diff --git a/modules/identity/src/Volo.Abp.Identity.Application/Volo/Abp/Identity/IdentityUserAppService.cs b/modules/identity/src/Volo.Abp.Identity.Application/Volo/Abp/Identity/IdentityUserAppService.cs index 4fced6274b..3f28afb3f5 100644 --- a/modules/identity/src/Volo.Abp.Identity.Application/Volo/Abp/Identity/IdentityUserAppService.cs +++ b/modules/identity/src/Volo.Abp.Identity.Application/Volo/Abp/Identity/IdentityUserAppService.cs @@ -17,7 +17,7 @@ namespace Volo.Abp.Identity private readonly IPermissionAppServiceHelper _permissionAppServiceHelper; public IdentityUserAppService( - IdentityUserManager userManager, + IdentityUserManager userManager, IIdentityUserRepository userRepository, IPermissionAppServiceHelper permissionAppServiceHelper) { @@ -113,6 +113,7 @@ namespace Volo.Abp.Identity await _permissionAppServiceHelper.UpdateAsync(UserPermissionValueProvider.ProviderName, id.ToString(), input); } + [Authorize(IdentityPermissions.Users.Default)] public async Task FindByUsernameAsync(string username) { return ObjectMapper.Map( @@ -120,6 +121,7 @@ namespace Volo.Abp.Identity ); } + [Authorize(IdentityPermissions.Users.Default)] public async Task FindByEmailAsync(string email) { return ObjectMapper.Map( diff --git a/modules/identity/src/Volo.Abp.Identity.HttpApi/Volo/Abp/Identity/IdentityUserController.cs b/modules/identity/src/Volo.Abp.Identity.HttpApi/Volo/Abp/Identity/IdentityUserController.cs index eb2e448c9c..761f98d6bf 100644 --- a/modules/identity/src/Volo.Abp.Identity.HttpApi/Volo/Abp/Identity/IdentityUserController.cs +++ b/modules/identity/src/Volo.Abp.Identity.HttpApi/Volo/Abp/Identity/IdentityUserController.cs @@ -64,16 +64,11 @@ namespace Volo.Abp.Identity return _userAppService.UpdatePermissionsAsync(id, input); } + //todo: add authorize attrbutes on the corresponding methods. [HttpGet] public virtual Task FindByUsernameAsync(string username) { - if (CurrentUser.Id.HasValue) - { - return _userAppService.FindByUsernameAsync(username); - } - - Console.WriteLine("Not logged in!"); - throw new UnauthorizedAccessException(); + return _userAppService.FindByUsernameAsync(username); } [HttpGet]