diff --git a/docs/en/Modules/Identity.md b/docs/en/Modules/Identity.md index 8cd7bf3966..60976347ab 100644 --- a/docs/en/Modules/Identity.md +++ b/docs/en/Modules/Identity.md @@ -1,38 +1,59 @@ # Identity Management Module -Identity module is used to manage organization units, roles, users and their permissions, based on the Microsoft Identity library. +Identity module is used to manage roles, users and their permissions, based on the [Microsoft Identity library](https://docs.microsoft.com/en-us/aspnet/core/security/authentication/identity). -> **See [the source code](https://github.com/abpframework/abp/tree/dev/modules/identity). Documentation will come soon...** +## How to Install +This module comes as pre-installed (as NuGet/NPM packages) when you [create a new solution](https://abp.io/get-started) with the ABP Framework. You can continue to use it as package and get updates easily, or you can include its source code into your solution (see `get-source` [CLI](../CLI.md) command) to develop your custom module. -## Identity Security Log +### The Source Code -The security log can record some important operations or changes about your account. You can save the security log if needed. +The source code of this module can be accessed [here](https://github.com/abpframework/abp/tree/dev/modules/identity). The source code is licensed with [MIT](https://choosealicense.com/licenses/mit/), so you can freely use and customize it. -You can inject and use `IdentitySecurityLogManager` or `ISecurityLogManager` to write security logs. It will create a log object by default and fill in some common values, such as `CreationTime`, `ClientIpAddress`, `BrowserInfo`, `current user/tenant`, etc. Of course, you can override them. +## Menu Items -```cs -await IdentitySecurityLogManager.SaveAsync(new IdentitySecurityLogContext() -{ - Identity = "IdentityServer"; - Action = "ChangePassword"; -}); -``` +This module adds an *Identity management* menu item under the *Administration* menu: -Configure `AbpSecurityLogOptions` to provide the application name for the log or disable this feature. **Enabled** by default. +![identity-module-menu](../images/identity-module-menu.png) -```cs -Configure(options => -{ - options.ApplicationName = "AbpSecurityTest"; -}); -``` +The menu items and the related pages are authorized. That means the current user must have the related permissions to make them visible. The `admin` role (and the users with this role - like the `admin` user) already has these permissions. If you want to enable permissions for other roles/users, open the *Permissions* dialog on the *Roles* or *Users* page and check the permissions as shown below: + +![identity-module-permissions](../images/identity-module-permissions.png) + +See the [Authorization document](../Authorization.md) to understand the permission system. + +## Pages + +This section introduces the main pages provided by this module. + +### Users + +This page is used to see the list of users. You can create/edit and delete users, assign users to roles. + +![identity-module-users](../images/identity-module-users.png) + +A user can have zero or more roles. Users inherit permissions from their roles. In addition, you can assign permissions directly to the users (by clicking the *Actions* button, then selecting the *Permissions*). + +### Roles + +Roles are used to group permissions assign them to users. + +![identity-module-roles](../images/identity-module-roles.png) -## Organization Unit Management +Beside the role name, there are two properties of a role: -Organization units (OU) is a part of **Identity Module** and can be used to **hierarchically group users and entities**. +* `Default`: If a role is marked as "default", then that role is assigned to new users by default when they register to the application themselves (using the [Account Module](Account.md)). +* `Public`: A public role of a user can be seen by other users in the application. This feature has no usage in the Identity module, but provided as a feature that you may want to use in your own application. -### OrganizationUnit Entity +## Other Features + +This section covers some other features provided by this module which don't have the UI pages. + +### Organization Units + +Organization Units (OU) can be used to **hierarchically group users and entities**. + +#### OrganizationUnit Entity An OU is represented by the **OrganizationUnit** entity. The fundamental properties of this entity are: @@ -41,8 +62,6 @@ An OU is represented by the **OrganizationUnit** entity. The fundamental propert - **Code**: A hierarchical string code that is unique for a tenant. - **DisplayName**: Shown name of the OU. -The OrganizationUnit entity's primary key (Id) is a **Guid** type and it derives from the [**FullAuditedAggregateRoot**](../Entities.md) class. - #### Organization Tree Since an OU can have a parent, all OUs of a tenant are in a **tree** structure. There are some rules for this tree; @@ -52,7 +71,7 @@ Since an OU can