COMPREHENSIVE REPORT: TLP PRO-PALESTINE CAMPAIGNS & PROTESTS

Coverage Period: October 2023 – October 2025
Subject Entity: Tehreek-e-Labbaik Pakistan (TLP)
 
1. Executive Summary
Following the escalation of the Middle East conflict on October 7, 2023, the socio-political landscape in Pakistan saw massive mobilization. TLP, under the leadership of Hafiz Saad Hussain Rizvi, pivoted a significant portion of its Public Support and Public Messaging towards total solidarity with the Palestinian cause. Through nationwide million-man marches, targeted economic boycotts, specialized religious conventions, and direct political sit-ins, TLP successfully pressured federal authorities into executing institutional actions against Israeli interests and scaling up humanitarian aid pipelines. TLP successfully linked Palestine with Pakistan’s national, religious, and cultural occasions to foster a shared sense of identity, solidarity, and belonging towards a collective bigger achievement.


2. Chronological Timeline of Major Events


🗓️ 13 October 2023: Nationwide “Labbaik Ya Aqsa” Marches
Event Type: Nationwide simultaneous protest rallies.
Primary Locations: Karachi (Main Avenue), Lahore, Islamabad, and other tier-1 cities.
Key Speakers:
Hafiz Saad Hussain Rizvi (Ameer of TLP)
Ismail Haniyeh (Former chairman of the Hamas Political Bureau)
Mufti Muhammad Qasim (Former Member of the Sindh Assembly).
Shafeeq Al Ameeni (KPK Province Ameer and Member of Shura)
Mufti Umair Al Azhri (Member of Majlis-e-Shura)
 
Key Observations:
Millions marched holding banners that visually represented the solidarity with the cause and waving Palestinian flags from Faizabad Interchange to D-Chowk Islamabad
This march became one of the biggest march in the Pakistani history where million of citizens took part in.
Protesters vocally chanted solidary slogans which are used worldwide and demanded actual physical response from the government of Pakistan in response to Illegal settlement Isreal escalating military operations in the Gaza Strip.
Core Statement: Publicly condemned the killing of Palestinian civilians, labelling the operations as the illegal state’s sponsored barbarism. He formally demanded that all Muslim-majority nations unite, break political compliance, and actively resist domination.
Sourced Visual Baseline: Verified via Associated Press Archives (Karachi Rally Footage).
Links:
https://www.youtube.com/watch?v=tIoVT-cnfCs
 
🗓️ 17 October 2023: “Visit to State of Palestine’s Embassy in Islamabad”
Event Type: Hafiz Saad Hussain Rizvi visits the Palestine’s Embassy in Pakistan along with Majlis-e-Shura Members.
Significance: This visit shows the Party’s dedication and sincerity to show solidarity with the Palestinian cause on each level.
Impact: This visit later became a trend for other party’s leaders to visit the Embassy as well to show solidary, Rizvi’s visit highlighted the presence Palestine body in Pakistan which before was forgotten.
Key Developments:
This visit made a huge impact in the people’s mind and highliting the presence of the State of Palestine in Pakistan.
 
🗓️ 5 November 2023: “Toofan Al-Aqsa Million March”
Event Type: Massive cross-city convergence and long march.
Route: Originating from Faizabad Interchange, marching directly towards Shahrah-e-Dastoor (Constitutional Avenue), Islamabad.
Operational Impact: Capital police enacted stringent security blockades, sealing off all primary routes to the Red Zone to secure government and parliamentary infrastructures.
Key Developments:
Former Hamas leader Ismail Haniyeh addressed the TLP crowd remotely via a secure video link to express solidarity.
Protesters displayed massive Palestinian flags and chanted anti-Israel slogans late till the night to show the hate and heartbreak.
Key Speakers: Saad Hussain Rizvi.
Core Statement: Sharply criticized the “criminal silence” adopted by the 57 Islamic nations, focusing specifically on the passivity of the Pakistani state apparatus. He claimed the public demanded active intervention rather than diplomatic neutrality.
Sourced Visual Baseline: Verified via Associated Press Archives (Islamabad Long March).
Links:
https://www.dawn.com/news/1786901
https://www.youtube.com/watch?v=oajebxrCOIg
https://www.dawn.com/news/1786779
https://www.youtube.com/watch?v=FTAH37quFsc


