Bcrypt + Sequelize密码不保存为DB中的哈希值

问题描述 投票:1回答:1

Sequelize + Bcrypt不将密码存储在DB中作为哈希

正如标题所说,每当我尝试将用户存储到我的SQLite数据库中时,控制台就会输出密码作为哈希值,但是当我使用DBbrowser查看数据库时,我可以看到明文密码。

模型

// const Promise = require('bluebird')
const bcrypt = require('bcrypt')

async function hashPassword (user, options) {
  if (!user.changed('password')) {
    return 0
  }
  const SALT_FACTOR = 8
  await bcrypt.hash(user.password, SALT_FACTOR, (err, hash) => {
    if (err) {
      console.log(err)
    }
    // user.setDataValue('password', hash)
    user.password = hash
    console.log(user)
  })
}

module.exports = (sequelize, DataTypes) => {
  const User = sequelize.define('User', {
    email: {
      type: DataTypes.STRING,
      unique: true
    },
    password: DataTypes.STRING
  }, {
    hooks: {
      beforeSave: hashPassword,
      beforeCreate: hashPassword
    }
  })

  User.prototype.comparePassword = function (password) {
    bcrypt.compare(password, this.password, function (res, err) {
      if (res) {
        console.log(res)
      } else {
        console.log(err)
      }
    })
    return bcrypt.compare(password, this.password)
  }

  return User
}

控制器

module.exports = {
  async register (req, res) {
    try {
      const user = await User.create(req.body)
      const userJson = user.toJSON()
      res.send({
        user: userJson,
        token: jwtSignUser(userJson)
      })
    } catch (err) {
      // e-mail already exists or such
      res.status(400).send({
        error: 'This email address is already in use'
      })
    }
  },
  async login (req, res) {
    try {
      // Grab user input
      const { email, password } = req.body
      const user = await User.findOne({
        where: {
          email: email
        }
      })
      // Check to see if user is in db
      if (!user) {
        res.status(403).send({
          error: 'the login information was incorrect / Not Found'
        })
      }
      // Check to see if password is valid
      const isPasswordValid = await user.comparePassword(password)
      if (!isPasswordValid) {
        return res.status(403).send({
          error: 'The login information was incorrect'
        })
      }
      // return user using toJSON()
      const userJson = user.toJSON()
      res.send({
        user: userJson,
        token: jwtSignUser(userJson)
      })
    } catch (e) {
      res.status(500).send({ error: 'An error occured attempting to login' })
      console.log(e)
    }
  }
}

为了详细说明,每当我创建用户时,我都会收到以下信息:

{
    "user": {
        "id": 1,
        "email": '[email protected]",
        "password": "$2b$08$SYYXU/GDSCFsp3MVeuqrduI0lOLHeeub7whXiaMMoVxO53YJry.1i",
        "updatedAt": "2018-09-07T22:44:12.944Z",
        "createdAt": "2018-09-07T22:44:12.944Z"
    },
    "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6MSwiZW1haWwiOiJTVVBCUkhVQGxvbC5jb20iLCJwYXNzd29yZCI6IiQyYiQwOCRTWVlYVS9HRFNDRnNwM01WZXVxcmR1STBsT0xIZWV1Yjd3aFhpYU1Nb1Z4TzUzWUpyeS4xaSIsInVwZGF0ZWRBdCI6IjIwMTgtMDktMDdUMjI6NDQ6MTIuOTQ0WiIsImNyZWF0ZWRBdCI6IjIwMTgtMDktMDdUMjI6NDQ6MTIuOTQ0WiIsImlhdCI6MTUzNjM2MDI1MywiZXhwIjoxNTM2OTY1MDUzfQ.mDaeIikzUcV_AGTuklnLucx9mVyeScGpMym1y0kJnsg"
}

对我来说,数据库成功地删除了我的密码并存储了它。我这个悬而未决的问题是我相信它会导致bcrypt.compare函数吐出'false'。与往常一样,任何见解或帮助将不胜感激!

express hash sequelize.js bcrypt
1个回答
0
投票

你可以尝试只添加一个钩子

hooks: {
      beforeSave: hashPassword,
    }

因为我认为你的密码被哈希两次。 as beforeSave和beforeCreate两个钩子都被执行​​了。

希望能帮助到你

© www.soinside.com 2019 - 2024. All rights reserved.