feat: 后端用户密码哈希存储

This commit is contained in:
539943419 committed 2025-02-07 23:02:38 +08:00
1 parent 6e0a416422
commit 315916d027
10 files changed
+50 -31

No files matched your search

+5 -11
View File
@@ -1,4 +1,4 @@
// import bcrypt from 'bcryptjs';
import bcrypt from 'bcryptjs';
import BetterSqlite3 from 'better-sqlite3';
// import { defineEventHandler, createError, readBody } from 'h3';
import jwt from 'jsonwebtoken';
@@ -27,18 +27,12 @@ export default defineEventHandler(async (event) => {
}
// 验证旧密码是否正确
// const passwordMatch = bcrypt.compareSync(oldPassword, user.password);
const passwordMatch = oldPassword === user.password;
if (!passwordMatch) {
const authRes = await authUser(username, oldPassword);
if (!authRes) {
userDB.close();
throw createError({ statusCode: 401, statusMessage: 'Invalid old password' });
throw createError({ statusCode: 401, statusMessage: 'Old password is incorrect' });
}
// 哈希新密码
// const salt = bcrypt.genSaltSync(10);
// const hashedNewPassword = bcrypt.hashSync(newPassword, salt);
const hashedNewPassword = newPassword;
const hashedNewPassword = bcrypt.hashSync(newPassword, 10);
// 更新密码
const stmt = userDB.prepare('UPDATE user SET password =? WHERE username =?');