String oldPassword = su.getPassword() ;
String userFormOldPassword = passwordEncoder.encodePassword(csupvo.getOldPassword(), null) ;
if(!oldPassword.equals(userFormOldPassword))
{
BusinessRuleException bre = new BusinessRuleException();
bre.addCodedMessage("seteUser.OldPasswordInvalid");
throw bre;
}
// new password
su.setPassword(passwordEncoder.encodePassword(csupvo.getNewPassword(), null));