNameNavigationProvider. You can use the example below for MVC. You need to pass the permission value for the relevant page to the permissionDependency parameter. If the user does not have permission here, the relevant page will not be displayed.

    .AddItem(new MenuItemDefinition(
            YourProjectAreaNamePageNames.Host.Dashboard,
            L("Dashboard"),
            url: "YourProjectAreaName/HostDashboard",
            icon: "flaticon-line-graph",
            permissionDependency: new SimplePermissionDependency(AppPermissions.Pages_Administration_Host_Dashboard)
        )
    )
    

    In Angular, you can also define a permission value for the menu item defined in the admin-routing.module.ts or main-routing.module.ts file. You can use the example below.

    {
        path: 'users',
        loadChildren: () => import('./users/users.module').then((m) => m.UsersModule),
        data: { permission: 'Pages.Administration.Users' },
    },
    

    You can use AbpAuthorize attribute in the Controller or AppService request for the relevant page.

    Example:

    [AbpAuthorize(AppPermissions.Pages_Administration_AuditLogs)]
    public class AuditLogAppService : YourProjectNameAppServiceBase, IAuditLogAppService
    {
        ...
    }
    

    Related Document

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ufukyalcin created

    Merhaba,

    İstediğim şey, yalnızca yetki olmayan sekmelerin gizlenmesi değildi. Benim amacım, yetki olmayan bir sayfaya tıklandığında, "Yetkiniz yoktur" gibi bir mesaj görüntülenmesiydi. Bu amaçla, IsEnabled fonksiyonu tanımlanmış ancak, menü öğelerini eklerken bu fonksiyonu true veya false olarak ayarlamam işlevsiz kalıyordu. Şu şekilde bir çözüm geliştirdim, aşağıda paylaşıyorum:

    .AddItem(new MenuItemDefinition( MpaPageNames.Tenant.ProgramList, L("ProgramMaster"), url: "-/-/ProgramList", icon: "fa fa-edit" icon: "fa fa-edit", customData: AppPermissions.Pages_Program ) )

    Burada, customData olarak istediğim yetkiyi belirledim.

    URL'yi oluşturduğum CalculateUrl fonksiyonunu ise şu şekilde güncelledim:

    public static string CalculateUrl(this UserMenuItem menuItem, string applicationPath) { if (!string.IsNullOrEmpty(menuItem.CustomData?.ToString())) { var permissionChecker = IocManager.Instance.Resolve<IPermissionChecker>(); if (permissionChecker != null) if (!permissionChecker.IsGranted(menuItem.CustomData.ToString())) return $"javascript:abp.message.error(app.localize("MenuUnAuthorizedUser","{menuItem.DisplayName}"), app.localize("UnauthorizedUser"))"; }...}

    Bu güncelleme ile, kullanıcının yetkisi olmayan bir menü öğesine tıkladığında, gerekli mesajı göstererek işlem yapılmasını sağladım.


    Hi,

    What I was looking for wasn’t just hiding the tabs that the user doesn’t have permission to access. My goal was to display a message like "You don’t have permission" when trying to access a page without the necessary permissions. The IsEnabled function is defined, but setting it to true or false while adding the menu items didn’t work as expected. I came up with the following solution, which I am sharing below:

    .AddItem(new MenuItemDefinition( MpaPageNames.Tenant.ProgramList, L("ProgramMaster"), url: "-/-/ProgramList", icon: "fa fa-edit" icon: "fa fa-edit", customData: AppPermissions.Pages_Program ) )

    Here, I set the required permission using customData.

    I also updated the CalculateUrl function where the URL is generated as follows:

    public static string CalculateUrl(this UserMenuItem menuItem, string applicationPath) { if (!string.IsNullOrEmpty(menuItem.CustomData?.ToString())) { var permissionChecker = IocManager.Instance.Resolve<IPermissionChecker>(); if (permissionChecker != null) if (!permissionChecker.IsGranted(menuItem.CustomData.ToString())) return $"javascript:abp.message.error(app.localize("MenuUnAuthorizedUser","{menuItem.DisplayName}"), app.localize("UnauthorizedUser"))"; }...}

    With this update, if the user clicks on a menu item they don’t have permission to access, it will show the appropriate message.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)