I'm writing a simple CRUD with login app using Express as a backend and React as a frontend. In the backend, after user is logged in correctly, I create a session variable, where I store information about the user - and it works well.
In some places in the frontend, I want to know if user is authenticated or not (checking in the server session if session.user is set).
Is this a proper approach of verifying user's authentication in the frontend? Or is there a better way of verifying user's authentication in the frontend?
Here's my code where I'm setting session variable:
module.exports = {
login: function(req, res){
const {email, password} = req.body;
console.log(email, password);
UserModel.authenticate(email, password, function(err, result){
if(err){
throw err;
}
if (result.rows.length == 0){
return res.status(404).send('Bad credentials');
}
req.session.user = result.rows[0];
return res.sendStatus(200);
});
}
}