🗓️ 09 November 2023: Iqbal Day “Message of Awakening” & Palestine Solidarity Rallies
Event Type: Nationwide decentralized cultural and ideological rallies.
Thematic Framework: Tehreek-e-Labbaik Pakistan (TLP) strategically utilized Pakistan’s national Iqbal Day holiday to frame global Muslim struggles through the lens of Mohammed Iqbal Lahori’s philosophical poetry on self-realisation and resistance. Rallies across major provincial hubs explicitly paired the anniversary with a strong pro-Palestinian narrative. Speakers invoked Iqbal’s pan-Islamic vision to condemn the ongoing war in Gaza, urging the federal government to move beyond verbal diplomacy and take decisive, concrete state action against international human rights violations.
🗓️ 21 November 2023: 3rd Annual Urs Mubarak Devoted to Palestine
Event Type: Major religious-political convention.
Thematic Pivot: The annual death anniversary gathering of TLP founder Allama Khadim Hussain Rizvi was entirely re-dedicated to the freedom of Palestine and the resilience of its citizens
Key Speakers: Hafiz Anas Hussain Rizvi & Hafiz Saad Hussain Rizvi
Core Statement: Delivered an intense sermon stating that when the Honor of Islamic sanctities and Muslim lives are systematically violated, the theological mandate shifts entirely from maintaining peace to active resistance (Jihad) (3:30). He formally requested the Pakistani Army Chief and state authorities to officially declare an operational front against Israel (4:20).
Sourced Video Baseline: Hafiz Anas Hussain Rizvi Full Address.
Links:
https://www.youtube.com/watch?v=vFb7tsWBvvA
https://www.youtube.com/watch?v=PKYkXFuoEKY


🗓️ 21 – 28 November 2023: Week-Long Anti-Israel Economic Boycott Campaign
Event Type: Structural consumer boycott and public awareness campaign across Pakistan.
Target Vectors: Major global multi-nationals perceived as pro-Israel or pro-America (e.g., McDonald’s, KFC, Pizza Hut, Coca-Cola, Pepsi and others).
Strategic Methods: TLP leadership and digital influencers leveraged social media platforms to enforce an ethical consumer ban.
Documented Outcomes:
Local retailers and corporate suppliers reported record-breaking declines in weekly sales for US and Israeli-linked products.
Hit corporations were forced to roll out extensive public relations and social media counter-campaigns to minimize brand damage and regain lost domestic market shares.
Source Attribution: Reported via Periódico ¡ahora! Global Solidarity Archives.
Links:
https://www.ahora.cu/en/fidel-among-us/15-section/world/20134-solidarity-campaign-in-pakistan-launches-boycott-of-u-s-and-israeli-products


🗓️ 5 February 2024: Kashmir-Palestine Solidarity March
Event Type: Geopolitical intersectionality march.
Thematic Framework: Strategically synchronized with Pakistan’s official Kashmir Solidarity Day. TLP explicitly merged the narratives of Kashmir and Palestine, framing both as unfinished agendas of self-determination against occupying forces. Rallies across regional hubs demanded dual state actions to address human rights violations in both territories.


🗓️ 13 – 19 July 2024: The Faizabad Sit-In (Dharna) & Institutional Settlement
Event Type: Strategic traffic blockade and continuous protest camp.
Location: Faizabad Interchange (the critical transit artery connecting Rawalpindi and Islamabad).
Core Demands:
An official, state-sanctioned embargo on all Israeli-linked goods.
Immediate deployment of government-backed medical and food logistics to Gaza.
Formal state declaration labeling Israeli Prime Minister Benjamin Netanyahu an international terrorist.
Links:
https://tribune.com.pk/story/2481052/government-and-tlp-reach-agreement-to-end-faizabad-sit-in
https://www.thenews.com.pk/latest/1211208-tlp-ends-faizabad-sit-in-after-govt-assures-of-stepping-up-gaza-aid
https://www.dawn.com/news/1846728/week-long-agony-ends-as-tlp-protesters-wrap-up-faizabad-sit-in
https://www.pakistantoday.com.pk/2024/07/19/govt-and-tlp-reach-agreement-faizabad-sit-in-concluded



🗓️ 14 August 2024: “Pakistan Independence Day Rally”
Event Type: Celebrating Pakistan Independence rally and solidarity with Palestine rally.


