Migrate from Inversoft Passport to FusionAuth

1. Overview

If you are currently an Inversoft Passport customer and looking to move to FusionAuth you have come to the right place. Here you’ll find important information on API changes, database upgrade procedures, etc.

We have attempted to build an exhaustive list of changes you will need to be aware of, but please do plan to test your migration and ask for assistance from the FusionAuth team during your migration.

2. Naming Changes

In addition to the obvious change of Passport to FusionAuth, as you read through the documentation and update your integration be aware of the following name changes.

Table 1. Name changes
Old name New Name Description

Passport

FusionAuth

Passport is now known as FusionAuth

passport.properties

fusionauth.properties

The Passport configuration file is now named fusionauth.properties.

Passport Backend

FusionAuth App

The Passport Backend which refers to the webservice that services APIs and provides the UI is now referred as FusionAuth or FusionAuth App.

passport-backend

fusionauth-app

The passport-backend which was the name of the package or bundle which contained the Passport Backend service will now be called fusionauth-app.

Passport Search Search

FusionAuth Search

The Passport Search Search which refers to the webservice that provides search capability to FusionAuth is now referred to FusionAuth Search.

passport-search-engine

fusionauth-search

The passport-search-engine which was the name of the package or bundle which contained the Passport Search Engine service will now be called fusionauth-search.

X-Passport-TenantId

X-FusionAuth-TenantId

The X-Passport-TenantId which was used if you had configured more than one tenant to scope an API request to a particular tenant should be changed to X-FusionAuth-TenantId.

3. License Changes

Because FusionAuth is no longer licensed in a traditional way, no license is required and no license checks are performed during a User create or Registration process.

4. Breaking Changes

Review the following breaking changes when moving from Passport to FusionAuth. A breaking change means that compatibility has been broken and if your integration will break if you do not review the following changes and update your integration accordingly.

4.1. API Changes

  • When the Search Engine service is down or un-reachable a new status code of 503 will be returned. Previously this error condition would have returned a 500 status code.

  • If you were passing the Tenant Id in an HTTP header, this header X-Passport-TenantId should now be provided as X-FusionAuth-TenantId.

  • Application API

    • Free form data is now available on the Application object, see application.data

  • Audit Log API

    • auditLog.data.attributes moved to auditLog.data

    • auditLog.data.newValue moved to auditLog.newValue

    • auditLog.data.oldValue moved to auditLog.oldValue

    • auditLog.data.reason moved to auditLog.reason

  • Group API

    • group.data.attributes moved to group.data

  • Group Member API

    • groupMember.data.attributes moved to groupMember.data

  • SystemConfiguration API

    • systemConfiguration.failedAuthenticationUserActionId moved to systemConfiguration.failedAuthenticationConfiguration.userActionId

    • systemConfiguration.forgotEmailTemplateId moved to systemConfiguration.emailConfiguration.forgotPasswordEmailTemplateId

    • systemConfiguration.setPasswordEmailTemplateId moved to systemConfiguration.emailConfiguration.setPasswordEmailTemplateId

    • systemConfiguration.verificationEmailTemplateId moved to systemConfiguration.emailConfiguration.verificationEmailTemplateId

    • systemConfiguration.verifyEmail moved to systemConfiguration.emailConfiguration.verifyEmail

    • systemConfiguration.verifyEmailWhenChanged moved to systemConfiguration.emailConfiguration.verifyEmailWhenChanged

  • Tenant API

    • tenant.data.attributes moved to tenant.data

    • tenant.forgotEmailTemplateId moved to tenant.data

    • tenant.setPasswordEmailTemplateId moved to tenant.emailConfiguration.forgotPasswordEmailTemplateId

    • tenant.verificationEmailTemplateId moved to tenant.emailConfiguration.verificationEmailTemplateId

    • tenant.verifyEmail moved to tenant.emailConfiguration.verifyEmail

    • tenant.verifyEmailWhenChanged moved to tenant.emailConfiguration.verifyEmailWhenChanged

  • User API

    • user.data.attributes moved to user.data

    • user.data.preferredLanguages moved to user.preferredLanguages

    • Removed childIds and parentId

  • User Registration API

    • userRegistration.data.attributes moved to userRegistration.data

    • userRegistration.data.timezone moved to userRegistration.timezone

    • userRegistration.data.preferredLanguages moved to userRegistration.preferredLanguages

4.2. Client Libraries

If you were using a Passport Client library please upgrade to the FusionAuth version. See Client Libraries

4.3. Removed Features

  • Parent and Child relationships between users was removed in FusionAuth. This feature is planned to be re-introduced with better support for a family structure and a more flexible relationship model. If you currently utilize this feature please contact the FusionAuth team for assistance.

