Node.js使用bcrypt登录时出现null错误求助
登录验证失败问题排查
我搭建了连接本地MySQL的基础注册登录页面,系统收集邮箱、用户名和密码(密码通过bcrypt哈希后存储到数据库)。但登录时仅提示null错误,控制台输出“password + else2”,说明执行到了bcrypt.compare的else分支。相关代码如下:
login.js 文件
exports.login = (req, res) => { console.log(req.body); let email = req.body.email; let password = req.body.password; let username = req.body.username; //if it finds username and email matching login credentials it will check for password db.query('SELECT username, email, password FROM users WHERE username = ? AND email = ?', [username, email], function (error, results) { if (error) { res.send({ "code": 400, "failed": "error ocurred" }); } //results[0].password means the password of the user that was found. // it should compare plain password with the encrypted password in database //and redirect to the /profile page if the password are a match. if (results.length > 0) { bcrypt.compare(password, results[0].password, function (error, answer) { if (error) { console.log(password +'if1') console.log("comparing gone wrong", error); return res.render('login', { message3: 'Comparing error - please try again later' }); } if (answer) { console.log(password + 'if 2') res.redirect("/profile"); console.log("login successfull!"); } else { console.log(password + ' else2', error) return res.render('login', { message3: 'User or password or email is wrong' }); } }); } else { console.log(password + 'else3') return res.render('login', { message3: 'User or password or email is wrong' }); } }); };
register.js 文件
exports.register = (req, res) => { console.log(req.body); const { username, email, password, passwordConfirm } = req.body; db.query('SELECT email FROM users WHERE email = ?', [email], async (error, result) => { if(error) { console.log(error); } if( result.length > 0 ) { return res.render('register', { message: 'That email is already in use' }) } else if( password !== passwordConfirm) { return res.render('register', { message: 'That passwords do not match' }); } let hashedPassword = await bcrypt.hash(password, 8); console.log(hashedPassword); db.query('INSERT INTO users SET ?', {username: username, email: email, password: hashedPassword }, (error, result) => { if(error) { console.log(error); } else { console.log(result); return res.render('register', { message2: 'User Registered!' }); } }) }); }
问题排查与修复方案
检查请求参数完整性
查看console.log(req.body)的输出,确认前端提交的参数是否包含username、email和password,参数名是否和后端一致(比如前端是否误传user_name而非username)。修正SQL查询逻辑
当前登录查询要求username和email同时匹配才能找到用户,这不符合常规登录逻辑(通常是用户名或邮箱二选一)。如果是业务逻辑错误,将SQL改为:SELECT username, email, password FROM users WHERE username = ? OR email = ?同时调整参数传入,比如用用户输入的登录值(比如
loginId)同时匹配两个字段。验证哈希存储与比对一致性
- 检查数据库
users表的password字段长度,bcrypt哈希值长度为60字符,需确保字段类型为VARCHAR(255)(避免截断)。 - 在
bcrypt.compare前添加日志,确认从数据库取出的哈希值完整:console.log('Stored hash:', results[0].password);
- 检查数据库
完善错误处理逻辑
在db.query的错误分支添加return,防止后续代码继续执行:if (error) { console.log('DB query error:', error); return res.send({ "code": 400, "failed": "error occurred" }); }简化登录流程(可选)
修改前端页面,仅要求用户输入**登录名(用户名/邮箱)**和密码,减少输入项,避免双重匹配的逻辑问题。
内容的提问来源于stack exchange,提问作者Paweł Owczarek
相关产品推荐
相关产品推荐

