.js页面不接受来自数据库的散列密码

时间:2016-08-18 20:01:04

标签: javascript php mysql authentication hash

这是manager.js文件,我在' util.createHash中输入密码("密码")'字段并从< localhost / manager / hash'获取哈希键。然后我将散列密码添加到' ra_password'我创建的sql数据库中的字段。

manager.js

var express = require('express');
var router = express.Router();
var async = require('async');

var util = require('../utils/util');
var db = require('../utils/database');
var connection = db.connection();

router.get('/login', function (req, res) {
  if (req.session.manager) {
    return res.redirect('/');
  }

  if (req.query.tip == 'error') {
    var tip = 'username or password incorrect!';
  } else {
    var tip = null;
  }
  res.render('login', { tip: tip });
});

router.get('/hash', function(req,res){
    res.end(util.createHash("password")); **//I enter pwd here for Hash**
});

router.post('/login', function (req, res) {
  var username = req.body.username;
  var password = req.body.password;
  var sql = 'SELECT * FROM restaurant_accounts WHERE ra_name=?';
  connection.query(sql, [username], function (err, result) {
    if (err) throw err;
    if (result.length == 0) {
      return res.redirect('/manager/login?tip=error');
    } 
    var account = result[0];
    if (!util.checkHash(password, account.ra_password)) {
      return res.redirect('/manager/login?tip=error');
    }

    connection.query('SELECT * FROM restaurants WHERE rest_owner_id=?', [account.ra_id], function (err, result) {
      if (err) throw err;
      var restaurant = result[0];
      req.session.manager = {
        id: account.ra_id,
        name: account.ra_name,
        rest_id: restaurant.rest_id,
        rest_name: restaurant.rest_name
      };
      res.redirect('/');
    });
  });
});

router.get('/logout', function (req, res) {
  req.session.destroy();
  res.redirect('/manager/login');
});

module.exports = router;

但是当我使用该密码登录" localhost / manager / login"页面上它不接受密码并且说“"用户名或密码不正确!”#34;。为什么会这样?

0 个答案:

没有答案