ユーザー登録とログイン
パスワードのハッシュ化や認証情報の安全な保存を含む、ユーザー登録とログイン機能を構築します。
「ユーザー登録とログイン」はCoddyKit上の無料Node.js Backend Development Bootcampレッスンです。 これはレッスン1/6です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはNode.js Backend Development Bootcamp学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Node.js Backend Development Bootcampコースには全6レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
Welcome to User Authentication
User authentication is how we verify who a user is. It's a critical part of almost any application that handles personal data or restricted features.
- Why it matters: Protects user accounts and sensitive information.
- What we'll cover: Building registration and login flows from scratch.
The User Registration Flow
Registering a new user involves several steps to create a new account:
- User provides credentials (e.g., username, password, email).
- Input data is validated (e.g., strong password, unique email).
- The password is hashed for security.
- New user data (including the hashed password) is saved to the database.
Why Hash Passwords?
Storing passwords in plain text is a huge security risk! If your database is breached, all user passwords would be exposed.
Hashing transforms a password into a fixed-size, unreadable string. It's a one-way process, meaning you can't easily get the original password back from the hash.
We use libraries like bcrypt in Node.js for robust password hashing, which also adds a 'salt' to prevent common attacks.
Hashing Passwords with bcrypt
bcrypt is a popular library for securely hashing passwords. It's computationally intensive, making brute-force attacks harder.
Try running this example to see a password hashed:
const bcrypt = require('bcrypt');
const password = "mySecretP@ssword";
const saltRounds = 10; // Cost factor for hashing (higher is slower/more secure)
async function hashPassword() {
try {
const hashedPassword = await bcrypt.hash(password, saltRounds);
console.log("Original: " + password);
console.log("Hashed: " + hashedPassword);
} catch (error) {
console.error("Error hashing:" + error.message);
}
}
hashPassword();
Storing Hashed Credentials
After hashing, only the hashed password should be stored in your database, along with other user details like their email or username.
- NEVER store plain-text passwords.
- The hash is unique for each password, even if the original passwords are the same (thanks to salting).
- This hash is what you'll use for comparison during login.
The User Login Flow
When a user tries to log in, your application follows these steps:
- User provides their username/email and password.
- Application retrieves the user's record (including their stored hashed password) from the database based on the username/email.
- The provided password is hashed and compared against the stored hash.
- If they match, the user is authenticated, and a session or token is created.
Verifying Passwords with bcrypt
To check if a user's provided password matches the stored hash, we use bcrypt.compare(). It performs the hashing and comparison securely.
Run this code to see password comparison in action:
const bcrypt = require('bcrypt');
// This hash would typically come from your database
const storedHash = "$2b$10$w090/qB2k6n0Y7o8p9q.u.0Z1X2Y3Z4A5B6C7D8E9F0G1H2I3J4K5L6M7N8O9P0Q1R";
const passwordAttempt = "mySecretP@ssword";
const wrongAttempt = "incorrectPassword";
async function comparePasswords() {
try {
const isMatch = await bcrypt.compare(passwordAttempt, storedHash);
console.log(`'${passwordAttempt}' matches: ${isMatch}`);
const isWrongMatch = await bcrypt.compare(wrongAttempt, storedHash);
console.log(`'${wrongAttempt}' matches: ${isWrongMatch}`);
} catch (error) {
console.error("Error comparing:" + error.message);
}
}
comparePasswords();
Secure Credential Storage Practices
Beyond just hashing passwords, other credentials need protection:
- API Keys & Database URLs: Store these in environment variables (e.g.,
.envfiles), not directly in your code. - Sensitive User Data: Encrypt any highly sensitive data at rest in your database.
- Regular Updates: Keep your hashing libraries and dependencies up-to-date.
Handling Authentication Errors
When registration or login fails, provide helpful but generic error messages to the user. This prevents revealing too much information to potential attackers.
- Instead of 'User not found', say 'Invalid credentials'.
- Instead of 'Password incorrect', also say 'Invalid credentials'.
- Log detailed errors on the server side for debugging, but don't expose them to the client.
Quick Check: Password Hashing
Test your understanding of why password hashing is essential for security.
Recap: Registration & Login
In this lesson, you learned the fundamental steps for user registration and login:
- We covered the importance of password hashing using
bcryptto protect sensitive user data. - You saw how to implement both the hashing for registration and the comparison for login.
- We also touched on best practices for secure credential storage and handling authentication errors gracefully.
Next, we'll dive into implementing stateless authentication using JSON Web Tokens (JWTs).
よくある質問
「ユーザー登録とログイン」レッスンは無料ですか?
はい。「ユーザー登録とログイン」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Node.js Backend Development Bootcampコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Node.js Backend Development Bootcampコースには全6レッスンが含まれています。
「ユーザー登録とログイン」で何を学びますか?
パスワードのハッシュ化や認証情報の安全な保存を含む、ユーザー登録とログイン機能を構築します。 ブラウザで直接実行するハンズオンコードでNode.js Backend Development Bootcampを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Node.js Backend Development Bootcampを始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのNode.js Backend Development Bootcampは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/6です。
「ユーザー登録とログイン」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このNode.js Backend Development Bootcampレッスンでコードを書いて実行できますか?
はい。すべてのNode.js Backend Development Bootcampレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。