Skip to content

Users: fix UserMenu.cshtml for anonymous visitors and without the Avatar feature - #340

Open
DavidHolmlabs wants to merge 1 commit into
OrchardCoreContrib:mainfrom
DavidHolmlabs:fix/users-usermenu-anonymous-and-no-avatar
Open

DavidHolmlabs wants to merge 1 commit into
OrchardCoreContrib:mainfrom
DavidHolmlabs:fix/users-usermenu-anonymous-and-no-avatar

Conversation

@DavidHolmlabs

Copy link
Copy Markdown

OrchardCoreContrib.Users' UserMenu.cshtml override breaks every page that renders the user menu (e.g. TheTheme's navbar, including the login page) in two cases. Both reproduce on 1.7.0 and on current main.

1. Anonymous visitors (Avatar enabled)

The view has no User.Identity.IsAuthenticated check. For a logged-out visitor it builds an avatar from a null User.Identity.Name:

ArgumentNullException: Value cannot be null. (Parameter 'DisplayName')

Fix: for anonymous visitors, render the same markup as the stock OrchardCore.Users UserMenu.cshtml (its anonymous dropdown, or a login link).

2. Any Users feature enabled without Avatar (e.g. only Impersonation)

Orchard Core binds a module's shape templates to every enabled feature of that module (ShapeTemplateBindingStrategy), so this view is active whenever any OrchardCoreContrib.Users feature is. The @attribute [Feature("OrchardCoreContrib.Users.Avatar")] doesn't prevent that. Without the Avatar feature, and with a host that doesn't call AddOrchardCoreContrib(), nothing registers IAvatarService:

InvalidOperationException: No service for type 'OrchardCoreContrib.Avatars.IAvatarService' has been registered.

Fix: resolve IAvatarService optionally. If there is none, or it returns an empty avatar (NullAvatarService), show a user icon in place of the <img>. Otherwise the dropdown is unchanged.

Verification

I booted OrchardCoreContrib.Modules.Web from the SaaS recipe (TheTheme) with WebApplicationFactory and requested /. I removed the host-level NullAvatarService registration in Program.cs, so the host behaves like a consumer app that doesn't call AddOrchardCoreContrib().

Features enabled Visitor Before After
Avatar anonymous throws ArgumentNullException 200, login link
Avatar logged in 200, avatar dropdown 200, avatar dropdown
Impersonation anonymous throws No service for type 'IAvatarService' 200, login link
Impersonation logged in throws (the login page itself fails) 200, dropdown with user icon
Impersonation + Avatar anonymous — 200, login link
Impersonation + Avatar logged in — 200, avatar dropdown

The Profile / Change password links resolve the same before and after.

Downstream we currently work around both bugs with a view override in our own module, which we'd like to delete once this is released.

🤖 Generated with Claude Code

…ar feature

- Anonymous visitors get the stock OrchardCore.Users menu (login link) instead of the avatar
  dropdown. Before, the view built an avatar from a null User.Identity.Name, which throws
  ArgumentNullException (Parameter 'DisplayName') and returns 500 for every page rendering
  the user menu (e.g. TheTheme's navbar).
- Resolve IAvatarService optionally. Orchard Core binds a module's shape templates to every
  enabled feature of the module (ShapeTemplateBindingStrategy), so the view is active whenever
  any OrchardCoreContrib.Users feature is - e.g. only Impersonation - and the [Feature] attribute
  doesn't prevent that. Without an avatar provider every page threw "No service for type
  IAvatarService". It now falls back to a user icon, also when the service returns an empty
  avatar (NullAvatarService).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hishamco

hishamco commented Oct 2, 2026

Copy link
Copy Markdown
Member

Thanks @DavidHolmlabs I will check your changes and hope to merge ASAP

One more thing: please provide the steps to reproduce for the first case, coz I presume it should show the menu after you're logged in

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants