In Angular side, we've used the angular-oauth2-oidc package to manage authorization code flow. As I know, there is no such package for the React Native. I do not know how can you achieve that but I can briefly explain the how code flow works:

  1. We execute initCodeFlow method of the OAuthService to navigate user to login page.
  2. OAuthService redirects to the IDS's page (url is like this: https://localhost:44305/connect/authorize?response_type=code&client_id=MyProjectName_App&state=R0xMQzR-NnkwbVgxMm8tOHozNVNLN2J5ZzBNfmN0eWxKQnloSUtIR2guWFFn&redirect_uri=
  3. IDS redirects to login page (url is like this: https://localhost:44305/Account/Login?ReturnUrl=/connect/authorize/callback?response_type=code&client_id=MyProjectName_App&state=R0xMQzR-NnkwbVgxMm8tOHozNVNLN2J5ZzBNfmN0eWxKQnloSUtIR2guWFFn&
  4. If login is successfull, IDS redirects to Angular app back (redirection url: http://localhost:4200?code=94DFAD919F8645959A13EC08E79636DEE658ECB11D3D654F8D0DEAC7BC14E605&scope=openid%20MyProjectName&state=R0xMQzR-NnkwbVgxMm8tOHozNVNLN2J5ZzBNfmN0eWxKQnloSUtIR2guWFFn&session_state=Hp45_ZHnuI2DJvBHfiqDilY-900FQmYAchPNm08yJ4o.6689B8D57ADA3BA44B02B792137710FA)
  5. angular-oauth2-oidc package performs a POST request: URL: https://localhost:44305/connect/token Body (form data): grant_type=authorization_code&code=94DFAD919F8645959A13EC08E79636DEE658ECB11D3D654F8D0DEAC7BC14E605&redirect_uri= Response: {"id_token":"id token shortened for brevity","access_token":"access token shortened for brevity","expires_in":31536000,"token_type":"Bearer","scope":"openid AbpCommercialDemo"}

You should examine the angular-oauth2-oidc package's source code for the details.


The problem is related to @ng-bootstrap/ng-bootstrap package. We're working on this. You can follow this issue:

I'll notify you when the problem is resolved. Thanks!

Please see the comment below to fix problem temporarily:

Hello @talhazengin

We've created an internal issue. We'll let you know when it is resolved. Thanks for the repoting!


It is already done:

You need to update your project to v4.4.4 at least. Thanks!

Here is the guide for custom login & register pages for v4.4+:



For some technical reasons, we have used innerHtml for the columns of the extensible table component. No vulnerability in this case. You cannot inject any script. Angular sanitizes it by default.



It seems a problem. Can you share the access token and refresh token response?

We use theangular-ouath2-oidc package for the authentication. So this problem is related to this package. Downgrading the RxJS version to v6 may be fixed the problem if you use RxJS 7. If the problem will not resolve, please provide the steps to reproduce in detail.

can we expect a fix for this problem in the upcoming update?

I don't know, you can report that by creating an issue to angular-ouath2-oidc repo. The problem should be fixed by the package authors.


