0Pricing
Node.js Backend Development Bootcamp · 강의

사용자 등록과 로그인

비밀번호 해싱과 안전한 자격 증명 저장을 포함한 사용자 등록 및 로그인 기능을 구축합니다.

사용자 등록과 로그인은(는) CoddyKit의 무료 Node.js Backend Development Bootcamp 강의입니다. 이것은 6개 중 1번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Node.js Backend Development Bootcamp 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Node.js Backend Development Bootcamp 강의에는 총 6개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

Welcome to User Authentication

User authentication is how we verify who a user is. It's a critical part of almost any application that handles personal data or restricted features.

  • Why it matters: Protects user accounts and sensitive information.
  • What we'll cover: Building registration and login flows from scratch.

The User Registration Flow

Registering a new user involves several steps to create a new account:

  1. User provides credentials (e.g., username, password, email).
  2. Input data is validated (e.g., strong password, unique email).
  3. The password is hashed for security.
  4. New user data (including the hashed password) is saved to the database.

Why Hash Passwords?

Storing passwords in plain text is a huge security risk! If your database is breached, all user passwords would be exposed.

Hashing transforms a password into a fixed-size, unreadable string. It's a one-way process, meaning you can't easily get the original password back from the hash.

We use libraries like bcrypt in Node.js for robust password hashing, which also adds a 'salt' to prevent common attacks.

Hashing Passwords with bcrypt

bcrypt is a popular library for securely hashing passwords. It's computationally intensive, making brute-force attacks harder.

Try running this example to see a password hashed:

const bcrypt = require('bcrypt');

const password = "mySecretP@ssword";
const saltRounds = 10; // Cost factor for hashing (higher is slower/more secure)

async function hashPassword() {
  try {
    const hashedPassword = await bcrypt.hash(password, saltRounds);
    console.log("Original: " + password);
    console.log("Hashed: " + hashedPassword);
  } catch (error) {
    console.error("Error hashing:" + error.message);
  }
}

hashPassword();

Storing Hashed Credentials

After hashing, only the hashed password should be stored in your database, along with other user details like their email or username.

  • NEVER store plain-text passwords.
  • The hash is unique for each password, even if the original passwords are the same (thanks to salting).
  • This hash is what you'll use for comparison during login.

The User Login Flow

When a user tries to log in, your application follows these steps:

  1. User provides their username/email and password.
  2. Application retrieves the user's record (including their stored hashed password) from the database based on the username/email.
  3. The provided password is hashed and compared against the stored hash.
  4. If they match, the user is authenticated, and a session or token is created.

Verifying Passwords with bcrypt

To check if a user's provided password matches the stored hash, we use bcrypt.compare(). It performs the hashing and comparison securely.

Run this code to see password comparison in action:

const bcrypt = require('bcrypt');

// This hash would typically come from your database
const storedHash = "$2b$10$w090/qB2k6n0Y7o8p9q.u.0Z1X2Y3Z4A5B6C7D8E9F0G1H2I3J4K5L6M7N8O9P0Q1R"; 

const passwordAttempt = "mySecretP@ssword";
const wrongAttempt = "incorrectPassword";

async function comparePasswords() {
  try {
    const isMatch = await bcrypt.compare(passwordAttempt, storedHash);
    console.log(`'${passwordAttempt}' matches: ${isMatch}`);

    const isWrongMatch = await bcrypt.compare(wrongAttempt, storedHash);
    console.log(`'${wrongAttempt}' matches: ${isWrongMatch}`);
  } catch (error) {
    console.error("Error comparing:" + error.message);
  }
}

comparePasswords();

Secure Credential Storage Practices

Beyond just hashing passwords, other credentials need protection:

  • API Keys & Database URLs: Store these in environment variables (e.g., .env files), not directly in your code.
  • Sensitive User Data: Encrypt any highly sensitive data at rest in your database.
  • Regular Updates: Keep your hashing libraries and dependencies up-to-date.

Handling Authentication Errors

When registration or login fails, provide helpful but generic error messages to the user. This prevents revealing too much information to potential attackers.

  • Instead of 'User not found', say 'Invalid credentials'.
  • Instead of 'Password incorrect', also say 'Invalid credentials'.
  • Log detailed errors on the server side for debugging, but don't expose them to the client.

Quick Check: Password Hashing

Test your understanding of why password hashing is essential for security.

Recap: Registration & Login

In this lesson, you learned the fundamental steps for user registration and login:

  • We covered the importance of password hashing using bcrypt to protect sensitive user data.
  • You saw how to implement both the hashing for registration and the comparison for login.
  • We also touched on best practices for secure credential storage and handling authentication errors gracefully.

Next, we'll dive into implementing stateless authentication using JSON Web Tokens (JWTs).

자주 묻는 질문

“사용자 등록과 로그인” 강의는 무료인가요?

네 — “사용자 등록과 로그인” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Node.js Backend Development Bootcamp 강의 전체를 잠금 해제할 수 있습니다. Node.js Backend Development Bootcamp 강의에는 총 6개의 강의가 포함되어 있습니다.

“사용자 등록과 로그인”에서 뭘 배우나요?

비밀번호 해싱과 안전한 자격 증명 저장을 포함한 사용자 등록 및 로그인 기능을 구축합니다. 브라우저에서 직접 실행하는 실습 코드로 Node.js Backend Development Bootcamp을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

Node.js Backend Development Bootcamp을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 Node.js Backend Development Bootcamp은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 6개 중 1번째 강의입니다.

“사용자 등록과 로그인” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 Node.js Backend Development Bootcamp 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 Node.js Backend Development Bootcamp 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. 사용자 등록과 로그인
  2. JWT 토큰 생성 및 검증
  3. 상태 비저장 인증을 위한 JWT
  4. OAuth2 비밀번호 흐름 연동
  5. 역할 기반 접근 제어
  6. 역할 기반 접근 제어(RBAC)
← Node.js Backend Development Bootcamp(으)로 돌아가기