🗓️ 09 November 2024: Iqbal Day “Message of Awakening” & Palestine Solidarity Rallies
Event Type: Nationwide decentralized cultural and ideological rallies.
Thematic Framework: Tehreek-e-Labbaik Pakistan (TLP) strategically utilized Pakistan’s national Iqbal Day holiday to frame global Muslim struggles through the lens of Allama Iqbal’s philosophical poetry on self-realisation and resistance. Rallies across major provincial hubs explicitly paired the anniversary with a strong pro-Palestinian narrative. Speakers invoked Iqbal’s pan-Islamic vision to condemn the ongoing war in Gaza, urging the federal government to move beyond verbal diplomacy and take decisive, concrete state action against international human rights violations.
 
🗓️ 19 November 2024: 4th Annual Urs Mubarak
Event Type: Major religious-political convention.
Mass Boycott Oath: Attendees took an oath on the final day to keep boycotting pro-Israel products.
Local Campaigns: Participants committed to launching grassroots awareness campaigns in their home districts to encourage others to join the boycott.
 
🗓️ 5 February 2025: Kashmir-Palestine Solidarity March
Event Type: Geopolitical intersectionality march.
Thematic Framework: Same as last year Kashmir day rallies this year again TLP strategically synchronized with Pakistan’s official Kashmir Solidarity Day. Explicitly merged the narratives of Kashmir and Palestine, framing both as unfinished agendas of self-determination against occupying forces. Rallies across regional hubs demanded dual state actions to address human rights violations in both territories.


🗓️ 21 March 2025: “Labbaik Ya-Aqsa March”
Event Type: Massive cross-city convergence and long march.


🗓️ May 2025: Tehreek Labbaik Pakistan postponed Protest/March
Event Type: Massive protest in front of US embassy.
Outcome: TLP postponed the protest due to geopolitical situation and rising tensions between India and Pakistan. TLP instead had an agreement with the govt. of Paksitan
Link:
https://x.com/zarrar_11PK/status/1917134660456583307?lang=en


🗓️ 14 August 2025: “Pakistan Independence Day Rally”
Event Type: Celebrating Pakistan Independence rally and solidarity with Palestine rally.
 
🗓️ 10 October 2025: The “Labbaik Ya Aqsa Million March” from TLP Markaz
Event Type: March from Lahore to the US Embassy (Islamabad Red Zone) to show an anti-Israeli demonstration and submit a formal diplomatic resolution condemning Western-backed Gaza peace frameworks.
Origin Point: TLP Party Headquarters / Markaz (Masjid Rehmatul lil Alameen, Multan Road, Lahore).
Intended Destination: The United States Embassy inside the Red Zone, Islamabad.
Context & Trigger: Organized following a global announcement of a US-brokered Middle East ceasefire plan. TLP Chief Saad Hussain Rizvi rejected the terms during Friday prayers at the Lahore Markaz, declaring a march to demand more aggressive state-level support for Gaza.
⚡ What Came After: The Government Crackdown & Escalation
The state responded with an immediate, high-intensity security operation to halt the march before it could leave Punjab or compromise the capital.
Pre-emptive Blockades and attack on Masjid (October 8–9): Before the march officially commenced, police raided regional hubs, detained hundreds of workers, imposed Section 144 in Rawalpindi, and heavily barricaded the twin cities using freight containers and crack down on the masjid resulting  in causalities in the masjid and dozens many injured including party workers, worshippers in mosque and pedestrians.
Violent Highway Clashes (October 10–13): As thousands of demonstrators pushed out from the Lahore Markaz onto the Grand Trunk (GT) Road and main highway routes, severe clashes erupted. Police deployed tear gas, baton charges, and rubber bullets, while demonstrators countered with stones and improvised blockades.
The Muridke Encounters: The situation peaked approximately 40 kilometres outside Lahore in Muridke, where massive encampments were violently broken up by joint police contingents and the Pakistan Rangers. Casualties on both sides were heavily documented, with TLP claiming numerous fatalities and over a thousand injured workers.
Digital and Civil Blackout: To control crowds and stifle media visibility, the federal government suspended 3G/4G mobile internet data networks across Lahore, Rawalpindi, and sections of Islamabad.
 
