From 9456694f08a0e7bb9facf5f13d9b29cef00234fb Mon Sep 17 00:00:00 2001 From: maliming Date: Sat, 2 May 2026 17:03:19 +0800 Subject: [PATCH] Simplify parent tenant validation --- .../Volo/Abp/Identity/Localization/en-GB.json | 2 +- .../Volo/Abp/Identity/Localization/en.json | 2 +- .../Abp/Identity/OrganizationUnitManager.cs | 53 ++++++++----------- .../Identity/OrganizationUnitManager_Tests.cs | 38 ------------- 4 files changed, 23 insertions(+), 72 deletions(-) diff --git a/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json b/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json index 22dc4880ad..3318b5cf19 100644 --- a/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json +++ b/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en-GB.json @@ -76,7 +76,7 @@ "Volo.Abp.Identity:010007": "You can't change your two factor setting.", "Volo.Abp.Identity:010008": "Changing the two factor setting is not allowed.", "Volo.Abp.Identity:010009": "You cannot delegate yourself!", - "Volo.Abp.Identity:010010": "The parent organisation unit ('{ParentId}') does not exist or belong to a different tenant.", + "Volo.Abp.Identity:010010": "The parent organisation unit ('{ParentId}') does not exist, or it belongs to a different tenant.", "Volo.Abp.Identity:010021": "Name exist: '{0}'", "Volo.Abp.Identity:010022": "Can not update a static ClaimType.", "Volo.Abp.Identity:010023": "Can not delete a static ClaimType.", diff --git a/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json b/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json index 9c508f28ae..3a6e9e18ca 100644 --- a/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json +++ b/modules/identity/src/Volo.Abp.Identity.Domain.Shared/Volo/Abp/Identity/Localization/en.json @@ -77,7 +77,7 @@ "Volo.Abp.Identity:010007": "You can't change your two factor setting.", "Volo.Abp.Identity:010008": "It's not allowed to change two factor setting.", "Volo.Abp.Identity:010009": "You can not delegate yourself.", - "Volo.Abp.Identity:010010": "The parent organization unit ('{ParentId}') does not exist or belong to a different tenant.", + "Volo.Abp.Identity:010010": "The parent organization unit ('{ParentId}') does not exist, or it belongs to a different tenant.", "Volo.Abp.Identity:010021": "Name exist: '{0}'.", "Volo.Abp.Identity:010022": "Can not update a static ClaimType.", "Volo.Abp.Identity:010023": "Can not delete a static ClaimType.", diff --git a/modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs b/modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs index 0a1866f6e0..cb8fa17a77 100644 --- a/modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs +++ b/modules/identity/src/Volo.Abp.Identity.Domain/Volo/Abp/Identity/OrganizationUnitManager.cs @@ -41,14 +41,11 @@ public class OrganizationUnitManager : DomainService [UnitOfWork] public virtual async Task CreateAsync(OrganizationUnit organizationUnit) { - using (CurrentTenant.Change(organizationUnit.TenantId)) - { - await ValidateParentTenantAsync(organizationUnit.ParentId, organizationUnit.TenantId); + await ValidateParentTenantAsync(organizationUnit.ParentId, organizationUnit.TenantId); - organizationUnit.Code = await GetNextChildCodeAsync(organizationUnit.ParentId); - await ValidateOrganizationUnitAsync(organizationUnit); - await OrganizationUnitRepository.InsertAsync(organizationUnit); - } + organizationUnit.Code = await GetNextChildCodeAsync(organizationUnit.ParentId); + await ValidateOrganizationUnitAsync(organizationUnit); + await OrganizationUnitRepository.InsertAsync(organizationUnit); } public virtual async Task UpdateAsync(OrganizationUnit organizationUnit) @@ -112,31 +109,28 @@ public class OrganizationUnitManager : DomainService return; } - using (CurrentTenant.Change(organizationUnit.TenantId)) - { - await