Resetting password using express and JWT token - express

I am trying to reset the user password using the following code and Postman.
But what I realised is that there is no user after I generate the token. the console is saying null;
// Reset User Password
exports.resetPassword = function (req, res) {
reset_password_token: req.body.token,
reset_password_expires: {
}).exec(function (err, user) {
console.log('this user: ' + user)
if (!err && user) {
if (req.body.newPassword === req.body.verifyPassword) {
user.hash_password = bcrypt.hashSync(req.body.newPassword, 10);
user.reset_password_token = undefined;
user.reset_password_expires = undefined; (err) {
if (err) {
return res.status(422).send({
message: err
} else {
} else {
return res.status(422).send({
message: 'Passwords do not match'
} else {
return res.status(400).send({
message: 'Password reset token is invalid or has expired.'
This is how I use it in Postman
"newPassword": "cocacola",
"verifyPassword": "cocacola",
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJzdWIiOiI1YjI3NjAyNDAwOWI1NDA5ZjMwNzAzZWYiLCJpYXQiOjE1MzA5NjA2NDEwOTN9.1LjroayiTWDNevShnH30n3LxUGCrazmTaJlHgOUNvJ0"
and the response in Postman is message from status 400


Getting error in MERN stack Error [ERR_HTTP_HEADERS_SENT]: Cannot set headers after they are sent to the client

I am new to MERN. I was using this code below . I followed a youtube tutorial and it was working fine for me for 4 to 5 days but now suddenly it has stopped working. I didn't change anything. I am not able to login, logout or even fetch data. My postman is giving positive results using these api but it won't work on my code. I want to remind you guys again, it was working fine for 4 to 5 days.
const User = require("../model/user");
const bcrypt = require("bcryptjs");
const jwt = require("jsonwebtoken");
const signup = async (req, res, next) => {
const { fname, lname, email, password, role, phone } = req.body;
let existingUser;
try {
existingUser = await User.findOne({ email: email });
} catch (err) {
if (existingUser) {
return res.status(400).json({ message: "user already exists" });
const hashedPassword = bcrypt.hashSync(password);
const user = new User({
password: hashedPassword,
try {
} catch (err) {
return res.status(201).json({ message: user });
const login = async (req, res, next) => {
const { email, password } = req.body;
let existingUser;
try {
existingUser = await User.findOne({ email: email });
} catch (err) {
if (!existingUser) {
return res
.json({ message: "user doesn't exist. Please signup" });
const isPasswordCorrect = bcrypt.compareSync(password, existingUser.password);
if (!isPasswordCorrect) {
return res.status(401).json({ message: "invalid email or password" });
const token = jwt.sign({ id: existingUser._id }, "change1122", {
expiresIn: "1h",
res.cookie(String(existingUser._id), token, {
path: "/",
expires: new Date( + 1000 * 3600),
httpOnly: true,
sameSite: "lax",
return res
.json({ message: "user logged in sucessfully", user: existingUser, token });
const verifyToken = (req, res, next) => {
const cookies = req.headers.cookie;
const token = cookies.split("=")[1];
if (!token) {
res.status(404).json({ message: "no token found" });
jwt.verify(String(token), "change1122", (err, user) => {
if (err) {
return res.status(404).json({ message: "invalid token" });
} =;
const getUser = async (req, res, next) => {
const id =;
let user;
try {
user = await User.findById(id, "-password");
} catch (err) {
if (!user) {
res.status(404).json({ message: "user not found with the id" });
return res.status(200).json({ user });
const logout = async (req, res, next) => {
const cookies = req.headers.cookie;
const token = cookies.split("=")[1];
if (!token) {
res.status(404).json({ message: "no token found" });
const user =;
req.cookies[`${user}`] = "";
return res.status(200).json({ message: "successfully logged out" });
exports.signup = signup;
exports.login = login;
exports.verifyToken = verifyToken;
exports.getUser = getUser;
exports.logout = logout;
Here is the error
Error [ERR_HTTP_HEADERS_SENT]: Cannot set headers after they are sent to the client
at new NodeError (node:internal/errors:372:5) at ServerResponse.setHeader (node:_http_outgoing:576:11)
at ServerResponse.header (E:\Reacct\pos\server\node_modules\express\lib\response.js:794:10)
at ServerResponse.send (E:\Reacct\pos\server\node_modules\express\lib\response.js:174:12)
at ServerResponse.json (E:\Reacct\pos\server\node_modules\express\lib\response.js:278:15)
at getUser (E:\Reacct\pos\server\controller\user-controller.js:86:25)
at processTicksAndRejections (node:internal/process/task_queues:96:5) {
[nodemon] app crashed - waiting for file changes before starting...
I think i have an issue with cookies or token, I am new so i don't understand it properly.

get logged in ID from jwt so that only logged in user can see particular data in nodejs

