# Can't login with CakePHP3

**URL:** <https://discourse.cakephp.org/t/cant-login-with-cakephp3/5745>\
**Category:** Need Help\
**Created:** [March 7, 2019, 12:41am UTC](https://discourse.cakephp.org/t/cant-login-with-cakephp3/5745 "2019-03-07T00:41:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![naldson.bc](https://avatars.discourse-cdn.com/v4/letter/n/bc8723/32.png) [@naldson.bc](https://discourse.cakephp.org/u/naldson.bc)\
**Post date:** [March 7, 2019, 12:41am UTC](https://discourse.cakephp.org/t/cant-login-with-cakephp3/5745/1 "2019-03-07T00:41:33Z")

</div>

I am trying to authenticate with CakePHP according to what I saw in the framework documentation.

What is happening now is that my first user, with id 1 normally enters the application, but all the users that I register now, always fail even me typing email and password correctly.

My code looks like this:

Form:

```auto
<div class="row">
  <?=$this->Form->create()?>
  <div class="form-group">
  <?=$this->Form->control('email', ['class' => 'form-control'])?>
  </div>
  <div class="form-group">
    <?=$this->Form->control('password', ['class' => 'form-control'])?>
  </div>
  <?=$this->Form->button('Entrar', ['class' => 'btn btn-info'])?>
  <?=$this->Html->link(__('Ainda não tem uma conta? Cadastre-se'), 
  ['action' => 'add']);?>
  <?=$this->Form->end()?>
</div>

```

Login method:

```auto
 public function login()
    {
        if ($this->request->is('POST')) {

            $user = $this->Auth->identify();

            if ($user) {
                $this->Auth->setUser($user);
                $this->Flash->success(__('Bem vindo '.$this->Auth->user()['name']));
                return $this->redirect($this->Auth->redirectUrl());
            } else {
                $this->Flash->error(__('Nome de usário ou senha incorretos'));
            }
        }
    }

```

and AppController conf:

```auto
$this->loadComponent('Auth', [
            'authenticate' => [
                'Form' => [
                    'fields' => [
                        'username' => 'email',
                        'password' => 'password',
                    ],
                ],
            ],
            'loginRedirect' => [
                'controller' => 'welcome',
                'action' => 'index',
            ],
            'logoutRedirect' => [
                'controller' => 'users',
                'action' => 'login',
            ],
        ]);
        $this->Auth->allow(['add']);

```

---

<div class="post-metadata">

**Author:** ![Zuluru](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/zuluru/32/1230_2.png) [@Zuluru](https://discourse.cakephp.org/u/Zuluru)\
**Post date:** [March 7, 2019, 5:48am UTC](https://discourse.cakephp.org/t/cant-login-with-cakephp3/5745/2 "2019-03-07T05:48:27Z")

</div>

How are you creating the new users? Are their passwords being hashed correctly before going into the database?

---

<div class="post-metadata">

**Author:** ![naldson.bc](https://avatars.discourse-cdn.com/v4/letter/n/bc8723/32.png) [@naldson.bc](https://discourse.cakephp.org/u/naldson.bc)\
**Post date:** [March 7, 2019, 10:25am UTC](https://discourse.cakephp.org/t/cant-login-with-cakephp3/5745/3 "2019-03-07T10:25:37Z")

</div>

In my database, all data is normal.

I’m creating the users this way:

```auto
public function add()
    {
        $user = $this->Users->newEntity();

        if ($this->request->is('POST')) {

            $userPatchEntity = $this->Users->PatchEntity($user,
                $this->request->getData());
            $userPatchEntity->balance = $userPatchEntity->salary+$userPatchEntity->extra_lace;

            if ($this->Users->save($user)) {
                $this->Flash->success('Cadastro realizado com sucesso');
                return $this->redirect(['action' => 'login']);
            } else {
                $this->Flash->error('Não foi possível realizar o seu cadastro');
            }
        }

```

And yes

```auto
public function _setPassword() {
    return (new DefaultPasswordHasher())->hash($password);
}

```