 
 3. Policy Outcomes & Government Negotiations
The week-long Faizabad blockade concluded successfully following intensive, direct negotiations between senior TLP leaders and top-tier federal government representatives, including Information Minister Attaullah Tarar and Advisor Rana Sanaullah.
Source Attribution: Documented comprehensively via News Guru Pakistan Report (July 2024 Accord) and archived under the Wikipedia 2024 Faizabad Sit-In Registry.

 

Impact of Micromanagement on IT Teams: Challenges and Consequences

A micromanaging boss in IT can have numerous negative impacts on both the team and the organization. Here are some key downsides:

1. Decreased Productivity

  • Lack of Autonomy: Employees may spend more time seeking approvals or redoing tasks to meet the boss’s overly detailed expectations, slowing down progress.
  • Over-emphasis on Minor Details: Micromanagers often focus on trivial details rather than the bigger picture, which can derail project timelines.

2. Poor Employee Morale

  • Lack of Trust: Micromanagement signals a lack of confidence in employees’ abilities, leading to frustration and dissatisfaction.
  • Demotivation: Constant oversight can make employees feel undervalued and disengaged, reducing their motivation to perform.

3. Stifled Innovation

  • Fear of Experimentation: Employees may avoid suggesting new ideas or taking risks, fearing criticism or rejection.
  • Rigid Work Environment: Micromanagement often creates a culture of conformity rather than creativity.

4. High Employee Turnover

  • Burnout: Continuous oversight and pressure can lead to stress and burnout, prompting employees to leave.
  • Talent Drain: Skilled IT professionals may prefer environments where they can exercise autonomy and creativity.

5. Inefficient Use of Leadership Time

  • Focus on Minor Tasks: The manager spends excessive time on tasks that should be delegated, neglecting strategic responsibilities.
  • Bottlenecks: Decision-making becomes slower, as everything must go through the micromanaging boss.

6. Negative Team Dynamics

  • Dependency Culture: Team members may become overly dependent on the manager, reducing initiative and problem-solving skills.
  • Conflict and Resentment: Constant interference can lead to friction between the manager and team members.

7. Poor Project Outcomes

  • Missed Deadlines: Over-involvement can delay critical milestones.
  • Compromised Quality: A focus on micromanagement often means less attention is paid to overall project quality.

8. Reputation Damage

  • Client Dissatisfaction: Delays and inefficiencies caused by micromanagement can result in missed deadlines, ultimately impacting client trust.
  • Difficulty Attracting Talent: Word spreads quickly in the IT industry, and companies with a reputation for micromanagement may struggle to attract top talent.

How to Address It:

Leadership Training: Encourage the manager to focus on outcomes rather than processes, emphasizing trust and delegation.

Clear Communication: Establish trust and clarify expectations to reduce the need for micromanagement.

Empower Employees: Allow team members to take ownership of their tasks and decisions.

Alternatives of Micromanagement:

Instead of defaulting to micromanagement, consider:

  • Clear Expectations: Set measurable goals and outcomes.
  • Regular Check-Ins: Use structured updates instead of constant oversight.
  • Delegation: Trust employees to take ownership of tasks.
  • Feedback and Support: Offer guidance when needed, but step back once confidence is built.

AWS Kinesis & SQS

What is Amazon Kinesis Data Streams

Amazon Kinesis Data Streams is a fully managed AWS service that you can use to collect and process large streams of data records in real time.

