Passport Facebook授权始终自动重定向问题求助
Hey there! I totally get how frustrating this can be—let's fix that issue where your app skips the Facebook login screen after the first successful authentication.
问题原因
This happens because Facebook sets a persistent cookie in the user's browser after the first login, which tells Facebook the user is already authenticated. By default, passport-facebook doesn't override this behavior, so it automatically redirects to your callback route instead of showing the login page.
解决方案
You just need to add a specific parameter to your passport.authenticate call to force Facebook to show the login screen every time. Here are two common options:
1. 强制用户选择账号(适合多账号场景)
Modify your auth route to include the prompt: 'select_account' option:
router.get('', passport.authenticate('facebook', { prompt: 'select_account' }));
This will make Facebook show the account selection screen every time, even if the user has an active session.
2. 强制用户重新输入密码(更高安全要求)
If you want to require the user to re-enter their Facebook password every time, use the authType: 'reauthenticate' option instead:
router.get('', passport.authenticate('facebook', { authType: 'reauthenticate' }));
额外优化建议(非问题根源,但值得关注)
Your current serializeUser and deserializeUser are storing the full user object in the session—while this works, it's better practice to store only the user ID to keep sessions lightweight:
passport.serializeUser((user, done) => { done(null, user._id); }); passport.deserializeUser((id, done) => { User.findById(id, (err, user) => { done(err, user); }); });
Give either of the prompt or authType options a try, and you should see the Facebook login screen every time you visit /auth/facebook.
内容的提问来源于stack exchange,提问作者David Zerah

