From f8772d2f57c63df7c3ccdf925882ccd17464b2e0 Mon Sep 17 00:00:00 2001 From: maliming Date: Wed, 27 May 2026 10:57:54 +0800 Subject: [PATCH] Add validation for invalid password on login for users required to change password --- .../IdentityServerSupportedLoginModel.cs | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs b/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs index 9e3fff950b..676f37aa47 100644 --- a/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs +++ b/modules/account/src/Volo.Abp.Account.Web.IdentityServer/Pages/Account/IdentityServerSupportedLoginModel.cs @@ -159,6 +159,23 @@ public class IdentityServerSupportedLoginModel : LoginModel if (result.IsNotAllowed) { + var notAllowedUser = await UserManager.FindByNameAsync(LoginInput.UserNameOrEmailAddress) ?? + await UserManager.FindByEmailAsync(LoginInput.UserNameOrEmailAddress); + if (notAllowedUser != null) + { + using (CurrentTenant.Change(notAllowedUser.TenantId)) + { + await IdentityOptions.SetAsync(); + if ((notAllowedUser.ShouldChangePasswordOnNextLogin || + await UserManager.ShouldPeriodicallyChangePasswordAsync(notAllowedUser)) && + !await UserManager.CheckPasswordAsync(notAllowedUser, LoginInput.Password)) + { + Alerts.Danger(L["InvalidUserNameOrPassword"]); + return Page(); + } + } + } + Alerts.Warning(L["LoginIsNotAllowed"]); return Page(); }