跳到主内容

Encrypt passwords in transit

This guide explains how to turn on the password obfuscator of an organization. The Casdoor frontend then encrypts passwords before it sends them to the server, in addition to the encryption of the HTTPS connection.


Learning outcomes​

  • Choose the obfuscation algorithm and key of an organization.
  • Know which API fields are encrypted and how clients without obfuscation behave.

What you need​

  • Administrator access to the organization in the Casdoor admin console

Turn on the obfuscator​

  1. In the Casdoor admin console, open the edit page of the organization.

  2. Select an option in Password obfuscator:

    选项Passwords are sent
    PlainAs plaintext
    AESEncrypted with AES
    DESEncrypted with DES

    Password obfuscator field of the organization

  3. When you select AES or DES, Casdoor generates a key and fills in Password obf key. To use your own key, replace the value. If the key doesn't fit the algorithm, Casdoor shows an error with the expected format.

    Password obf key field of the organization

  4. Save the organization.

Encrypted fields​

API加密的字段
Sign in (/api/login)密码
Set password (/api/set-password)oldPassword、newPassword

The frontend encrypts these fields. The backend decrypts them with the algorithm and key of the organization and then processes them as usual.

Clients without obfuscation​

The set-password API accepts obfuscated passwords and plaintext passwords. If the organization has no obfuscator, or if decryption fails, the API treats the value as plaintext. The following clients therefore keep working:

  • SDKs that don't support the obfuscator yet
  • Direct API calls with plaintext passwords
  • 已有的集成

See also​