From b33e14bf89224017daed1515c8457f939fa0a807 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Sat, 22 May 2021 01:57:31 +0300 Subject: [PATCH 1/5] Added Locked Out page and NotAllowed logic --- .../Account/Localization/Resources/en.json | 6 +++- .../Pages/Account/LockedOut.cshtml | 30 +++++++++++++++++++ .../Pages/Account/LockedOut.cshtml.cs | 18 +++++++++++ .../Pages/Account/Login.cshtml.cs | 12 +++++++- 4 files changed, 64 insertions(+), 2 deletions(-) create mode 100644 modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml create mode 100644 modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs diff --git a/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json b/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json index 459d115398..0884e04984 100644 --- a/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json +++ b/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json @@ -62,6 +62,10 @@ "PasswordResetInfoInEmail": "We received an account recovery request! If you initiated this request, click the following link to reset your password.", "ResetMyPassword": "Reset my password", "AccessDenied": "Access denied!", - "AccessDeniedMessage": "You do not have access to this resource." + "AccessDeniedMessage": "You do not have access to this resource.", + "LockedOut": "Locked Out", + "AccountDisabledTitle": "Your account is not enabled!", + "AccountLockedOutTitle": "Your account is locked!", + "AccountLockedOutText": "Please contact to admin." } } diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml new file mode 100644 index 0000000000..2fc1083c5b --- /dev/null +++ b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml @@ -0,0 +1,30 @@ +@page "/Account/LockedOut" +@model Volo.Abp.Account.Web.Pages.Account.LockedOut +@using Volo.Abp.Account.Localization +@using Microsoft.AspNetCore.Mvc.Localization +@using Volo.Abp.Identity.Settings +@using Volo.Abp.Settings +@inject IHtmlLocalizer L +@inject Volo.Abp.AspNetCore.Mvc.UI.Layout.IPageLayout PageLayout +@inject ISettingProvider SettingProvider +@{ + PageLayout.Content.Title = L["LockedOut"].Value; + var requireConfirmedEmail = await SettingProvider.IsTrueAsync(IdentitySettingNames.SignIn.RequireConfirmedEmail); + var requireConfirmedPhoneNumber = await SettingProvider.IsTrueAsync(IdentitySettingNames.SignIn.RequireConfirmedPhoneNumber); + bool isAccountDisabled = requireConfirmedEmail || requireConfirmedPhoneNumber; + +} + + + @if (isAccountDisabled) + { + @L["AccountDisabledTitle"] + @L["LoginIsNotAllowed"] + } + else + { + @L["AccountLockedOutTitle"] + @L["AccountLockedOutText"] + } + + \ No newline at end of file diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs new file mode 100644 index 0000000000..90eb091d64 --- /dev/null +++ b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs @@ -0,0 +1,18 @@ +using System.Threading.Tasks; +using Microsoft.AspNetCore.Mvc; + +namespace Volo.Abp.Account.Web.Pages.Account +{ + public class LockedOut : AccountPageModel + { + public virtual Task OnGetAsync() + { + return Task.FromResult(Page()); + } + + public virtual Task OnPostAsync() + { + return Task.FromResult(Page()); + } + } +} \ No newline at end of file diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs index a69b186adc..004df26348 100644 --- a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs +++ b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs @@ -213,7 +213,17 @@ namespace Volo.Abp.Account.Web.Pages.Account if (result.IsLockedOut) { - throw new UserFriendlyException("Cannot proceed because user is locked out!"); + // throw new UserFriendlyException("Cannot proceed because user is locked out!"); + Logger.LogWarning($"Cannot proceed because user is locked out!"); + return RedirectToPage("./LockedOut"); + } + + if (result.IsNotAllowed) + { + // throw new UserFriendlyException("External login callback error: User is Not Allowed!"); + Logger.LogWarning($"External login callback error: User is Not Allowed!"); + // Returns a view informing the user about the locked account + return RedirectToPage("./LockedOut"); } if (result.Succeeded) From 01f4f642568ed63477faf765719ec31d9d623d26 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Sat, 22 May 2021 02:06:05 +0300 Subject: [PATCH 2/5] removed comments --- .../src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs | 3 --- 1 file changed, 3 deletions(-) diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs index 004df26348..26881d9e5f 100644 --- a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs +++ b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs @@ -213,16 +213,13 @@ namespace Volo.Abp.Account.Web.Pages.Account if (result.IsLockedOut) { - // throw new UserFriendlyException("Cannot proceed because user is locked out!"); Logger.LogWarning($"Cannot proceed because user is locked out!"); return RedirectToPage("./LockedOut"); } if (result.IsNotAllowed) { - // throw new UserFriendlyException("External login callback error: User is Not Allowed!"); Logger.LogWarning($"External login callback error: User is Not Allowed!"); - // Returns a view informing the user about the locked account return RedirectToPage("./LockedOut"); } From 76b09d5d4733cf8d102cca0edfacabfee686e7ff Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Mon, 24 May 2021 11:50:14 +0300 Subject: [PATCH 3/5] updated to return confirm page when user is not allowed --- .../Volo/Abp/Account/Localization/Resources/en.json | 1 - .../Pages/Account/LockedOut.cshtml | 12 ------------ .../Pages/Account/Login.cshtml.cs | 6 +++++- 3 files changed, 5 insertions(+), 14 deletions(-) diff --git a/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json b/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json index 0884e04984..5817e558ee 100644 --- a/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json +++ b/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json @@ -64,7 +64,6 @@ "AccessDenied": "Access denied!", "AccessDeniedMessage": "You do not have access to this resource.", "LockedOut": "Locked Out", - "AccountDisabledTitle": "Your account is not enabled!", "AccountLockedOutTitle": "Your account is locked!", "AccountLockedOutText": "Please contact to admin." } diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml index 2fc1083c5b..5fdd5ebbcb 100644 --- a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml +++ b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml @@ -2,29 +2,17 @@ @model Volo.Abp.Account.Web.Pages.Account.LockedOut @using Volo.Abp.Account.Localization @using Microsoft.AspNetCore.Mvc.Localization -@using Volo.Abp.Identity.Settings @using Volo.Abp.Settings @inject IHtmlLocalizer L @inject Volo.Abp.AspNetCore.Mvc.UI.Layout.IPageLayout PageLayout @inject ISettingProvider SettingProvider @{ PageLayout.Content.Title = L["LockedOut"].Value; - var requireConfirmedEmail = await SettingProvider.IsTrueAsync(IdentitySettingNames.SignIn.RequireConfirmedEmail); - var requireConfirmedPhoneNumber = await SettingProvider.IsTrueAsync(IdentitySettingNames.SignIn.RequireConfirmedPhoneNumber); - bool isAccountDisabled = requireConfirmedEmail || requireConfirmedPhoneNumber; } - @if (isAccountDisabled) - { - @L["AccountDisabledTitle"] - @L["LoginIsNotAllowed"] - } - else - { @L["AccountLockedOutTitle"] @L["AccountLockedOutText"] - } \ No newline at end of file diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs index 26881d9e5f..f43d837252 100644 --- a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs +++ b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs @@ -220,7 +220,11 @@ namespace Volo.Abp.Account.Web.Pages.Account if (result.IsNotAllowed) { Logger.LogWarning($"External login callback error: User is Not Allowed!"); - return RedirectToPage("./LockedOut"); + return RedirectToPage("./ConfirmUser", new + { + returnUrl = ReturnUrl, + returnUrlHash = ReturnUrlHash + }); } if (result.Succeeded) From 6149193415ac8f579e27ebbe38df9a6deb9a0ae1 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Mon, 24 May 2021 11:59:39 +0300 Subject: [PATCH 4/5] updated to throw errors --- .../Pages/Account/LockedOut.cshtml | 18 ------------------ .../Pages/Account/LockedOut.cshtml.cs | 18 ------------------ .../Pages/Account/Login.cshtml.cs | 12 ++++-------- 3 files changed, 4 insertions(+), 44 deletions(-) delete mode 100644 modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml delete mode 100644 modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml deleted file mode 100644 index 5fdd5ebbcb..0000000000 --- a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml +++ /dev/null @@ -1,18 +0,0 @@ -@page "/Account/LockedOut" -@model Volo.Abp.Account.Web.Pages.Account.LockedOut -@using Volo.Abp.Account.Localization -@using Microsoft.AspNetCore.Mvc.Localization -@using Volo.Abp.Settings -@inject IHtmlLocalizer L -@inject Volo.Abp.AspNetCore.Mvc.UI.Layout.IPageLayout PageLayout -@inject ISettingProvider SettingProvider -@{ - PageLayout.Content.Title = L["LockedOut"].Value; - -} - - - @L["AccountLockedOutTitle"] - @L["AccountLockedOutText"] - - \ No newline at end of file diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs deleted file mode 100644 index 90eb091d64..0000000000 --- a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/LockedOut.cshtml.cs +++ /dev/null @@ -1,18 +0,0 @@ -using System.Threading.Tasks; -using Microsoft.AspNetCore.Mvc; - -namespace Volo.Abp.Account.Web.Pages.Account -{ - public class LockedOut : AccountPageModel - { - public virtual Task OnGetAsync() - { - return Task.FromResult(Page()); - } - - public virtual Task OnPostAsync() - { - return Task.FromResult(Page()); - } - } -} \ No newline at end of file diff --git a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs index f43d837252..313f3f07c0 100644 --- a/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs +++ b/modules/account/src/Volo.Abp.Account.Web/Pages/Account/Login.cshtml.cs @@ -213,18 +213,14 @@ namespace Volo.Abp.Account.Web.Pages.Account if (result.IsLockedOut) { - Logger.LogWarning($"Cannot proceed because user is locked out!"); - return RedirectToPage("./LockedOut"); + Logger.LogWarning($"External login callback error: user is locked out!"); + throw new UserFriendlyException("Cannot proceed because user is locked out!"); } if (result.IsNotAllowed) { - Logger.LogWarning($"External login callback error: User is Not Allowed!"); - return RedirectToPage("./ConfirmUser", new - { - returnUrl = ReturnUrl, - returnUrlHash = ReturnUrlHash - }); + Logger.LogWarning($"External login callback error: user is not allowed!"); + throw new UserFriendlyException("Cannot proceed because user is not allowed!"); } if (result.Succeeded) From 8fd031c8ec6361c421abbc5b3bfdc86bc06c5c97 Mon Sep 17 00:00:00 2001 From: maliming Date: Mon, 24 May 2021 17:03:26 +0800 Subject: [PATCH 5/5] Update en.json --- .../Volo/Abp/Account/Localization/Resources/en.json | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json b/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json index 5817e558ee..459d115398 100644 --- a/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json +++ b/modules/account/src/Volo.Abp.Account.Application.Contracts/Volo/Abp/Account/Localization/Resources/en.json @@ -62,9 +62,6 @@ "PasswordResetInfoInEmail": "We received an account recovery request! If you initiated this request, click the following link to reset your password.", "ResetMyPassword": "Reset my password", "AccessDenied": "Access denied!", - "AccessDeniedMessage": "You do not have access to this resource.", - "LockedOut": "Locked Out", - "AccountLockedOutTitle": "Your account is locked!", - "AccountLockedOutText": "Please contact to admin." + "AccessDeniedMessage": "You do not have access to this resource." } }