MERN project remove password from response to client-side

Viewed 11

I'm building a mern-stack project and I'm trying to remove the password in my code before I send it to the client side. this is my controller for the login, is there anyone with good tips?


export const login = async (req, res) => {
  const loginUser = req.body;
  const User = await user.findOne({ email: loginUser.email})
 
 

  if (!User)
    return res.status(400).json({ msg: `No account with this email found` });

  if the passwords match (bcrypt will do this for us)
  const doesPasswordMatch = bcrypt.compareSync(
    loginUser.password,
    User.password
  ); 

  
  if (!doesPasswordMatch)
    return res.status(400).json({ msg: `Passwords did not match` });
  
  else {
   
    const token = jwt.sign(
      { email: User.email, userId: User._id },
      process.env.TOKEN_KEY,
      { expiresIn: "1h" }
    );
    
 
    return res.status(200).json({ msg: `logged in`, token: token, user: User });
  }
};

0 Answers
Related