使用 Passport 在 Node JS 中实现基于 cookie 的身份验证

Implement cookie based authentication in Node JS with Passport

下面是我的server.js (app.js)。我正在使用带有护照的快递,用于用户身份验证。但是每当我重新启动我的节点服务器用户注销时。

我是 nodejs 的新手,我想知道如何实现基于 cookie 的身份验证。这样即使服务器启动,用户也不会注销。我确定有一些我找不到的配置更改。

// server.js

// set up ======================================================================
// get all the tools we need
var express  = require('express');
var app      = express();
var port     = process.env.PORT || 80;
var mongoose = require('mongoose');
var passport = require('passport');
var flash    = require('connect-flash');

var morgan       = require('morgan');
var cookieParser = require('cookie-parser');
var bodyParser   = require('body-parser');
var session      = require('express-session');

var configDB = require('./config/database.js');

// configuration ===============================================================
mongoose.connect(configDB.url); // connect to our database

require('./config/passport')(passport); // pass passport for configuration

// set up our express application
app.use(morgan('dev')); // log every request to the console
app.use(cookieParser()); // read cookies (needed for auth)
app.use(bodyParser()); // get information from html forms

app.set('view engine', 'ejs'); // set up ejs for templating

// required for passport
app.use(session({ secret: 'yassers' })); // session secret
app.use(passport.initialize());
app.use(passport.session()); // persistent login sessions
app.use(flash()); // use connect-flash for flash messages stored in session

// routes ======================================================================
require('./app/routes.js')(app, passport); // load our routes and pass in our app and fully configured passport

// launch ======================================================================
app.listen(port);
console.log('The magic happens on port ' + port);

当您重新启动时它会注销,因为它存储在 MemoryStore(RAM) 中。使用 mongoStore 存储您的会话 mongodb。试试下面的代码:

var session = require('express-session');
var MongoStore = require('connect-mongo')(session);

var mongoStore = new MongoStore({
  url: 'your mongo db url'  
});

app.use(session({
  secret: 'your secret',
  saveUninitialized: true, // don't create session until something stored
  resave: false, //don't save session if unmodified
  store: mongoStore,
  cookie: {
    domain: 'domain name',    
    maxAge: 1000 * 24 * 60
  }
}));