Key concepts:

  • Data record – A unit of data that is stored by Kinesis Data Streams. Data records are composed of a sequence number, a partition key, and a data blob, which is an immutable sequence of bytes. Kinesis Data Streams does not inspect, interpret, or change the data in the blob in any way. A data blob can be up to 1 MB.
  • Data stream – A resource that represents a group of data records.
  • Shard – A uniquely identified sequence of data records in a stream. A data stream is composed of one or more shards. Each shard provides a fixed unit of capacity.
  • Producer – A source that puts data into a Kinesis data stream.
  • Consumer – An application that gets records from data streams and processes them.
  • Kinesis Producer Library (KPL) – An easy-to-use, highly configurable library that helps you write to a data stream.
  • Kinesis Client Library (KCL) – An easy-to-use, highly configurable library that helps you consume and process data from a data stream.

What happens if producer exceeds ingest values:

 If your data producer exceeds either of those values, Amazon Kinesis Streams raises an exception, and your producer needs to retry records that did not get written successfully. Retrying failed records is a valid approach if the spike is very short-lived. However, to ingest more than 1000 records per second for a longer duration, you need to scale the number of shards in your stream. This can be achieved automatically by scaling the shards.

What is SQS

Amazon Simple Queue Service (Amazon SQS) offers a secure, durable, and available hosted queue that lets you integrate and decouple distributed software systems and components.

Queue types

Standard queueFIFO queue
Unlimited Throughput – Standard queues support a nearly unlimited number of API calls per second, per API action (SendMessageReceiveMessage, or DeleteMessage).At-Least-Once Delivery – A message is delivered at least once, but occasionally more than one copy of a message is delivered.Best-Effort Ordering – Occasionally, messages are delivered in an order different from which they were sent.High Throughput – If you use batching, FIFO queues support up to 3,000 transactions per second, per API method (SendMessageBatchReceiveMessage, or DeleteMessageBatch). The 3000 transactions represent 300 API calls, each with a batch of 10 messages. To request a quota increase, submit a support request. Without batching, FIFO queues support up to 300 API calls per second, per API method (SendMessageReceiveMessage, or DeleteMessage).Exactly-Once Processing – A message is delivered once and remains available until a consumer processes and deletes it. Duplicates aren’t introduced into the queue.First-In-First-Out Delivery – The order in which messages are sent and received is strictly preserved.
Send data between applications when the throughput is important, for example:Decouple live user requests from intensive background work: let users upload media while resizing or encoding it.Allocate tasks to multiple worker nodes: process a high number of credit card validation requests.Batch messages for future processing: schedule multiple entries to be added to a database.Send data between applications when the order of events is important, for example:Make sure that user-entered commands are run in the right order.Display the correct product price by sending price modifications in the right order.Prevent a student from enrolling in a course before registering for an account.

Kinesis vs SQS

Assembly redirects fix

If you ever run into a problem when after updating the library through nuget compilation throws an error of assembly version not found as system is still expecting an older version. This may cause due to the assembly redirects in the code.
One way to fix this is to run the following command in the Package Manager Console

PM> Get-Project –All | Add-BindingRedirect

Second method to fix this issue is to enable the automatic binding redirects in the web apps project.

Automatic binding redirects are implemented differently for web apps. Because the source configuration (web.config) file must be modified for web apps, binding redirects are not automatically added to the configuration file. However, Visual Studio notifies you of binding conflicts, and you can add binding redirects to resolve the conflicts. Because you’re always prompted to add binding redirects, you don’t need to explicitly disable this feature for a web app.

To add binding redirects to a web.config file:

  • In Visual Studio, compile the app, and check for build warnings.
    clr-assemblyrefwarning
  • If there are assembly binding conflicts, a warning appears. Double-click the warning, or select the warning and press Enter.A dialog box that enables you to automatically add the necessary binding redirects to the source web.config file appears.

    clr-addbindingredirect

ng-select multiple drop down with grouping + reactive forms

ng-select is a good npm package to use when we want to allow user to select multiple items from the dropdown.
The help on the official page is not helpful much in case if we are using the ng-select with reactive forms in Angular.
Recently I’ve to use the grouping option with checkboxes and reactive forms.
Below is the code snippet which works for me.

