Registo e Início de Sessão de Utilizadores
Crie funcionalidades de registo e início de sessão de utilizadores, incluindo hashing de palavras-passe e armazenamento seguro de credenciais.
Registo e Início de Sessão de Utilizadores é uma aula grátis de Node.js Backend Development Bootcamp no CoddyKit. Esta é a aula 1 de 6. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Node.js Backend Development Bootcamp, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Node.js Backend Development Bootcamp inclui 6 aulas no total.
Partes desta aula ainda não foram traduzidas e aparecem em inglês.
Welcome to User Authentication
User authentication is how we verify who a user is. It's a critical part of almost any application that handles personal data or restricted features.
- Why it matters: Protects user accounts and sensitive information.
- What we'll cover: Building registration and login flows from scratch.
The User Registration Flow
Registering a new user involves several steps to create a new account:
- User provides credentials (e.g., username, password, email).
- Input data is validated (e.g., strong password, unique email).
- The password is hashed for security.
- New user data (including the hashed password) is saved to the database.
Why Hash Passwords?
Storing passwords in plain text is a huge security risk! If your database is breached, all user passwords would be exposed.
Hashing transforms a password into a fixed-size, unreadable string. It's a one-way process, meaning you can't easily get the original password back from the hash.
We use libraries like bcrypt in Node.js for robust password hashing, which also adds a 'salt' to prevent common attacks.
Hashing Passwords with bcrypt
bcrypt is a popular library for securely hashing passwords. It's computationally intensive, making brute-force attacks harder.
Try running this example to see a password hashed:
const bcrypt = require('bcrypt');
const password = "mySecretP@ssword";
const saltRounds = 10; // Cost factor for hashing (higher is slower/more secure)
async function hashPassword() {
try {
const hashedPassword = await bcrypt.hash(password, saltRounds);
console.log("Original: " + password);
console.log("Hashed: " + hashedPassword);
} catch (error) {
console.error("Error hashing:" + error.message);
}
}
hashPassword();
Storing Hashed Credentials
After hashing, only the hashed password should be stored in your database, along with other user details like their email or username.
- NEVER store plain-text passwords.
- The hash is unique for each password, even if the original passwords are the same (thanks to salting).
- This hash is what you'll use for comparison during login.
The User Login Flow
When a user tries to log in, your application follows these steps:
- User provides their username/email and password.
- Application retrieves the user's record (including their stored hashed password) from the database based on the username/email.
- The provided password is hashed and compared against the stored hash.
- If they match, the user is authenticated, and a session or token is created.
Verifying Passwords with bcrypt
To check if a user's provided password matches the stored hash, we use bcrypt.compare(). It performs the hashing and comparison securely.
Run this code to see password comparison in action:
const bcrypt = require('bcrypt');
// This hash would typically come from your database
const storedHash = "$2b$10$w090/qB2k6n0Y7o8p9q.u.0Z1X2Y3Z4A5B6C7D8E9F0G1H2I3J4K5L6M7N8O9P0Q1R";
const passwordAttempt = "mySecretP@ssword";
const wrongAttempt = "incorrectPassword";
async function comparePasswords() {
try {
const isMatch = await bcrypt.compare(passwordAttempt, storedHash);
console.log(`'${passwordAttempt}' matches: ${isMatch}`);
const isWrongMatch = await bcrypt.compare(wrongAttempt, storedHash);
console.log(`'${wrongAttempt}' matches: ${isWrongMatch}`);
} catch (error) {
console.error("Error comparing:" + error.message);
}
}
comparePasswords();
Secure Credential Storage Practices
Beyond just hashing passwords, other credentials need protection:
- API Keys & Database URLs: Store these in environment variables (e.g.,
.envfiles), not directly in your code. - Sensitive User Data: Encrypt any highly sensitive data at rest in your database.
- Regular Updates: Keep your hashing libraries and dependencies up-to-date.
Handling Authentication Errors
When registration or login fails, provide helpful but generic error messages to the user. This prevents revealing too much information to potential attackers.
- Instead of 'User not found', say 'Invalid credentials'.
- Instead of 'Password incorrect', also say 'Invalid credentials'.
- Log detailed errors on the server side for debugging, but don't expose them to the client.
Quick Check: Password Hashing
Test your understanding of why password hashing is essential for security.
Recap: Registration & Login
In this lesson, you learned the fundamental steps for user registration and login:
- We covered the importance of password hashing using
bcryptto protect sensitive user data. - You saw how to implement both the hashing for registration and the comparison for login.
- We also touched on best practices for secure credential storage and handling authentication errors gracefully.
Next, we'll dive into implementing stateless authentication using JSON Web Tokens (JWTs).
Perguntas Frequentes
A aula “Registo e Início de Sessão de Utilizadores” é grátis?
Sim — o texto completo de “Registo e Início de Sessão de Utilizadores” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Node.js Backend Development Bootcamp, atualize para CoddyKit PRO. O curso de Node.js Backend Development Bootcamp inclui 6 aulas no total.
O que vou aprender em “Registo e Início de Sessão de Utilizadores”?
Crie funcionalidades de registo e início de sessão de utilizadores, incluindo hashing de palavras-passe e armazenamento seguro de credenciais. Você pratica Node.js Backend Development Bootcamp com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.
Preciso ter experiência prévia para começar Node.js Backend Development Bootcamp?
Nenhuma experiência prévia é necessária. Node.js Backend Development Bootcamp no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 1 de 6.
Quanto tempo leva a aula “Registo e Início de Sessão de Utilizadores”?
A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.
Posso escrever e executar código nesta aula de Node.js Backend Development Bootcamp?
Sim. Cada aula de Node.js Backend Development Bootcamp inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.
Todas as aulas deste curso
- Registo e Início de Sessão de Utilizadores
- Geração e validação de tokens JWT
- JWT para Autenticação sem Estado
- Integração do fluxo de senha do OAuth2
- Controlo de Acesso Baseado em Funções
- Controle de acesso baseado em funções (RBAC)