Alex Rivera | Logout

How to bind to a PasswordBox in MVVM

Asked 2009-09-27T16:34:25.853
305

I have come across a problem with binding to a PasswordBox. It seems it's a security risk but I am using the MVVM pattern so I wish to bypass this. I found some interesting code here (has anyone used this or something similar?)

http://www.wpftutorial.net/PasswordBox.html

It technically looks great, but I am unsure of how to retrieve the password.

I basically have properties in my LoginViewModel for Username and Password. Username is fine and is working as it's a TextBox.

I used the code above as stated and entered this

<PasswordBox ff:PasswordHelper.Attach="True"
    ff:PasswordHelper.Password="{Binding Path=Password}" Width="130"/>

When I had the PasswordBox as a TextBox and Binding Path=Password then the property in my LoginViewModel was updated.

My code is very simple, basically I have a Command for my Button. When I press it CanLogin is called and if it returns true it calls Login.
You can see I check my property for Username here which works great.

In Login I send along to my service a Username and Password, Username contains data from my View but Password is Null|Empty

private DelegateCommand loginCommand;

public string Username { get; set; }
public string Password { get; set; }


public ICommand LoginCommand
{
    get
    {
        if (loginCommand == null)
        {
            loginCommand = new DelegateCommand(
                Login, CanLogin );
        }
        return loginCommand;
    }
}

private bool CanLogin()
{
    return !str
Edit
Report

2 Answers

6

This implementation is slightly different. You pass a PasswordBox to the View through binding of a property in ViewModel. It doesn't use any command params. The ViewModel stays ignorant of the View. I have a VB VS 2010 Project that can be downloaded from SkyDrive. WPF MVVM PassWordBox Example.zip

The way that I am using PasswordBox in a WPF MVVM application is pretty simplistic and works well for me.

Basically you create a public readonly property that the View can bind to as a PasswordBox (The actual control):

Private _thePassWordBox As PasswordBox
Public ReadOnly Property ThePassWordBox As PasswordBox
    Get
        If IsNothing(_thePassWordBox) Then _thePassWordBox = New PasswordBox
        Return _thePassWordBox
    End Get
End Property

I use a backing field just to do the self initialization of the property.

Then from the Xaml you bind the Content of a ContentControl or a Control Container:

 <ContentControl Grid.Column="1" Grid.Row="1" Height="23" Width="120" Content="{Binding Path=ThePassWordBox}" HorizontalAlignment="Center" VerticalAlignment="Center" />

From there you have full control of the PasswordBox. I also use a PasswordAccessor (just a function of String) to return the Password Value when doing login or whatever else you want the Password for. In the example I have a public property in a Generic User Object Model. Example:

Public Property PasswordAccessor() As Func(Of String)

In the User Object the password string property is readonly without any backing store. It just returns the Password from the PasswordBox. Example:

Public ReadOnly Property PassWord
answered 2011-08-31T06:36:36.950
0

You find a solution for the PasswordBox in the ViewModel sample application of the WPF Application Framework (WAF) project.

However, Justin is right. Don't pass the password as plain text between View and ViewModel. Use SecureString instead (See MSDN PasswordBox).

answered 2009-10-02T17:58:38.290

Your Answer