Capture

Most of the code is same as in the help provided with the control

https://ng-select.github.io/ng-select#/multiselect-checkbox

The only problem is it’s not with reactive forms. So to make it work with the reactive forms the code change is to change the [ngModel] with [checked] in ng-template section. We also don’t need [(ngModel)] as it’s replaced by formContralName in reactive forms

Asp Net Core 2.0: resolve error CALL_AND_RETRY_LAST Allocation failed – JavaScript heap out of memory

This is the easiest way to solve this error if someone is using Asp.net Core, Angular, Webpack (AngularTemplateProject)

Marco Barbero's avatarExpert Code Blog

This error is caused by a memory leak problem of node.js.

On a Visual Studio 2017 Asp Net Core 2.0 project started from the Angular CLI Template, that use WebPack to manage the build process, after some publish builds, due to file size increase, we can get this error:

node node_modules/webpack/bin/webpack.js --env.prod
EXEC(0,0): Error : CALL_AND_RETRY_LAST Allocation failed - JavaScript heap out of memory

To resolve this error we need to expand the memory size used by node.js.

This is possible setting the max_old_space_size parameter on the node command line with the [size] expressed in bytes:

--max_old_space_size=[size]

But how can we set this value into the publish process.

This is possible changing the .csproj file in this way:

  • Open the .csproj of the project that we are publishing.
  • Find the PublishRunWebpack target.
  • Set the value on each Exec Command which refers to node.
  • Save the changes.

For example, if we…

View original post 95 more words

Migrate from ASP.NET Core 1.x to 2.0

I’ve one project made in .net core 1.1 and recently worked on it to move it to .net core 2.0. For this purpose I follow This link.

I’m using HybridAndClientCredentials on the STS server and openid Connect and cookies on the client. Most of the migration is covered by the above link, but I faced issue where most of my claims are missing.

With the ASP.NET Core 1.x, client would have received the claims: nbf, exp, iss, aud, nonce, iat, c_hash, sid, sub, auth_time, idp, amr.

In Core 2.0 we only get sid, sub and idp. What happened?

Microsoft added a new concept to their OpenID Connect handler called ClaimActions. Claim actions allow modifying how claims from an external provider are mapped (or not) to a claim in your ClaimsPrincipal. Looking at the ctor of the OpenIdConnectOptions, you can see that the handler will now skip the following claims by default:

ClaimActions.DeleteClaim("nonce");
ClaimActions.DeleteClaim("aud");
ClaimActions.DeleteClaim("azp");
ClaimActions.DeleteClaim("acr");
ClaimActions.DeleteClaim("amr");
ClaimActions.DeleteClaim("iss");
ClaimActions.DeleteClaim("iat");
ClaimActions.DeleteClaim("nbf");
ClaimActions.DeleteClaim("exp");
ClaimActions.DeleteClaim("at_hash");
ClaimActions.DeleteClaim("c_hash");
ClaimActions.DeleteClaim("auth_time");
ClaimActions.DeleteClaim("ipaddr");
ClaimActions.DeleteClaim("platf");
ClaimActions.DeleteClaim("ver");

If you want to “un-skip” a claim, you need to delete a specific claim action when setting up the handler. The following is the very intuitive syntax to get the amr claim back:

options.ClaimActions.Remove("amr");

Requesting more claims from the OIDC provider

When you are requesting more scopes, e.g. profile or custom scopes that result in more claims, there is another confusing detail to be aware of.

Depending on the response_type in the OIDC protocol, some claims are transferred via the id_token and some via the userinfo endpoint.