5. Database Migration

Due to the data model changes that were made in FusionAuth your database schema will need to be updated. Please be aware that you Passport database MUST be upgraded to the latest version prior to migrating to FusionAuth. The latest Passport version is 1.22.4, the easiest way to upgrade your schema is to install the latest version of Passport and start up the service and allow Maintenance Mode to upgrade your database for you. Once this is complete you may then run the migration script.

Stop! Read me

Prior to upgrading to FusionAuth, you MUST upgrade Passport to version 1.22.4. If you do not, this will not work and you will need to restore your database from a backup.

5.1. MySQL

The following is the MySQL database migration. Please ensure you fully test this migration or contact the FusionAuth team for assistance.

-- Passport to FusionAuth

-- Update the version.
UPDATE version
SET version = '1.0.0';

CREATE TABLE instance (
  id         BINARY(16) NOT NULL,
  support_id BINARY(16) NULL
)
  ENGINE = innodb
  CHARACTER SET utf8mb4
  COLLATE utf8mb4_bin;

-- Insert instance
INSERT INTO instance(id) VALUES (random_bytes(16));

-- Rename the forgot password
ALTER TABLE system_configuration
  CHANGE COLUMN forgot_email_templates_id forgot_password_email_templates_id BINARY(16) NULL;
ALTER TABLE tenants
  CHANGE COLUMN forgot_email_templates_id forgot_password_email_templates_id BINARY(16) NULL;

-- Delete the system_configuration columns (verify_email and verify_email_when_changed didn't make it through and need to be manually updated)
UPDATE system_configuration SET data = CONCAT(
  SUBSTRING(data, 1, LENGTH(data) - 1),
  ',"data":{},"emailConfiguration":',
  SUBSTRING(COALESCE(email_configuration, '{}'), 1, LENGTH(email_configuration) - 1),
  ',"verifyEmail":',
  IF(verify_email, 'true', 'false'),
  ',"verifyEmailWhenChanged":',
  IF(verify_email_when_changed, 'true', 'false'),
  '},"passwordValidationRules":',
  COALESCE(password_validation_rules, '{}'),
  '}'
  );
ALTER TABLE system_configuration
  DROP COLUMN email_configuration,
  DROP COLUMN password_expiration_days,
  DROP COLUMN password_validation_rules,
  DROP COLUMN verify_email,
  DROP COLUMN verify_email_when_changed;

-- Add timezone to registration
ALTER TABLE user_registrations
  ADD COLUMN timezone VARCHAR(255) NULL;

-- Delete parent/child relationships
ALTER TABLE users
  DROP COLUMN parent_id,
  DROP COLUMN parental_consent_type;

-- Clean up application (two cases because some old Applications might have a data column with the value '{}' only)
UPDATE applications SET data = CONCAT(
  SUBSTRING(data, 1, LENGTH(data) - 1),
  ',"cleanSpeakConfiguration":',
  COALESCE(clean_speak_configuration, '{}'),
  ',"data":{},"oauthConfiguration":',
  COALESCE(oauth_configuration, '{}'),
  '}'
  ) WHERE data != '{}';
UPDATE applications SET data = CONCAT(
  '{"cleanSpeakConfiguration":',
  COALESCE(clean_speak_configuration, '{}'),
  ',"data":{},"oauthConfiguration":',
  COALESCE(oauth_configuration, '{}'),
  '}'
  ) WHERE data = '{}';
ALTER TABLE applications
  DROP COLUMN clean_speak_configuration,
  DROP COLUMN oauth_configuration;

-- Fix the data column for audit_logs
UPDATE audit_logs SET data = CONCAT('{"data"', SUBSTRING(data, 14)) WHERE data LIKE '{"attributes"%';

-- Fix the data column for groups
UPDATE groups SET data = CONCAT('{"data"', SUBSTRING(data, 14)) WHERE data LIKE '{"attributes"%';

-- Fix the data column for group_members
UPDATE group_members SET data = CONCAT('{"data"', SUBSTRING(data, 14)) WHERE data LIKE '{"attributes"%';

-- Fix the data column for users
UPDATE users SET data = CONCAT('{"data"', SUBSTRING(data, 14)) WHERE data LIKE '{"attributes"%';

-- Fix the data column for user_registrations
UPDATE user_registrations SET data = CONCAT('{"data"', SUBSTRING(data, 14)) WHERE data LIKE '{"attributes"%';

-- Fix the data column for tenants
UPDATE tenants SET data = REPLACE(data, '"emailConfiguration":{"enabled":true}', '"emailConfiguration":{"enabled":true');
UPDATE tenants SET data = REPLACE(data, '"emailConfiguration":{"enabled":false}', '"emailConfiguration":{"enabled":false');
UPDATE tenants SET data = CONCAT(data, '}');

-- Fix the internal API key
DELETE FROM authentication_keys WHERE id LIKE '__internal_%' AND meta_data LIKE '%"cacheReloader"%';
INSERT INTO authentication_keys(id, permissions, meta_data, tenants_id) VALUES (concat('__internal_', replace(to_base64(random_bytes(64)), '\n', '')),
                                                                                '{"endpoints": {"/api/cache/reload": ["POST"]}}', '{"attributes": {"internalCacheReloader": "true"}}', NULL);

5.2. PostgreSQL

The following is the PostgreSQL database migration. Please ensure you fully test this migration or contact the FusionAuth team for assistance.