I am using nodejs, jwt and mysql.
I want the current logged in user ID soo that I can show the data respective to it.
This is my code where SQL logic is written and here I am expecting to get a current user ID.
const pool = require('../../dbconfig/dbconfig');
module.exports = {
getProfile : (callBack) => {
var sql = 'SELECT name, shopStatus, phone, shopaddress.shopNo, shopaddress.complex, shopaddress.landmark, shopaddress.street, shopaddress.area, FROM shop INNER JOIN shopaddress ON = shopaddress.shop_id WHERE = ?'
var insertSql = [ /* how can i get ID here.. */ ]
pool.query(sql, insertSql, (err, results, fields) => {
if(err) {
return callBack(err)
return callBack(null, results)
this happens to be jwt middleware code
const jwt = require('jsonwebtoken')
const config = require('../../config')
module.exports = {
isAuth: (req, res, next) => {
let token = req.get("authorization");
if (token) {
// Remove Bearer from string
token = token.slice(7);
jwt.verify(token, config.secret, (err, decoded) => {
if (err) {
return res.json({
status: 'error',
message: "Invalid Token..."
} else {
req.decoded = decoded;
} else {
return res.json({
status: 'error',
message: "Access Denied! Unauthorized User"
and this is controller
const shopService = require('./shop.service')
module.exports = {
shopProfile : (req, res) => {
shopService.getProfile((err, results) => {
return res.status(500).json({
status : 'error',
error : err,
message : 'Database connection error'
return res.status(200).json({
data : results

user.comparePassword is not a function

I got stuck on hashed password validation with bcrypt-nodejs, nodeJS (expressJS) and mongoose. User can register and code generates hashed password but when I try to validate that password with comparePassword function in login page it does not work and gives me error user.comparePassword is not a function
Here is the code:
UserSchema.pre('save', async function(next){
var user = this;
if(!user.isModified('password')) return next();
bcrypt.genSalt(SALT_WORK_FACTOR, function(err, salt){
if(err) return next(err)
bcrypt.hash(user.password, salt,null, function(err,hash){
if(err) return next(err)
user.password = hash
UserSchema.methods.comparePassword = async function(candidatePassword, cb){, this.password, function(err, isMatch){
if(err) return cb(err);
cb(null, isMatch)
Route:'/', async (req, res) => {
try {
const {username, password} = req.body;
const user = await User.findOne({username}).lean();
if (!user) {
return res.status(404).send({
message: 'user is not registered'
if(username.trim().length < 1 && password.trim().length < 1){
return res.status(409).send({message: 'username & password is required'})
// if (user.password !== password) {
// return res.status(403).send({
// message: 'user password invalid'
user.comparePassword(password, function(err, isMatch){
return res.status(500).send({message: err.message})
return res.status(403).send({
message: 'user password invali'
req.session.user = user;
const redirectTo = '/dashboard';
if ('application/json') // request content type is json
|| // or
req.xhr // is ajax
) {
// respond with json response
return res.status(200).send({redirectTo});
// not ajax request
// then respond redirect header
const mongoose = require('mongoose');
var bcrypt = require('bcrypt-nodejs');
const userDataModal = mongoose.Schema({
username: {
type: String,
required : true,
password: {
type: String,
required : true
userDataModal.pre('save', function(next) {
var user = this;
// only hash the password if it has been modified (or is new)
if (!user.isModified('password')) return next();
// generate a salt
bcrypt.genSalt(SALT_WORK_FACTOR, function(err, salt) {
if (err) return next(err);
// hash the password using our new salt
bcrypt.hash(user.password, salt, null, function(err, hash) {
if (err) return next(err);
// override the cleartext password with the hashed one
user.password = hash;
userDataModal.methods.comparePassword = function(candidatePassword, cb) {, this.password, function(err, isMatch) {
if (err) return cb(err);
cb(null, isMatch);
// Users.index({ emaiId: "emaiId", fname : "fname", lname: "lname" });
const userDatamodal = module.exports = mongoose.model("usertemplates" , userDataModal)
//inserting document
userDataModel.findOne({ username: reqData.username }).then(doc => {
if (doc == null) {
let userDataMode = new userDataModel(reqData);
// userDataMode.password = userDataMode.generateHash(reqData.password);{new:true}).then(data=>{
let obj={
message: "New user registered successfully",
else {
success: true,
docExists: true,
message: "already user registered",
data: doc
}).catch(err => {
//retriving and checking
// test a matching password
user.comparePassword(requestData.password, function(err, isMatch) {
if (err){
'status': 'Error',
'data': err
throw err;
} else {
'status': true,
'data': user,
'loginStatus' : "successfully Login"
console.log('Password123:', isMatch); // -> Password123: true

