Skip to main content

Organizations

An organization is the unit in which Casdoor manages users and applications. A user who has signed in to an organization can open all applications of that organization without signing in again.

The organization that you select for an application or a provider determines which users can sign in to the application and where the provider is available.

You edit an organization in the Casdoor admin console under User Management > Organizations. This page describes the general settings. Other pages of this section cover the account page, password complexity, the password obfuscator, the theme, MFA items, and groups. You configure LDAP per organization as well. See LDAP.

Sign-in page of an organization​

Users usually sign in through an application. They can also sign in on the sign-in page of their organization, at /login/<organization-name>. On the demo site, for example: https://door.casdoor.com/login/casbin.

When a user signs in through this URL, Casdoor remembers the organization. When the session expires, Casdoor sends the user back to the sign-in page of the same organization.

Password storage​

Password type sets the algorithm with which Casdoor stores the passwords of the organization's users. New organizations use bcrypt.

NameAlgorithmDescriptionTypical use
plain—Passwords stored in cleartext. Not recommended for production.—
saltSHA-256SHA-256 is a cryptographic hash function that produces a 256-bit value.—
md5-saltMD5MD5 is a widely used but cryptographically weak hash (128-bit).Discuz!
bcryptbcryptbcrypt hashes and salts passwords securely. Default for new organizations.Spring Boot, WordPress
pbkdf2-saltSHA-256 and PBKDF2PBKDF2 is a key derivation function resistant to dictionary and rainbow-table attacks. Use when importing users via the Keycloak syncer.Keycloak

Password salt​

The algorithms salt, md5-salt, and pbkdf2-salt use a salt. Password salt controls where the salt comes from:

Password saltSaltUse it when
SetAll users of the organization share this saltYou need hashes that are compatible with another system
EmptyCasdoor generates a random salt for each user and stores it with the password hashYou set up a new organization. This is the recommended setting, because it limits the use of precomputed hash tables

Permanent avatars​

When a user signs in through an OAuth provider, such as GitHub or Google, Casdoor stores the URL of the avatar at the provider. If the provider later changes or removes that URL, the avatar breaks.

Turn on Use permanent avatar to make Casdoor download the avatar and upload it to its own storage provider. The URL then stays stable. Casdoor uploads an avatar only when it is new or has changed.

Email as username​

Turn on Use Email as username to register users without a separate username. Then:

  • At sign-up, if the username field is hidden, the email address becomes the username.
  • When a user changes the email address, the username changes with it.

Soft deletion​

By default, deleting a user removes the user from the database.

With Soft deletion turned on, deleting a user only marks the user as deleted:

  • The user stays in the user list, with Is deleted selected and a Deleted time.
  • The user can no longer sign in, and Casdoor revokes the tokens and sessions of the user.
  • To restore the user, clear Is deleted on the edit page of the user.
  • To remove the user for good, delete the user a second time.

Two settings control which pages members of the organization see in the navigation of the Casdoor admin console:

SettingApplies toDefault
Admin navbar items (navItems)AdministratorsAll pages
User navbar items (userNavItems)Regular usersNo pages. Regular users see only their own account pages

Select the pages in each tree, for example Applications, Providers, Resources, Keys, Products, Orders, and Webhooks.

When a regular user opens the Casdoor home page (/), Casdoor redirects the user to the first of the following pages that the user may see:

  1. Apps (/apps)
  2. Shortcuts (/shortcuts)
  3. The account page (/account)

Issuer name in authenticator apps​

Casdoor uses the display name of the organization, or its name if it has no display name, as the issuer of time-based one-time passwords (TOTP). Users who have several entries in an authenticator app recognize the account by it.

See also​