# Password migration?

**URL:** <https://forum.litium.com/t/password-migration/600>\
**Category:** Questions\
**Created:** [February 18, 2019, 8:59pm UTC](https://forum.litium.com/t/password-migration/600 "2019-02-18T20:59:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robin.w](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.litium.com/robin.w/32/75_2.png) [@Robin.w](https://forum.litium.com/u/Robin.w)\
**Post date:** [February 18, 2019, 8:59pm UTC](https://forum.litium.com/t/password-migration/600/1 "2019-02-18T20:59:07Z")

</div>

We have implemented a PasswordServiceDecorator to allow for password migrations and as per an example in this forum, we try to override VerifyHashedPassword to check for a password prefix and use custom logic.

But before I get to the VerifyHashedPassword breakpoint the PasswordSignIn throws an exception becasue of a invalid \* sign in the password has:

var result = \_authenticationService.PasswordSignIn(loginName, password, newPassword);

`Undantagsinformation: System.FormatException: Indata är ingen giltig Base-64-sträng eftersom den innehåller ett tecken som inte har Base-64-format, fler än två utfyllnadstecken eller ett ogiltigt tecken som inte är ett blankstegstecken.`

Do I need to create a AuthenticationServiceDecorator aswell?

**Update:** The VerifyHashedPassword don’t seem to be called at all, not even on successful logins, something has changed in litium 7 right? The decoratior works when creating new users, but never ends up in VerifyHashedPassword

Litium version: 7.1

---

<div class="post-metadata">

**Author:** ![patric.forsgard](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.litium.com/patric.forsgard/32/10_2.png) [@patric.forsgard](https://forum.litium.com/u/patric.forsgard)\
**Post date:** [February 18, 2019, 10:32pm UTC](https://forum.litium.com/t/password-migration/600/2 "2019-02-18T22:32:12Z")

</div>

It’s little different ways the code is executed and sometimes (some methods) are using the `PasswordService` and other are using the `Litium.Application.Security.Cryptography.PasswordHasher` directly. The later of them is used in both cases but I think that class not allows decorating with new logic and instead you need to inherit and make an derivied implementation (you mean in that case need to set remove the default type in web.config section litium\foundation\plugins\types to ensure correct class is loaded).

The `PasswordService` service only return an `bool` that contains the result of the hash, the `PasswordHasher` return an enum that have an option to set that the password need to be rehashed and the `AuthenticationService` is then automatic handle the rehashing and updating the database with updated password hash.

---

<div class="post-metadata">

**Author:** ![Robin.w](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.litium.com/robin.w/32/75_2.png) [@Robin.w](https://forum.litium.com/u/Robin.w)\
**Post date:** [February 19, 2019, 1:38pm UTC](https://forum.litium.com/t/password-migration/600/3 "2019-02-19T13:38:45Z")

</div>

Thanks, but i don’t realt understand the web config part,

Should i add the newly created type here?

```auto
                <assemblies>
                </assemblies>
                <types>
                </types>
            </plugins> 

```

Or do I need to create some kind of replacement mapping for `Litium.Application.Security.Cryptography.PasswordHasher to my extention?

_Edit_: Ok it seams to work without doing anyting with the web.config but if you have time to explain, pleas do 🙂

---

<div class="post-metadata">

**Author:** ![patric.forsgard](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.litium.com/patric.forsgard/32/10_2.png) [@patric.forsgard](https://forum.litium.com/u/patric.forsgard)\
**Post date:** [February 19, 2019, 6:10pm UTC](https://forum.litium.com/t/password-migration/600/4 "2019-02-19T18:10:15Z")

</div>

We have some description on [https://docs.litium.com/documentation/get-started/web\_config#plugins](https://docs.litium.com/documentation/get-started/web_config#plugins) hope it will help to understand; otherwise you can create a new thread about the subject and we continue in that.
