I am trying to build a session-based authentication for my web app. I have the following auth function:
function authenticate(req, res) {
var body = req.body;
getAuthUser(body.username, function (err, result) {
if (hash(body.password) != result.password) {
// invalid pass
return;
}
req.session['user'] = result;
res.redirect('/logged/panel');
console.log(req.session); // 'user' session is displayed here
});
}
I have also a middleware which ensures that user is authenticated when accessing secured content:
function validateRequest(req, res, next) {
console.log(req.session); // 'user' session is not displayed here
(req.session.user) ? next() : res.redirect('/login');
}
The problem is that my middleware does not see the stored variable by the authenticate
function. Thank you in advance.
EDIT:
This is how I use my middleware:
router.use(validateRequest);