# AuthService.updateCustomPassword custom logic

```ts
/* -------------------------- start custom logic here ------------------------- */
const authManager = new AuthManager();
const {data} = body;
if (!data?.old_password) throw new exceptions.UnprocessableEntityException('Old password is required');
if (!data?.password) throw new exceptions.UnprocessableEntityException('New password is required');

const doc = await this.userModel.findOne({ _id: authData.current.user._id, is_deleted: false });
if (!doc) throw new exceptions.UnauthorizedException('User not found');
if (doc.attributes.is_suspended) throw new exceptions.UnauthorizedException('User suspended');

const isValidPassword = await authManager.verifyPassword(data.old_password, doc.password);
if (!isValidPassword) throw new exceptions.UnauthorizedException('Invalid password');

const { salt, password } = await authManager.hashPassword(data.password);
doc.salt = salt;
doc.password = password;
await doc.save();

const payload: Jsm.Core.Security.JWTUserAuthPayload = {
  _id: doc._id.toString(),
  tracking_id: doc.tracking_id,
  role: doc.role,
  space: 'default'
};
const token = authManager.generateToken(payload, 'default', false, config.security.jwt);
const refresh_token = authManager.generateToken(payload, 'default', true, config.security.jwt);

// dispatch event
this.eventDispatcher.dispatch<Jsm.Core.Auth.Events.Payloads.UserSignedIn>(authEvents.userSignedIn, {
  data: mapDocumentToExposed(doc)
});
result.data = {
  user: mapDocumentToExposed(doc),
  token,
  refresh_token
};
/* -------------------------- end custom logic here ------------------------- */
		
```

