feat: 后端用户密码哈希存储

This commit is contained in:
539943419 committed 2025-02-07 23:02:38 +08:00
1 parent 6e0a416422
commit 315916d027
10 files changed
+50 -31

No files matched your search

+3 -3
View File
@@ -1,4 +1,3 @@
// import { defineEventHandler, readBody, createError } from 'h3';
import bcrypt from 'bcryptjs';
import BetterSqlite3 from 'better-sqlite3';
@@ -10,9 +9,10 @@ export default defineEventHandler(async (event) => {
// 查询用户
const userDB = BetterSqlite3('./userData/db/user.db');
const user: any = userDB.prepare('SELECT * FROM user WHERE username = ?').get(username);
if (!user || password !== user.password) {
const authRes = await authUser(username, password);
if(!authRes){
userDB.close();
throw createError({ statusCode: 401, statusMessage: 'Invalid username or password' });
throw createError({ statusCode: 401, statusMessage: 'Username or password is incorrect' });
}
// 更新最后登录时间
+5 -1
View File
@@ -10,6 +10,10 @@ export default defineEventHandler(async (event) => {
try {
// 验证旧的 Token
const decoded = jwt.verify(token, jwtSecret) as any;
const authRes = await authUser(decoded.username, decoded.password);
if (!authRes) {
throw createError({ statusCode: 401, statusMessage: 'Username or password is incorrect' });
}
// 生成新的 Token
const newToken = jwt.sign({
username: decoded.username,
@@ -21,4 +25,4 @@ export default defineEventHandler(async (event) => {
} catch (err) {
throw createError({ statusCode: 401, statusMessage: 'Token invalid or expired', data: { err, token } });
}
});
});
+1 -4
View File
@@ -20,10 +20,7 @@ export default defineEventHandler(async (event) => {
// throw createError({ statusCode: 400, statusMessage: 'Username already exists' });
// }
// 哈希密码,暂未实现,未来实现
// const salt = getKey().substring(0, 10);
// const hashedPassword = bcrypt.hashSync(password, salt);
const hashedPassword = password
const hashedPassword = bcrypt.hashSync(password, 10);
// 插入新用户
const createTime = Date.now();
+5 -11
View File
@@ -1,4 +1,4 @@
// import bcrypt from 'bcryptjs';
import bcrypt from 'bcryptjs';
import BetterSqlite3 from 'better-sqlite3';
// import { defineEventHandler, createError, readBody } from 'h3';
import jwt from 'jsonwebtoken';
@@ -27,18 +27,12 @@ export default defineEventHandler(async (event) => {
}
// 验证旧密码是否正确
// const passwordMatch = bcrypt.compareSync(oldPassword, user.password);
const passwordMatch = oldPassword === user.password;
if (!passwordMatch) {
const authRes = await authUser(username, oldPassword);
if (!authRes) {
userDB.close();
throw createError({ statusCode: 401, statusMessage: 'Invalid old password' });
throw createError({ statusCode: 401, statusMessage: 'Old password is incorrect' });
}
// 哈希新密码
// const salt = bcrypt.genSaltSync(10);
// const hashedNewPassword = bcrypt.hashSync(newPassword, salt);
const hashedNewPassword = newPassword;
const hashedNewPassword = bcrypt.hashSync(newPassword, 10);
// 更新密码
const stmt = userDB.prepare('UPDATE user SET password =? WHERE username =?');