尝试验证用户时,此函数始终返回true:
exports.IsUser = function(req, res, next) {
if (req.user.role === "user") {
next();
} else {
return res.status(401).json({ message: 'Unauthorized user!' });
}
};
json req.user:
{
"email": "test@gmail.com",
"fullName": "testname",
"role": "user",
"iat": 1502495033
}
路由功能:
app.route('/')
.get(function(req, res, next) {
res.json(req.user);})
.post(control.IsUser);