# Hasher / authentication error in Django 5

**URL:** <https://forum.djangoproject.com/t/hasher-authentication-error-in-django-5/28805>\
**Category:** Mystery Errors\
**Created:** [March 7, 2024, 9:18am UTC](https://forum.djangoproject.com/t/hasher-authentication-error-in-django-5/28805 "2024-03-07T09:18:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![csabbooca](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/csabbooca/32/19687_2.png) [@csabbooca](https://forum.djangoproject.com/u/csabbooca)\
**Post date:** [March 7, 2024, 9:18am UTC](https://forum.djangoproject.com/t/hasher-authentication-error-in-django-5/28805/1 "2024-03-07T09:18:59Z")

</div>

Dear Community,

we recently tried updating to Django 5.0.3, and noticed that we cannot authenticate our existing users anymore.

We use the authenticate() function from django.contrib.auth, and this works perfectly in the 4.2 line. However, after upgrading to the 5.0 line, we started to get strange errors about password field cannot be updated in the DB. I do not understand why a password reading and validating operation would write anything to the DB.

Is there something i am missing or this is some bug?

Please see below the exact stack trace:

```auto
Internal Server Error: /api/login/
Traceback (most recent call last):
  File "/opt/venv/lib/python3.12/site-packages/django/core/handlers/exception.py", line 55, in inner
    response = get_response(request)
               ^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv/lib/python3.12/site-packages/django/core/handlers/base.py", line 197, in _get_response
    response = wrapped_callback(request, *callback_args, **callback_kwargs)
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "<directory_of_our_application>/views.py", line 63, in login
    user_instance = authenticate(request, username = username, password = password)
                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv/lib/python3.12/site-packages/django/views/decorators/debug.py", line 75, in sensitive_variables_wrapper
    return func(*func_args, **func_kwargs)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv/lib/python3.12/site-packages/django/contrib/auth/ __init__.py", line 79, in authenticate
    user = backend.authenticate(request, **credentials)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv/lib/python3.12/site-packages/django/contrib/auth/backends.py", line 48, in authenticate
    if user.check_password(password) and self.user_can_authenticate(user):
       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv/lib/python3.12/site-packages/django/contrib/auth/base_user.py", line 125, in check_password
    return check_password(raw_password, self.password, setter)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv/lib/python3.12/site-packages/django/contrib/auth/hashers.py", line 77, in check_password
    setter(password)
  File "/opt/venv/lib/python3.12/site-packages/django/contrib/auth/base_user.py", line 123, in setter
    self.save(update_fields=["password"])
  File "/opt/venv/lib/python3.12/site-packages/django/contrib/auth/base_user.py", line 78, in save
    super().save(*args, **kwargs)
  File "/opt/venv/lib/python3.12/site-packages/django/db/models/base.py", line 822, in save
    self.save_base(
  File "/opt/venv/lib/python3.12/site-packages/django/db/models/base.py", line 909, in save_base
    updated = self._save_table(
              ^^^^^^^^^^^^^^^^^
  File "/opt/venv/lib/python3.12/site-packages/django/db/models/base.py", line 1042, in _save_table
    raise DatabaseError("Save with update_fields did not affect any rows.")
django.db.utils.DatabaseError: Save with update_fields did not affect any rows.

```

---

<div class="post-metadata">

**Author:** ![antoinehumbert](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/antoinehumbert/32/14851_2.png) [@antoinehumbert](https://forum.djangoproject.com/u/antoinehumbert)\
**Post date:** [March 7, 2024, 10:31am UTC](https://forum.djangoproject.com/t/hasher-authentication-error-in-django-5/28805/2 "2024-03-07T10:31:28Z")

</div>

The password is probably updated behind the scene because of the change of iterations number in the PKBDF2 hasher (see [Django 5.0 release notes | Django documentation | Django](https://docs.djangoproject.com/en/5.0/releases/5.0/#django-contrib-auth)).

The fact that an update is attempted means that authentication succeeded, but as the number of iterations for _actual_ password does not match the new requirements, the password is updated with this new number of iterations.

So, yes, the write to db is _normal_. But, I don’t know why the update fails in such manner. Do you have a specific user model ? If so, can you share its definition ?

---

<div class="post-metadata">

**Author:** ![csabbooca](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/csabbooca/32/19687_2.png) [@csabbooca](https://forum.djangoproject.com/u/csabbooca)\
**Post date:** [March 7, 2024, 11:59am UTC](https://forum.djangoproject.com/t/hasher-authentication-error-in-django-5/28805/3 "2024-03-07T11:59:19Z")

</div>

Thank you for the clarification. I would not have expected that iteration number change would result in a change of the hash, therefore i would not have expected a DB write - but still i can accept and be thankful for the explanation 🙂

I do have a custom user model which unfortunately i cannot share, but regarding the password it just routes back to the AbstractBaseUser model.

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [March 7, 2024, 12:57pm UTC](https://forum.djangoproject.com/t/hasher-authentication-error-in-django-5/28805/4 "2024-03-07T12:57:15Z")

</div>

The details - and possible explanation for the error are documented at [Password upgrading](https://docs.djangoproject.com/en/5.0/topics/auth/passwords/#password-upgrading).  
Are you using a custom or customized password hashing technique?

---

<div class="post-metadata">

**Author:** ![csabbooca](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/csabbooca/32/19687_2.png) [@csabbooca](https://forum.djangoproject.com/u/csabbooca)\
**Post date:** [March 8, 2024, 11:15am UTC](https://forum.djangoproject.com/t/hasher-authentication-error-in-django-5/28805/5 "2024-03-08T11:15:26Z")

</div>

Thank you, Ken, for your reply!

Indeed, “_When users log in, if their passwords are stored with anything other than the preferred algorithm, Django will automatically upgrade the algorithm to the preferred one._” explains why there is DB writing.

And it seems i found what caused the `django.db.utils.DatabaseError: Save with update_fields did not affect any rows.`, i.e. what i missed earlier: [Migrating existing UUIDField on MariaDB 10.7+](https://docs.djangoproject.com/en/5.0/releases/5.0/#migrating-existing-uuidfield-on-mariadb-10-7)

Thank you again for the guidance,