ValidateParentTenantAsync(parentId, organizationUnit.TenantId); + await ValidateParentTenantAsync(parentId, organizationUnit.TenantId); - //Should find children before Code change - var children = await FindChildrenAsync(id, true); - - //Store old code of OU - var oldCode = organizationUnit.Code; + //Should find children before Code change + var children = await FindChildrenAsync(id, true); - //Move OU - organizationUnit.Code = await GetNextChildCodeAsync(parentId); - organizationUnit.ParentId = parentId; + //Store old code of OU + var oldCode = organizationUnit.Code; - await ValidateOrganizationUnitAsync(organizationUnit); + //Move OU + organizationUnit.Code = await GetNextChildCodeAsync(parentId); + organizationUnit.ParentId = parentId; - //Update Children Codes - foreach (var child in children) - { - child.Code = OrganizationUnit.AppendCode(organizationUnit.Code, OrganizationUnit.GetRelativeCode(child.Code, oldCode)); - await OrganizationUnitRepository.UpdateAsync(child); - } + await ValidateOrganizationUnitAsync(organizationUnit); - await OrganizationUnitRepository.UpdateAsync(organizationUnit); + //Update Children Codes + foreach (var child in children) + { + child.Code = OrganizationUnit.AppendCode(organizationUnit.Code, OrganizationUnit.GetRelativeCode(child.Code, oldCode)); + await OrganizationUnitRepository.UpdateAsync(child); } + + await OrganizationUnitRepository.UpdateAsync(organizationUnit); } public virtual async Task GetCodeOrDefaultAsync(Guid id) @@ -165,12 +159,7 @@ public class OrganizationUnitManager : DomainService return; } - OrganizationUnit parent; - using (CurrentTenant.Change(tenantId)) - { - parent = await OrganizationUnitRepository.FindAsync(parentId.Value); - } - + var parent = await OrganizationUnitRepository.FindAsync(parentId.Value); if (parent == null || parent.TenantId != tenantId) { throw new BusinessException(IdentityErrorCodes.OrganizationUnitParentTenantMismatch) diff --git a/modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs b/modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs index 1f37f6ed9e..43c97a945a 100644 --- a/modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs +++ b/modules/identity/test/Volo.Abp.Identity.Domain.Tests/Volo/Abp/Identity/OrganizationUnitManager_Tests.cs @@ -160,44 +160,6 @@ public class OrganizationUnitManager_Tests : AbpIdentityDomainTestBase } } - [Fact] - public async Task Should_Not_Create_Organization_Unit_From_Host_With_Cross_Tenant_Parent() - { - var hostOu = await _organizationUnitRepository.GetAsync("OU1"); - - var newOu = new OrganizationUnit(_guidGenerator.Create(), "ForeignTenantOu", hostOu.Id, Guid.NewGuid()); - - var ex = await Assert.ThrowsAsync( - async () => await _organizationUnitManager.CreateAsync(newOu)); - - ex.Code.ShouldBe(IdentityErrorCodes.OrganizationUnitParentTenantMismatch); - } - - [Fact] - public async Task Should_Allow_Host_To_Create_Tenant_Organization_Unit_Under_Same_Tenant_Parent() - { - var tenantId = Guid.NewGuid(); - OrganizationUnit tenantRoot; - - using (_currentTenant.Change(tenantId)) - { - tenantRoot = new OrganizationUnit(_guidGenerator.Create(), "TenantRoot", null, tenantId); - await _organizationUnitManager.CreateAsync(tenantRoot); - } - - var child = new OrganizationUnit(_guidGenerator.Create(), "TenantChild", tenantRoot.Id, tenantId); - await _organizationUnitManager.CreateAsync(child); - - using (_currentTenant.Change(tenantId)) - { - var loaded = await _organizationUnitRepository.FindAsync(child.Id); - loaded.ShouldNotBeNull(); - loaded.ParentId.ShouldBe(tenantRoot.Id); - loaded.TenantId.ShouldBe(tenantId); - loaded.Code.ShouldBe(OrganizationUnit.AppendCode(tenantRoot.Code, OrganizationUnit.CreateCode(1))); - } - } - [Fact] public async Task Should_Reject_Cross_Tenant_Parent_When_Multi_Tenancy_Filter_Disabled() {