always when I try to compare between the newUser.password with profile.password it gives me success even if I put a wrong password
and here is my code
const bcrypt = require('bcrypt')
const router = require('express').Router()
// const jwt = require('jsonwebtoken')
let User = require('../models/user.model')
router.route('/login').post(async(req, res) => {
var newUser = {};
newUser.email = req.body.email;
newUser.password = req.body.password;
console.log(newUser.password)
User.findOne({ email: newUser.email })
.then(profile => {
if (!profile) {
res.send("User not exist");
here it will compare for me the hashed pass with the pass that the client give
}else if(bcrypt.compare(newUser.password, profile.password)){
res.send("success");
here will stop
}
else if((newUser.password !== profile.password)){
res.send("wrong");
}
})
.catch(err => res.status(400).json('Erorr: ' + err))
})
router.route('/add').post(async(req, res) => {
const hashedPassword = await bcrypt.hash(req.body.password, 10)
const username = req.body.username
const email = req.body.email
const password = hashedPassword
const firstname = req.body.firstname
const lastname = req.body.lastname
const newUser = new User({username, email, password, firstname, lastname})
// const accessToken = jwt.sign(password, process.env.ACCESS_TOKEN_SECRET)
// res.json({ accessToken: accessToken })
newUser.save()
.then(() => res.json('User added!'))
.catch(err => res.status(400).json('Erorr: ' + err))
})
// function authToken(req, res, next){
// const authHeader = req.headers['authorization']
// const token = authHeader && authHeader.split(' ')[1]
// if (token == null ) return res.sendStatus(401)
// jwt.verify(token, process.env.ACCESS_TOKEN_SECRET, (err, password) => {
// if (err) return res.sendStatus(403)
// req.password = password
// next()
// })
// }
module.exports = router