\set ON_ERROR_STOP true

-- Passport to FusionAuth

-- Update the version.
UPDATE version
SET version = '1.0.0';

CREATE TABLE instance (
  id         UUID NOT NULL,
  support_id UUID NULL
);

-- Insert instance
INSERT INTO instance(id)
VALUES (md5(random() :: text || clock_timestamp() :: text) :: uuid);

-- Rename the forgot password
ALTER TABLE system_configuration
  RENAME COLUMN forgot_email_templates_id TO forgot_password_email_templates_id;
ALTER TABLE tenants
  RENAME COLUMN forgot_email_templates_id TO forgot_password_email_templates_id;

-- Delete the system_configuration columns
-- Delete the system_configuration columns (verify_email and verify_email_when_changed didn't make it through and need to be manually updated)
UPDATE system_configuration SET data =
  SUBSTR(data, 1, LENGTH(data) - 1) ||
  ',"data":{},"emailConfiguration":' ||
  SUBSTR(COALESCE(email_configuration, '{}'), 1, LENGTH(email_configuration) - 1) ||
  ',"verifyEmail":' ||
  CASE WHEN verify_email=true THEN 'true' ELSE 'false' END ||
  ',"verifyEmailWhenChanged":' ||
  CASE WHEN verify_email_when_changed=true THEN 'true' ELSE 'false' END ||
  '},"passwordValidationRules":' ||
  COALESCE(password_validation_rules, '{}') ||
  '}';
ALTER TABLE system_configuration
  DROP COLUMN email_configuration,
  DROP COLUMN password_expiration_days,
  DROP COLUMN password_validation_rules,
  DROP COLUMN verify_email,
  DROP COLUMN verify_email_when_changed;

-- Add timezone to registration
ALTER TABLE user_registrations
  ADD COLUMN timezone VARCHAR(255) NULL;

-- Delete parent/child relationships
ALTER TABLE users
  DROP COLUMN parent_id,
  DROP COLUMN parental_consent_type;

-- Clean up application (two cases because some old Applications might have a data column with the value '{}' only)
UPDATE applications SET data =
  SUBSTR(data, 1, LENGTH(data) - 1) ||
  ',"cleanSpeakConfiguration":' ||
  COALESCE(clean_speak_configuration, '{}') ||
  ',"data":{},"oauthConfiguration":' ||
  COALESCE(oauth_configuration, '{}') ||
  '}' WHERE data != '{}';
UPDATE applications SET data =
  '{"cleanSpeakConfiguration":' ||
  COALESCE(clean_speak_configuration, '{}') ||
  ',"data":{},"oauthConfiguration":' ||
  COALESCE(oauth_configuration, '{}') ||
  '}' WHERE data = '{}';
ALTER TABLE applications
  DROP COLUMN clean_speak_configuration,
  DROP COLUMN oauth_configuration;

-- Fix the data column for audit_logs
UPDATE audit_logs SET data = '{"data"' || SUBSTR(data, 14) WHERE data LIKE '{"attributes"%';

-- Fix the data column for groups
UPDATE groups SET data = '{"data"' || SUBSTR(data, 14) WHERE data LIKE '{"attributes"%';

-- Fix the data column for group_members
UPDATE group_members SET data = '{"data"' || SUBSTR(data, 14) WHERE data LIKE '{"attributes"%';

-- Fix the data column for users
UPDATE users SET data = '{"data"' || SUBSTR(data, 14) WHERE data LIKE '{"attributes"%';

-- Fix the data column for user_registrations
UPDATE user_registrations SET data = '{"data"' || SUBSTR(data, 14) WHERE data LIKE '{"attributes"%';

-- Fix the data column for tenants
UPDATE tenants SET data = REPLACE(data, '"emailConfiguration":{"enabled":true}', '"emailConfiguration":{"enabled":true');
UPDATE tenants SET data = REPLACE(data, '"emailConfiguration":{"enabled":false}', '"emailConfiguration":{"enabled":false');
UPDATE tenants SET data = data || '}';

-- Fix the internal API key
DELETE FROM authentication_keys WHERE id LIKE '__internal_%' AND meta_data LIKE '%"cacheReloader"%';
INSERT INTO authentication_keys(id, permissions, meta_data, tenants_id) VALUES ('__internal_' || replace(encode(md5(random()::text || clock_timestamp()::text)::bytea || md5(random()::text || clock_timestamp()::text)::bytea, 'base64'), E'\n', ''),
                                                                                '{"endpoints": {"/api/cache/reload": ["POST"]}}', '{"attributes": {"internalCacheReloader": "true"}}', NULL);