feat: 后端用户密码哈希存储
This commit is contained in:
1 parent
6e0a416422
commit
315916d027
10 files changed
+50
-31
No files matched your search
@@ -1,4 +1,3 @@
|
||||
// import { defineEventHandler, readBody, createError } from 'h3';
|
||||
import bcrypt from 'bcryptjs';
|
||||
import BetterSqlite3 from 'better-sqlite3';
|
||||
|
||||
@@ -10,9 +9,10 @@ export default defineEventHandler(async (event) => {
|
||||
// 查询用户
|
||||
const userDB = BetterSqlite3('./userData/db/user.db');
|
||||
const user: any = userDB.prepare('SELECT * FROM user WHERE username = ?').get(username);
|
||||
if (!user || password !== user.password) {
|
||||
const authRes = await authUser(username, password);
|
||||
if(!authRes){
|
||||
userDB.close();
|
||||
throw createError({ statusCode: 401, statusMessage: 'Invalid username or password' });
|
||||
throw createError({ statusCode: 401, statusMessage: 'Username or password is incorrect' });
|
||||
}
|
||||
|
||||
// 更新最后登录时间
|
||||
|
||||
@@ -10,6 +10,10 @@ export default defineEventHandler(async (event) => {
|
||||
try {
|
||||
// 验证旧的 Token
|
||||
const decoded = jwt.verify(token, jwtSecret) as any;
|
||||
const authRes = await authUser(decoded.username, decoded.password);
|
||||
if (!authRes) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Username or password is incorrect' });
|
||||
}
|
||||
// 生成新的 Token
|
||||
const newToken = jwt.sign({
|
||||
username: decoded.username,
|
||||
@@ -21,4 +25,4 @@ export default defineEventHandler(async (event) => {
|
||||
} catch (err) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Token invalid or expired', data: { err, token } });
|
||||
}
|
||||
});
|
||||
});
|
||||
@@ -20,10 +20,7 @@ export default defineEventHandler(async (event) => {
|
||||
// throw createError({ statusCode: 400, statusMessage: 'Username already exists' });
|
||||
// }
|
||||
|
||||
// 哈希密码,暂未实现,未来实现
|
||||
// const salt = getKey().substring(0, 10);
|
||||
// const hashedPassword = bcrypt.hashSync(password, salt);
|
||||
const hashedPassword = password
|
||||
const hashedPassword = bcrypt.hashSync(password, 10);
|
||||
|
||||
// 插入新用户
|
||||
const createTime = Date.now();
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
// import bcrypt from 'bcryptjs';
|
||||
import bcrypt from 'bcryptjs';
|
||||
import BetterSqlite3 from 'better-sqlite3';
|
||||
// import { defineEventHandler, createError, readBody } from 'h3';
|
||||
import jwt from 'jsonwebtoken';
|
||||
@@ -27,18 +27,12 @@ export default defineEventHandler(async (event) => {
|
||||
}
|
||||
|
||||
// 验证旧密码是否正确
|
||||
// const passwordMatch = bcrypt.compareSync(oldPassword, user.password);
|
||||
const passwordMatch = oldPassword === user.password;
|
||||
if (!passwordMatch) {
|
||||
const authRes = await authUser(username, oldPassword);
|
||||
if (!authRes) {
|
||||
userDB.close();
|
||||
throw createError({ statusCode: 401, statusMessage: 'Invalid old password' });
|
||||
throw createError({ statusCode: 401, statusMessage: 'Old password is incorrect' });
|
||||
}
|
||||
|
||||
// 哈希新密码
|
||||
// const salt = bcrypt.genSaltSync(10);
|
||||
// const hashedNewPassword = bcrypt.hashSync(newPassword, salt);
|
||||
|
||||
const hashedNewPassword = newPassword;
|
||||
const hashedNewPassword = bcrypt.hashSync(newPassword, 10);
|
||||
|
||||
// 更新密码
|
||||
const stmt = userDB.prepare('UPDATE user SET password =? WHERE username =?');
|
||||
|
||||
Reference in new issue
Block a user