Encrypt passwords in transit
This guide explains how to turn on the password obfuscator of an organization. The Casdoor frontend then encrypts passwords before it sends them to the server, in addition to the encryption of the HTTPS connection.
Learning outcomes
- Choose the obfuscation algorithm and key of an organization.
- Know which API fields are encrypted and how clients without obfuscation behave.
What you need
- Administrator access to the organization in the Casdoor admin console
Turn on the obfuscator
-
In the Casdoor admin console, open the edit page of the organization.
-
Select an option in Password obfuscator:
选项 Passwords are sent PlainAs plaintext AESEncrypted with AES DESEncrypted with DES 
-
When you select
AESorDES, Casdoor generates a key and fills in Password obf key. To use your own key, replace the value. If the key doesn't fit the algorithm, Casdoor shows an error with the expected format. -
Save the organization.
Encrypted fields
| API | 加密的字段 |
|---|---|
Sign in (/api/login) | 密码 |
Set password (/api/set-password) | oldPassword、newPassword |
The frontend encrypts these fields. The backend decrypts them with the algorithm and key of the organization and then processes them as usual.
Clients without obfuscation
The set-password API accepts obfuscated passwords and plaintext passwords. If the organization has no obfuscator, or if decryption fails, the API treats the value as plaintext. The following clients therefore keep working:
- SDKs that don't support the obfuscator yet
- Direct API calls with plaintext passwords
- 已有的集成