So first of all, you need to enable support for the userinfo endpoint in the handler:

options.GetClaimsFromUserInfoEndpoint = true;

In the end you need to add the following class to import all other custom claims

public class MapAllClaimsAction : ClaimAction
    {
        public MapAllClaimsAction() : base(string.Empty, string.Empty)
        {
        }

        public override void Run(JObject userData, ClaimsIdentity identity, string issuer)
        {
            foreach (var claim in identity.Claims)
            {
                // If this claimType is mapped by the JwtSeurityTokenHandler, then this property will be set
                var shortClaimTypeName = claim.Properties.ContainsKey(JwtSecurityTokenHandler.ShortClaimTypeProperty) ?
                    claim.Properties[JwtSecurityTokenHandler.ShortClaimTypeProperty] : string.Empty;

                // checking if claim in the identity (generated from id_token) has the same type as a claim retrieved from userinfo endpoint
                JToken value;
                var isClaimIncluded = userData.TryGetValue(claim.Type, out value) || userData.TryGetValue(shortClaimTypeName, out value);

                // if a same claim exists (matching both type and value) both in id_token identity and userinfo response, remove the json entry from the userinfo response
                if (isClaimIncluded && claim.Value.Equals(value.ToString(), StringComparison.Ordinal))
                {
                    if (!userData.Remove(claim.Type))
                    {
                        userData.Remove(shortClaimTypeName);
                    }
                }
            }

            // adding remaining unique claims from userinfo endpoint to the identity
            foreach (var pair in userData)
            {
                JToken value;
                var claimValue = userData.TryGetValue(pair.Key, out value) ? value.ToString() : null;
                identity.AddClaim(new Claim(pair.Key, claimValue, ClaimValueTypes.String, issuer));
            }
        }
    }

In the end add the last ClaimActions in AddOpenIdConnection options list

options.ClaimActions.Add(new MapAllClaimsAction());

Auto redirect to an STS server in an Angular app using oidc Implicit Flow

Excellent npm package for Angular and Identity Server 4 Implicit flow implementation

damienbod's avatarSoftware Engineering

This article shows how to implement an auto redirect in an Angular application, if using the OIDC Implicit Flow with an STS server. When a user opens the application, it is sometimes required that the user is automatically redirected to the login page on the STS server. This can be tricky to implement, as you need to know when to redirect and when not. The OIDC client is implemented using the angular-auth-oidc-client npm package.

Code: https://github.com/damienbod/angular-auth-oidc-sample-google-openid

The angular-auth-oidc-client npm package provides an event when the OIDC module is ready to use and also can be configured to emit an event to inform the using component when the callback from the STS server has been processed. These 2 events, can be used to implement the auto redirect to the STS server, when not authorized.

The app.component can subscribe to these 2 events in the constructor.

The onOidcModuleSetup function handles the onModuleSetup…

View original post 189 more words

No executable found matching command dotnet-ef

If you try to run the dotnet ef command from powershell and see the following error.

No executable found matching command dotnet-ef

You need to do the following steps to fix it.

  • Add the Microsoft.EntityFrameworkCore.Tools and/or the Microsoft.EntityFrameworkCore.Tools.DotNet package libraries, depending if you want to use the PowerShell command or the CLI version. I personally do always install both of them.
<ItemGroup>
    <PackageReference Include="Microsoft.AspNetCore.All" Version="2.0.0" />
    <PackageReference Include="Microsoft.AspNetCore.Mvc.Versioning" Version="2.0.0" />
    <PackageReference Include="Microsoft.AspNetCore.StaticFiles" Version="2.0.0" />
    <PackageReference Include="Microsoft.EntityFrameworkCore" Version="2.0.0" />
    <PackageReference Include="Microsoft.EntityFrameworkCore.Tools" Version="2.0.0" />
    <PackageReference Include="Microsoft.EntityFrameworkCore.Tools.DotNet" Version="2.0.0" />
    <PackageReference Include="Microsoft.VisualStudio.Web.CodeGeneration.Design" Version="2.0.0" />
    <PackageReference Include="Pomelo.EntityFrameworkCore.MySql" Version="2.0.0" />
</ItemGroup>

it will add PackageReference like this

  • We also need to add the reference as DotNetCliToolReference which will add the following references
<ItemGroup>
   <DotNetCliToolReference Include="Microsoft.VisualStudio.Web.CodeGeneration.Tools" Version="2.0.0" />
   <DotNetCliToolReference Include="Microsoft.EntityFrameworkCore.Tools" Version="2.0.0" />
   <DotNetCliToolReference Include="Microsoft.EntityFrameworkCore.Tools.DotNet" Version="2.0.0" />
</ItemGroup>

