我希望只有登录的用户才能看到确定的页面

时间:2014-04-25 22:03:41

标签: node.js express ejs

嗨,大家好我用expressjs框架学习node.js。现在我想创建一个有两个页面的简单站点(登录页面和登录页面)。通过此练习,我的主要目标是仅授权已登录的用户查看已记录的页面 我希望防止未注册的用户使用www.mysite.com/logged来查看记录的页面 所以在app.js我添加了这个

app.get('/logged', routes.logged);

然后在index.js(它位于./routes文件夹中)我写了这个

exports.logged = function(req, res) {
if(req.session.isLogged) {
        res.status(200);
        res.render('logged', {Title: req.session.name});
} else {
    res.status(403);
    res.render('403');
}
}

但是当我尝试通过www.example.com/logged访问记录的页面时,我总是得到500 Error Internal server error
我收到的错误是:

Express
500 Error: Failed to lookup view "TypeError: Cannot read property 'commonUserId' of undefined" in views directory "C:\Users\Fabio\Desktop\SitoStatistica\views"
at Function.app.render (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\lib\application.js:493:17)
at ServerResponse.res.render (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\lib\response.js:798:7)
at Object.handle (C:\Users\Fabio\Desktop\SitoStatistica\app.js:32:6)
at next (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\node_modules\connect\lib\proto.js:188:17)
at next (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\node_modules\connect\lib\proto.js:190:11)
at next (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\node_modules\connect\lib\proto.js:190:11)
at pass (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\lib\router\index.js:110:24)
at nextRoute (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\lib\router\index.js:100:7)
at callbacks (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\lib\router\index.js:167:11)
at callbacks (C:\Users\Fabio\Desktop\SitoStatistica\node_modules\express\lib\router\index.js:170:9)

@pero

1 个答案:

答案 0 :(得分:1)

实施自己的身份验证系统并不是一个好理想的选择。

对于NodeJS身份验证,您应该查看PassportJS

身份验证然后变得非常简单:

app.post('/login', passport.authenticate('local', { successRedirect: '/',
                                                failureRedirect: '/login' }));

然后

app.get('/logged', function (req, res, next) {
    if (req.isAuthenticated()) {
        return res.redirect('/login');
    }
    return res.render('login');
});
相关问题