【发布时间】:2016-10-24 09:41:40
【问题描述】:
我正在尝试创建一个将检查用户凭据的中间件,如果成功,则使用用户信息创建一个 JWT。我想创建一个 cookie,然后将 JWT 存储在 cookie 中,但我似乎无法让它正常工作。在 post 上点击登录方法后,我收到 404 'Not Found' 错误,说它“Cannot POST /authenticate”。我错过了什么?
路线:
app.post('/authenticate', function(req, res, next){
middleware.login(req, res, next);
});
中间件:
exports.login = function(req, res, next){
var username = req.body.username;
var password = req.body.password;
User.findByUsername(username,function(err, user){
if(err){
res.send({ success: false, message: 'Authentication failed.' });
}
if (!user) {
res.send({ success: false, message: 'Authentication failed. User not found.' });
}
if(user && !user.isuserenabled){
res.send({ success: false, message: 'Authentication failed. User not found.' });
}
if (!UserSchema.comparePassword(password,user.user_password )) {
res.send({ success: false, message: 'Authentication failed. User not found.' });
}
res.cookie('yummyCookie', jwt.sign(
//payload, secret, options, [callback]
{
id: user.user_id,
email: user.email,
name: user.firstname + " " + user.lastname,
role: user.role
},
config.secret, // DO NOT KEEP YOUR SECRET IN THE CODE
{expiresIn: "1h"}, {secure: true, httpOnly: true}));
return next();
});
};
【问题讨论】:
标签: javascript node.js express cookies http-headers