I'm building a mern-stack project and I'm trying to remove the password in my code before I send it to the client side. this is my controller for the login, is there anyone with good tips?
export const login = async (req, res) => {
const loginUser = req.body;
const User = await user.findOne({ email: loginUser.email})
if (!User)
return res.status(400).json({ msg: `No account with this email found` });
if the passwords match (bcrypt will do this for us)
const doesPasswordMatch = bcrypt.compareSync(
loginUser.password,
User.password
);
if (!doesPasswordMatch)
return res.status(400).json({ msg: `Passwords did not match` });
else {
const token = jwt.sign(
{ email: User.email, userId: User._id },
process.env.TOKEN_KEY,
{ expiresIn: "1h" }
);
return res.status(200).json({ msg: `logged in`, token: token, user: User });
}
};