have a parent, all OUs of a tenant are in a **tree** structure. #### OU Code -OU code is automatically generated and maintained by the OrganizationUnit Manager. It's a string that looks something like this: +OU code is automatically generated and maintained by the `OrganizationUnitManager` service. It's a string that looks something like this: "**00001.00042.00005**" @@ -72,6 +91,29 @@ The **OrganizationUnitManager** class can be [injected](../Dependency-Injection. - Move an OU in the OU tree. - Getting information about the OU tree and its items. -#### Multi-Tenancy +### Identity Security Log + +The security log can record some important operations or changes about your account. You can save the security log if needed. + +You can inject and use `IdentitySecurityLogManager` or `ISecurityLogManager` to write security logs. It will create a log object by default and fill in some common values, such as `CreationTime`, `ClientIpAddress`, `BrowserInfo`, `current user/tenant`, etc. Of course, you can override them. + +```cs +await IdentitySecurityLogManager.SaveAsync(new IdentitySecurityLogContext() +{ + Identity = "IdentityServer"; + Action = "ChangePassword"; +}); +``` + +Configure `AbpSecurityLogOptions` to provide the application name for the log or disable this feature. **Enabled** by default. + +```cs +Configure(options => +{ + options.ApplicationName = "AbpSecurityTest"; +}); +``` + +### Options -The `OrganizationUnitManager` is designed to work for a **single tenant** at a time. It works for the **current tenant** by default. \ No newline at end of file +TODO \ No newline at end of file diff --git a/docs/en/UI/AspNetCore/Basic-Theme.md b/docs/en/UI/AspNetCore/Basic-Theme.md index 67977ffd4e..3c63eb6b6a 100644 --- a/docs/en/UI/AspNetCore/Basic-Theme.md +++ b/docs/en/UI/AspNetCore/Basic-Theme.md @@ -83,8 +83,8 @@ See the [User Interface Customization Guide](Customization-User-Interface.md) to ### Copy & Customize -You can download the [source code](https://github.com/abpframework/abp/tree/dev/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Basic) of the Basic Theme, copy the project content into your solution, re-arrange the package/module dependencies (see the Installation section above to understand how it was installed to the project) and freely customize the theme based on your application requirements. +You can download the [source code](https://github.com/abpframework/abp/tree/rel-4.3/framework/src/Volo.Abp.AspNetCore.Mvc.UI.Theme.Basic) of the Basic Theme, copy the project content into your solution, re-arrange the package/module dependencies (see the Installation section above to understand how it was installed to the project) and freely customize the theme based on your application requirements. ## See Also -* [Theming](Theming.md) \ No newline at end of file +* [Theming](Theming.md) diff --git a/docs/en/UI/Blazor/Basic-Theme.md b/docs/en/UI/Blazor/Basic-Theme.md index 926d15cf11..d2947ecb17 100644 --- a/docs/en/UI/Blazor/Basic-Theme.md +++ b/docs/en/UI/Blazor/Basic-Theme.md @@ -50,8 +50,8 @@ See the [Customization / Overriding Components](Customization-Overriding-Compone ### Copy & Customize -You can download the [source code](https://github.com/abpframework/abp/tree/dev/framework/src/Volo.Abp.AspNetCore.Components.WebAssembly.BasicTheme) of the Basic Theme, copy the project content into your solution, re-arrange the package/module dependencies (see the Installation section above to understand how it was installed to the project) and freely customize the theme based on your application requirements. +You can download the [source code](https://github.com/abpframework/abp/tree/rel-4.3/framework/src/Volo.Abp.AspNetCore.Components.WebAssembly.BasicTheme) of the Basic Theme, copy the project content into your solution, re-arrange the package/module dependencies (see the Installation section above to understand how it was installed to the project) and freely customize the theme based on your application requirements. ## See Also -* [Theming](Theming.md) \ No newline at end of file +* [Theming](Theming.md) diff --git a/docs/en/images/identity-module-menu.png b/docs/en/images/identity-module-menu.png new file mode 100644 index 0000000000..8083e2f722 Binary files /dev/null and b/docs/en/images/identity-module-menu.png differ diff --git a/docs/en/images/identity-module-permissions.png b/docs/en/images/identity-module-permissions.png new file mode 100644 index 0000000000..24ef15e3b4 Binary files /dev/null and b/docs/en/images/identity-module-permissions.png differ diff --git a/docs/en/images/identity-module-roles.png b/docs/en/images/identity-module-roles.png new file mode 100644 index 0000000000..c8e2c9cde1 Binary files /dev/null and b/docs/en/images/identity-module-roles.png differ diff --git a/docs/en/images/identity-module-users.png b/docs/en/images/identity-module-users.png new file mode 100644 index 0000000000..7de6da77d4 Binary files /dev/null and b/docs/en/images/identity-module-users.png differ