[Django]-How to retrieve password in django

48đź‘Ť

âś…

No. It’s impossible, by design. But there should never be a need to do it anyway.

17đź‘Ť

Due to security restrictions the password hash method is one way. You will need to reset that users password.

Try using the set_password(raw_password) method to give the user a new password. Remember to call the save() method to ensure you save the change to the database.

u = User.objects.get(username__exact=username)
u.set_password(raw_password)
u.save()

8đź‘Ť

You can check if the password is correct with:

u.check_password("your password")

This method and u.set_password("you password") solves all of your problems.

sha1$f0971$441cac8f604d49869e33ca125a76253a02fef64e is:

hash function algorithm $ salt $ hash code

6đź‘Ť

no. and there shouldn’t be. as part of the security, passwords are passed through a one-way function before they are saved, so that they aren’t reveled if the database is compromised

what you can do is replace the user’s password with one you know. this is how (good) site’s “forgot your password” functions work: they send you a new random password, not your old one, since they (shouldn’t) have access to it

👤second

4đź‘Ť

No, the field contains the salted hash of the password. from the string we know it’s SHA1 function. If you have the password, you will be able to produce the same hash value which acts as the footprint. For security reason there should be now way to recover the password in a economical means (you can still brute force, but will take long time).,

0đź‘Ť

There is no way you can get the existing password because that password is been converted to salt hash.

Leave a comment