You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Passport.js与Express中间件限制页面访问遇认证异常

Troubleshooting req.isAuthenticated() Always Returning False After Successful Login

Let's walk through the most common causes and fixes for this issue— I've dealt with similar passport session problems before, so these steps should help you narrow it down:

1. Update Your Session Configuration

Your current session setup uses outdated default values that can cause unexpected session persistence issues. Update your express-session config to follow modern best practices:

server.use(session({ 
  secret: 'keyboard cat', 
  resave: false, // Disable forced saves when no session changes occur
  saveUninitialized: false, // Skip saving empty, uninitialized sessions
  cookie: { 
    secure: process.env.NODE_ENV === 'production', // Only use secure cookies in HTTPS environments
    httpOnly: true, // Block client-side JS from accessing cookies (security best practice)
    maxAge: 24 * 60 * 60 * 1000 // Optional: Set a 1-day expiration for cookies
  }
}));

The old resave: true and saveUninitialized: true settings often lead to session inconsistencies, especially when paired with passport's session integration.

2. Verify Passport's Deserialization Logic

The most likely root cause is that your deserializeUser function isn't properly fetching the user from your database, leaving req.user undefined (and req.isAuthenticated() false). Add debug logs to confirm:

exports.authDeserializer = function(id, done) {
  User.findById(id, function(err, user) {
    console.log('Deserializing user - Error:', err, 'Fetched User:', user); // Check if user is null/undefined
    done(err, user);
  });
};
  • If user returns null/undefined, double-check your User.findById method. For Mongoose users, ensure the ID format matches (e.g., ObjectID vs string) and the user exists in your database.
  • If there's an error in the query, fix the database logic to resolve it.

3. Ensure Sessions Are Saved Before Redirecting

Sometimes redirects happen before the session is fully persisted to storage, causing the session to "disappear" after login. Modify your login route to manually save the session before redirecting:

server.post('/maintenance_login', (req, res, next) => {
  passport.authenticate('local', function(err, user, info) {
    if (err) { return next(err); }
    if (!user) { 
      req.flash('error', info?.message || 'Invalid email or password');
      return res.redirect('/maintenance_login'); 
    }
    req.logIn(user, function(err) {
      if (err) { return next(err); }
      // Force session save to guarantee passport data is persisted
      req.session.save(function(err) {
        if (err) { return next(err); }
        return res.redirect('/maintenance');
      });
    });
  })(req, res, next);
});

This ensures the session (including passport's user data) is written to storage before the user is sent to the protected route.

4. Fix Your Protected Route Syntax

Your current route path has a syntax error— the query parameter needs a leading slash:

// Wrong: Missing slash before :query?
server.get('/maintenance:query?', auth_controller.restrict, maintenance_controller.maintenance_list);

// Correct:
server.get('/maintenance/:query?', auth_controller.restrict, maintenance_controller.maintenance_list);

While this might not be the core authentication issue, it can cause unexpected routing behavior, so fixing it is a critical first step.

5. Debug Session State Post-Login

Add logs right after login to confirm the session is being created correctly:

req.logIn(user, function(err) {
  if (err) { return next(err); }
  console.log('Post-login session:', req.session); // Look for the `passport` property
  console.log('Post-login user:', req.user); // Should be your full user object
  console.log('Is authenticated immediately after login?', req.isAuthenticated()); // Should return true
  req.session.save(function(err) {
    if (err) { return next(err); }
    return res.redirect('/maintenance');
  });
});

If req.isAuthenticated() is true here but false in your restrict middleware, the session isn't being carried over to the next request. This usually points to a cookie issue:

  • Ensure your login and protected routes use the same domain (no subdomain mismatches).
  • In development, don't set secure: true on cookies (since you're using HTTP, not HTTPS).

6. Rule Out express-flash-2 Interference

Temporarily remove express-flash-2 from your middleware stack to check if it's causing session conflicts:

// Comment these lines out temporarily
// server.use(flash());
// Also remove any req.flash() calls in your routes/middleware

If the issue resolves, verify that express-flash-2 is compatible with your versions of express-session and passport.


内容的提问来源于stack exchange,提问作者banapapaya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:37:49