不使用Mongoose时Passport.js无法正常工作,附代码求解决方案
Alright, let's figure out why Passport isn't working for you without Mongoose. First off, there's an obvious incomplete line in your code, and we also need to fill in the Passport configuration pieces that Mongoose would usually handle implicitly. Let's break this down step by step:
1. Fix the Incomplete Passport Session Middleware
Your code cuts off at app.use(passport.sessi... — you need to complete this line, as this middleware is critical for Passport to persist user sessions:
app.use(passport.initialize()); app.use(passport.session()); // 补全这行,缺失它会导致会话无法持久化
2. Implement Serialize/Deserialize Functions
Without Mongoose, you have to manually tell Passport how to store user data in the session and retrieve it later. Below is an example using the native MongoDB driver (adjust for your database if needed):
const passport = require('passport'); const LocalStrategy = require('passport-local').Strategy; const { MongoClient, ObjectId } = require('mongodb'); // Establish database connection (tweak the URI to match your DB setup) let db; MongoClient.connect('mongodb://localhost:27017/your-db-name') .then(client => { db = client.db(); }) .catch(err => console.error('Failed to connect to DB:', err)); // Serialize user: Store only the user ID in the session for efficiency passport.serializeUser((user, done) => { done(null, user._id); }); // Deserialize user: Fetch the full user object from the DB using the stored ID passport.deserializeUser((id, done) => { db.collection('users').findOne({ _id: new ObjectId(id) }) .then(user => done(null, user)) .catch(err => done(err)); });
3. Configure the Local Authentication Strategy
You need to define how Passport verifies user credentials without Mongoose's model methods. Here's a basic example (always encrypt passwords in production with bcrypt or similar tools):
passport.use(new LocalStrategy( (username, password, done) => { // Query your database for the user by username db.collection('users').findOne({ username: username }) .then(user => { if (!user) { return done(null, false, { message: 'Incorrect username.' }); } // Validate password (replace with bcrypt.compare() for hashed passwords) if (user.password !== password) { return done(null, false, { message: 'Incorrect password.' }); } return done(null, user); // Success: pass the user object to Passport }) .catch(err => done(err)); // Handle database errors } ));
4. Ensure Login Routes Use Passport Authentication
Finally, make sure your login route leverages Passport's authentication middleware:
app.post('/login', passport.authenticate('local', { successRedirect: '/dashboard', // Where to go after successful login failureRedirect: '/login', // Where to go if login fails failureFlash: true // Enable flash messages for error feedback }) );
Key Notes for Production
- Password Security: Never store plaintext passwords. Use
bcrypt.hash()when creating users andbcrypt.compare()during validation. - Session Configuration: Update your
express-sessionsetup with production-safe settings:app.use(session({ secret: 'your-strong-secret-here', resave: false, saveUninitialized: false, // Add a store like connect-mongo for persistent sessions in production })); - Database Compatibility: If you're using a database other than MongoDB, just replace the query logic with your database's native driver syntax — the Passport serialize/deserialize pattern stays the same.
内容的提问来源于stack exchange,提问作者james joel

