removed the default secret key
This commit is contained in:
@@ -30,7 +30,7 @@ router.post("/login", (req, res) => {
|
||||
const isMatch = await bcrypt.compare(password, user.password);
|
||||
|
||||
if (isMatch) {
|
||||
let jwtSecretKey = process.env.JWT_SECRET_KEY || "defaultSecretKey";
|
||||
let jwtSecretKey = process.env.JWT_SECRET_KEY;
|
||||
let data = { userId: user.id, username: user.username };
|
||||
// Create JWT token
|
||||
const token = jwt.sign(data, jwtSecretKey, { expiresIn: "1d" });
|
||||
|
||||
@@ -12,7 +12,7 @@ const verifyToken = (req, res, next) => {
|
||||
}
|
||||
|
||||
try {
|
||||
const jwtSecretKey = process.env.JWT_SECRET_KEY || "default_secret_key";
|
||||
const jwtSecretKey = process.env.JWT_SECRET_KEY;
|
||||
|
||||
const decoded = jwt.verify(token, jwtSecretKey);
|
||||
req.user = decoded;
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@ const authenticateToken = (req, res, next) => {
|
||||
}
|
||||
|
||||
try {
|
||||
const jwtSecretKey = process.env.JWT_SECRET_KEY || "defaultSecretKey";
|
||||
const jwtSecretKey = process.env.JWT_SECRET_KEY;
|
||||
const verified = jwt.verify(token, jwtSecretKey);
|
||||
req.user = verified;
|
||||
} catch (err) {
|
||||
|
||||
Reference in New Issue
Block a user