this.password is undefined in comparePassword method when using Bcrypt with mongoose. How to solve?

Viewed 1305

After fetching records from Mongo DB, comparePassword method is called to compare the password entered by user and the password stored in database. On printing the record all the data is shown, while inside comparePassword this.password is coming as undefined.

    User.findOne ({ username : req.body.username },
      function(err, user) {
  if (err) throw err;
console.log(user);
 user.comparePassword(req.body.password, function(err, isMatch) {
    if (err) throw err;
    console.log('Password Match:', isMatch); 
});});

Method:

    UserCredentialSchema.methods.comparePassword = function(pwd, cb) {
bcrypt.compare(pwd, this.password, function(err, isMatch) {
    console.log(this.password);
    if (err) return cb(err);
    cb(null, isMatch);
});};
3 Answers

This is a bit old, but I bump into this same problem. After spending half day, I found out why and might be applicable.

My problem is caused by the password field being declared with select: false in the schema. See the code below

var personSchema = new Schema({
  first       :   {type: String, required: 'FirstNameInvalid'},
  last        :   String,
  email       :   {type: String, unique: true, lowercase: true, required: 'EmailInvalid'},
  password    :   {type: String, select: false, required: 'PasswordInvalid'},
  isLocked    :   Boolean,
  isAdmin     :   Boolean
});

By changing the password declaration to select: true, or even removing the whole select statement, the problem is fixed.

Note that there are some security risk involved by removing the select statement. However this will be beyond the discussion of this topic

Related