how to compare a password for changing password ?

Recommended Posts

adrianmak    58

I'm going to build a form for front-end user password changing.

There should be three input fields

current password

new password

confirm new password

I knew that, password stored in database is hashed.

How could I compare the input current password with the password stored in database ?

Share this post

Link to post
Share on other sites
LostKobrakai    4,313

Just like you're comparing it for the login: hash the "current password" and compare it with the database entry. But pw does have you covered:

  • Like 6

Share this post

Link to post
Share on other sites
Martijn Geerts    3,178


Firstly it takes alot of effort in terms of time bandwidth to document it all next to the documentation that is already provided in the source code. Then it is difficult to have the documentation that is not in the code to be in sync with the 'changing' documentation. Then keep in mind that most 'advanced' users will look in the source code to find 'documentation' or figure out what is going on right there anyway without searching decoupled documentation. Documentation should be written by 'advanced' users, on the other hand, those users are likely to use the source code to lookup methods and stuff, so they are not the 'real users' of that decoupled documentation. Then there is the NOT fun part of documenting. In a lively environment as ProcessWire, new methods are added other methods become deprecated. It's hard to keep track of all those. 

I think we all wish documentation stays in sync and is complete. On the other-hand, when looking in the source code of ProcessWire you will recognise the effort Ryan takes to document and comment. I have to say, that the documentation in the code base is good and keeps getting better over time.

  • Like 5

Share this post

Link to post
Share on other sites

I am trying to do the same thing as adrianmak - had you figured out how to do this?

Do you need the 'current password' field? I think 'new password' and 'confirm new pass' should be enough if the user has access to this form. Or am I missing something?

You can use $user->pass->matches($inputPass) to check the input, but, to be clear, there is no PW function or similar that adds the same 'change password' thing that is in the admin profile edit?

Password is the same as any other input field? You can save a password from a form input simply with this?


$user->pass = $sanitizer->text($input->post->pass);


And then PW takes care of the hash stuff? The hash stuff is confusing... Or are there specific password checks or processes to take care of?


I see there is an InputfieldPassword.module, probably part of the forms API that I still can't wrap my head around. I guess you should use that somehow?

Adding this, as a quick test, produces a server error:



$field = $modules->get("InputfieldPassword");
$field->label = "Set new Password";
$field->required = 1;




Share this post

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

  • Similar Content

    • By Slav
      Hey guys... Ok so I have a problem with a registration form password inputfield... The problem is that InputfieldPassword.js and InputfieldPassword.css are not loaded/fired. Or I dont even know exactly what is happening... Im pretty new to processwire and the website was not created by me so Im trying to figure out what has been done and how processwire works. Anyway this is how the form looks right now:

      ...and as you can see the styling is off (password validation check in particular)... this is what I see when page is loaded (without adding any input)... it looks like js and css files from wire/modules/Inputfield/InputfieldPassword are not firing... I dont know how it is supposed to work exactly so I dont even know where to start.
      Maybe someone has had similar problem and know an easy fix or can navigate me to what could cause this situation in PW.
      Oh by the way this problem occured when upgrading the PW version (current version 3.0.65)... everything else is ok... this is the only problem that has been found after upgrade...
      Appreciate all the help!
    • By jen
      Yesterday we somehow lost access to all current admin, superuser/passwords to processwire.  We tried using the reset password form and nothing was sent.  We began noticing some of the menu buttons went missing as well as some photos.  Any suggestions how to resolve the login issue?
    • By modifiedcontent
      I have a simple front-end password update form like this:
      In the browser the label of the second field shows up as follows:
      I can't figure out what is changing the label, what is inserting /processwire/ and reformatting the thing. Is this something in PW? A "helpful" thing that browsers do?
      The problem disappears if I simply rename the second field to 'Confirm Password'.
      So my problem is solved, but I'll leave this here in case this is some kind of bug.
    • By modifiedcontent
      How do you get the same 'set password' form/input fields on the front-end as in the admin area?
      I have a working front-end version, but the admin version has some nifty stuff around it. Should be easy to get the same on the front-end, right?
    • By didhavn
      Hey all.
      I just came across a potential error in the FieldtypePassword.
      I have a password field added to some templates to protect the pages. However, whenever I want to save a page, I get the error of "required fiield missing"...that the password field is required and missing. But, the field is not set to required.
      Can anybody confirm that and/or has a solution?
      Best, Lukas