feat: 后端用户密码哈希存储
This commit is contained in:
1 parent
6e0a416422
commit
315916d027
10 files changed
+50
-31
No files matched your search
@@ -1,4 +1,3 @@
|
||||
// import { defineEventHandler, readBody, createError } from 'h3';
|
||||
import bcrypt from 'bcryptjs';
|
||||
import BetterSqlite3 from 'better-sqlite3';
|
||||
|
||||
@@ -10,9 +9,10 @@ export default defineEventHandler(async (event) => {
|
||||
// 查询用户
|
||||
const userDB = BetterSqlite3('./userData/db/user.db');
|
||||
const user: any = userDB.prepare('SELECT * FROM user WHERE username = ?').get(username);
|
||||
if (!user || password !== user.password) {
|
||||
const authRes = await authUser(username, password);
|
||||
if(!authRes){
|
||||
userDB.close();
|
||||
throw createError({ statusCode: 401, statusMessage: 'Invalid username or password' });
|
||||
throw createError({ statusCode: 401, statusMessage: 'Username or password is incorrect' });
|
||||
}
|
||||
|
||||
// 更新最后登录时间
|
||||
|
||||
@@ -10,6 +10,10 @@ export default defineEventHandler(async (event) => {
|
||||
try {
|
||||
// 验证旧的 Token
|
||||
const decoded = jwt.verify(token, jwtSecret) as any;
|
||||
const authRes = await authUser(decoded.username, decoded.password);
|
||||
if (!authRes) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Username or password is incorrect' });
|
||||
}
|
||||
// 生成新的 Token
|
||||
const newToken = jwt.sign({
|
||||
username: decoded.username,
|
||||
@@ -21,4 +25,4 @@ export default defineEventHandler(async (event) => {
|
||||
} catch (err) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Token invalid or expired', data: { err, token } });
|
||||
}
|
||||
});
|
||||
});
|
||||
@@ -20,10 +20,7 @@ export default defineEventHandler(async (event) => {
|
||||
// throw createError({ statusCode: 400, statusMessage: 'Username already exists' });
|
||||
// }
|
||||
|
||||
// 哈希密码,暂未实现,未来实现
|
||||
// const salt = getKey().substring(0, 10);
|
||||
// const hashedPassword = bcrypt.hashSync(password, salt);
|
||||
const hashedPassword = password
|
||||
const hashedPassword = bcrypt.hashSync(password, 10);
|
||||
|
||||
// 插入新用户
|
||||
const createTime = Date.now();
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
// import bcrypt from 'bcryptjs';
|
||||
import bcrypt from 'bcryptjs';
|
||||
import BetterSqlite3 from 'better-sqlite3';
|
||||
// import { defineEventHandler, createError, readBody } from 'h3';
|
||||
import jwt from 'jsonwebtoken';
|
||||
@@ -27,18 +27,12 @@ export default defineEventHandler(async (event) => {
|
||||
}
|
||||
|
||||
// 验证旧密码是否正确
|
||||
// const passwordMatch = bcrypt.compareSync(oldPassword, user.password);
|
||||
const passwordMatch = oldPassword === user.password;
|
||||
if (!passwordMatch) {
|
||||
const authRes = await authUser(username, oldPassword);
|
||||
if (!authRes) {
|
||||
userDB.close();
|
||||
throw createError({ statusCode: 401, statusMessage: 'Invalid old password' });
|
||||
throw createError({ statusCode: 401, statusMessage: 'Old password is incorrect' });
|
||||
}
|
||||
|
||||
// 哈希新密码
|
||||
// const salt = bcrypt.genSaltSync(10);
|
||||
// const hashedNewPassword = bcrypt.hashSync(newPassword, salt);
|
||||
|
||||
const hashedNewPassword = newPassword;
|
||||
const hashedNewPassword = bcrypt.hashSync(newPassword, 10);
|
||||
|
||||
// 更新密码
|
||||
const stmt = userDB.prepare('UPDATE user SET password =? WHERE username =?');
|
||||
|
||||
@@ -1,5 +1,4 @@
|
||||
import serverConfig from "../server.config"
|
||||
// import { verify } from 'jsonwebtoken'
|
||||
import jwt from 'jsonwebtoken'
|
||||
import getKey from "../utils/getKey"
|
||||
|
||||
@@ -17,10 +16,13 @@ export default defineEventHandler(async (event) => {
|
||||
const token = authHeader.split('Bearer ')[1].trim()
|
||||
try {
|
||||
const decoded = jwt.verify(token, key) as { userId: number, password: string, username: string, exp: number }
|
||||
const authRes = await authUser(decoded.username, decoded.password)
|
||||
if (!authRes) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Token invalid or expired', data: { err: 'auth failed', token } })
|
||||
}
|
||||
if (decoded.exp > Date.now()) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Token invalid or expired', data: { err: 'token expired', token } })
|
||||
}
|
||||
// console.log(decoded)
|
||||
// 将用户ID挂载到事件对象,供后续使用
|
||||
// event.context.userId = decoded.userId
|
||||
} catch (err) {
|
||||
|
||||
@@ -5,6 +5,7 @@ export default {
|
||||
'/api/test/testDir',
|
||||
'/api/posts/editPost',
|
||||
'/api/posts/uploadPost',
|
||||
'/api/posts/deletePost',
|
||||
'/api/user/updatePassword',
|
||||
'/api/system/update'
|
||||
])
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
import bcrypt from 'bcryptjs';
|
||||
import BetterSqlite3 from 'better-sqlite3';
|
||||
|
||||
export default async function authUser(
|
||||
username: string,
|
||||
password: string
|
||||
) {
|
||||
const userDB = BetterSqlite3('./userData/db/user.db');
|
||||
const user: any = userDB.prepare('SELECT * FROM user WHERE username = ?').get(username);
|
||||
const bPasswd = bcrypt.compareSync(password, user.password) || password === user.password;
|
||||
if (!user || !bPasswd) {
|
||||
userDB.close();
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
Reference in new issue
Block a user