diff --git a/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs b/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs index 9e3fff950b..676f37aa47 100644 --- a/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs +++ b/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs @@ -159,6 +159,23 @@ public class IdentityServerSupportedLoginModel : LoginModel if (result.IsNotAllowed) { + var notAllowedUser = await UserManager.FindByNameAsync(LoginInput.UserNameOrEmailAddress) ?? + await UserManager.FindByEmailAsync(LoginInput.UserNameOrEmailAddress); + if (notAllowedUser != null) + { + using (CurrentTenant.Change(notAllowedUser.TenantId)) + { + await IdentityOptions.SetAsync(); + if ((notAllowedUser.ShouldChangePasswordOnNextLogin || + await UserManager.ShouldPeriodicallyChangePasswordAsync(notAllowedUser)) && + !await UserManager.CheckPasswordAsync(notAllowedUser, LoginInput.Password)) + { + Alerts.Danger(L["InvalidUserNameOrPassword"]); + return Page(); + } + } + } + Alerts.Warning(L["LoginIsNotAllowed"]); return Page(); }