Don’t forget to change the version as per your current version of the .net Core

API Versioning in .net Core 2.0 via URL

Version is helpful when we want to roll out new features without breaking the functionality of the existing ones. . It can also help to provide additional functionalities to selected customers. API versioning can be done in different ways like appending the version in the URL or as a query string parameter, via custom header and via Accept-header.

In this post, let’s find how to support multiple version ASP.NET Core Web API by appending the version in URL.

Let’s create an ASP.NET Core web API application and first thing to do is to include the Microsoft.AspNetCore.Mvc.Versioning package (Install the latest package or what is suitable to your project from the nuget.org). At the point of writing this article .net Core 2.0 is out and also the final 2.0.0 version of this nuget package.

Once the package is restored, we need to configure it. Next open Startup.cs, add the highlighted lines of code in ConfigureServices method.

public void ConfigureServices(IServiceCollection services)
{
  services.AddMvc();
  services.AddApiVersioning(option =&gt; {
      option.ReportApiVersions = true;
      option.AssumeDefaultVersionWhenUnspecified = true;
      option.DefaultApiVersion = new ApiVersion(1, 0);
    });
}

As you can see, there are 3 different options configured.

  • ReportAPIVersions: This is optional. But when set to true, API returns supported versions information in the response header.
  • AssumeDefaultVersionWhenUnspecified: This option will be used to serve the request without a version. The assumed API version by default would be 1.0.
  • DefaultApiVersion: This option is used to specify the default API version to be used when no version is specified in the request. This will default the version to 1.0.

That’s all for the configuration and setup. Now we will see how to access the versions of the API via the URL path segment.

Query string parameters are useful, but it can be painful in case of long URL and other query string parameters. Instead, the better approach would be to add version in the URL path. Like,

  • api/v1/values
  • api/v2/values

So to do this, we need to put the version in the route attribute. Like,

namespace ValuesController
{
   [ApiVersion("1.0")]
   [Route("api/v{version:apiVersion}/[controller]")]
   public class ValuesController : Controller
   {
     [HttpGet]
     public IActionResult Get() => Ok(new string[] { "value1" });
   }
}

With this change, the API endpoints always need to have the version number. You can navigate to version 1.0 via api/v1/values and to access version 2.0, change the version number in the URL. Simple and looks more clean now.

Deprecated:When multiple API versions are supported, some versions will eventually be deprecated over time. To mark one or more API versions have been deprecated, simply decorate your controller with the deprecated API versions. This doesn’t mean that the API version is not supported. One can still call the endpoint/version. It just a way to make API users aware that following version will be deprecated in future.


[ApiVersion("1.0", Deprecated = true)]

ApiVersionNeutral: attribute defines that this API is version-neutral. This is useful for APIs that behaves the exact same way, regardless of API version or a legacy API that doesn’t support API versioning. So, you can add ApiVersionNeutralattribute to opt out from versioning.

[ApiVersionNeutral]
[RoutePrefix( "api/[controller]" )]
public class SharedController : Controller
{
    [HttpGet]
    public IActionResult Get() => Ok();
}

MapToApiVersion: attribute allows to map a single API action to any version. In other words, a single controller which supports multiple versions say 1 and 3. The controller may have an API action method supported by version 3 only. In such case, you can use MapToApiVersion. Take a look at below code.

namespace ValuesController
{
  [ApiVersion("1.0")]
  [ApiVersion("2.0")]
  [Route("api/v{version:apiVersion}/[controller]")]
  public class ValuesController : Controller
  {
     [HttpGet]
     public IActionResult Get() => Ok(new string[] { "value1" });

     [HttpGet, MapToApiVersion("2.0")]
     public IActionResult GetV3() => Ok(new string[] { "value2" });
  }
}