Bcrypt + Sequelize password not saving as hash in DB

Sequelize + Bcrypt not storing passwords in DB as hash
As the title says, whenever I attempt to store a user into my SQLite DB the console outputs the password as a hash but when I look into the DB with DBbrowser I can see the plaintext password.
// const Promise = require('bluebird')
const bcrypt = require('bcrypt')
async function hashPassword (user, options) {
if (!user.changed('password')) {
return 0
const SALT_FACTOR = 8
await bcrypt.hash(user.password, SALT_FACTOR, (err, hash) => {
if (err) {
// user.setDataValue('password', hash)
user.password = hash
module.exports = (sequelize, DataTypes) => {
const User = sequelize.define('User', {
email: {
type: DataTypes.STRING,
unique: true
password: DataTypes.STRING
}, {
hooks: {
beforeSave: hashPassword,
beforeCreate: hashPassword
User.prototype.comparePassword = function (password) {, this.password, function (res, err) {
if (res) {
} else {
return, this.password)
return User
module.exports = {
async register (req, res) {
try {
const user = await User.create(req.body)
const userJson = user.toJSON()
user: userJson,
token: jwtSignUser(userJson)
} catch (err) {
// e-mail already exists or such
error: 'This email address is already in use'
async login (req, res) {
try {
// Grab user input
const { email, password } = req.body
const user = await User.findOne({
where: {
email: email
// Check to see if user is in db
if (!user) {
error: 'the login information was incorrect / Not Found'
// Check to see if password is valid
const isPasswordValid = await user.comparePassword(password)
if (!isPasswordValid) {
return res.status(403).send({
error: 'The login information was incorrect'
// return user using toJSON()
const userJson = user.toJSON()
user: userJson,
token: jwtSignUser(userJson)
} catch (e) {
res.status(500).send({ error: 'An error occured attempting to login' })
To elaborate a little more, whenever I create a user, I receive the following:
"user": {
"id": 1,
"email": '",
"password": "$2b$08$SYYXU/GDSCFsp3MVeuqrduI0lOLHeeub7whXiaMMoVxO53YJry.1i",
"updatedAt": "2018-09-07T22:44:12.944Z",
"createdAt": "2018-09-07T22:44:12.944Z"
Which to me says the DB successfully hashed my password, and stored it. The overhanging issue for me with this is the fact that I believe it's causing the function to spit out 'false'. As always, any insight or help would be greatly appreciated!
I'm pretty sure that this answer is too late for you, but might help others landing on this same question.
The main issue I can see is how you are using the async/await pattern. Changing this:
async function hashPassword (user, options) {
if (!user.changed('password')) {
return 0
const SALT_FACTOR = 8
await bcrypt.hash(user.password, SALT_FACTOR, (err, hash) => {
if (err) {
// user.setDataValue('password', hash)
user.password = hash
to this, worked for me:
async function hashPassword(user, options) {
if (!user.changed("password")) {
return 0;
user.password = await bcrypt.hash(user.password, SALT_FACTOR);
Can you please try to add only one hook
hooks: {
beforeSave: hashPassword,
Because I think your password is getting hashed two times. as beforeSave and beforeCreate both hooks get executed.
Hope it helps

Using async in express

Below is my rest API endpoint /signup. The problem I'm having now is that the endpoint does not stop after validateEmail. Even after it failed email form-validation and res.send() is done, the endpoint continues. So I'm keep getting the error 'Error: Can't set headers after they are sent.'. I would like to be able to finish the endpoint inside its functions like validateEmail , checkEmailInUse, makeUser, and so on."/signup", async (req, res, next) => {
const { email, password } = req.body;
const users ="users");
validateEmail(res, email);
await checkEmailInUse(res, users, email);
const user = await makeUser(res, users, email, password);
res.send({ message: "POST signup request OK", user });
function validateEmail(res, email) {
const isEmail = emailFilter.test(email);
if (!isEmail) {
error: {
message: "Requested email is not email type",
type: "FormatValidation",
location: "validateEmail"
async function checkEmailInUse(res, users, email) {
const query = { email };
try {
const user = await users.findOne(query);
if (user) {
res.send({ message: "The email is already used" });
} catch (err) {
error: {
message: "Failed to find user",
type: "DatabaseError",
location: "checkEmailInUse"
The code keeps going after a failed validate because you call:
validateEmail(res, email);
and then your code just keeps going. This is normal flow of control in Javascript. Your function keeps executing lines of code until you return in the function. The same issue is true for checkEmailInUse(). If you want to sometimes send the response inside those functions and be done, then you need a return value from those functions that you can check and then use if statements to determine whether your code should do more or not.
Following your style of sending the error response inside the validation functions (which is not how I would probably structure things), you could return values from those functions and test those return values in the request handler like this:"/signup", async (req, res, next) => {
const { email, password } = req.body;
const users ="users");
if (validateEmail(res, email)) {
if (await checkEmailInUse(res, users, email)) {
const user = await makeUser(res, users, email, password);
res.send({ message: "POST signup request OK", user });
function validateEmail(res, email) {
const isEmail = emailFilter.test(email);
if (!isEmail) {
error: {
message: "Requested email is not email type",
type: "FormatValidation",
location: "validateEmail"
return false;
return true;
async function checkEmailInUse(res, users, email) {
const query = { email };
try {
const user = await users.findOne(query);
if (user) {
res.send({ message: "The email is already used" });
return false;
} else {
return true;
} catch (err) {
error: {
message: "Failed to find user",
type: "DatabaseError",
location: "checkEmailInUse"
return false;
But, I think you might find this is simpler if you get rid of the local functions because then when you send a response, you can just directly return from the main function and be done. Here's how that could look:"/signup", async (req, res, next) => {
function err(res, message, type, location) {
res.status(400).send({error: {message, type, location}});
const { email, password } = req.body;
if (!emailFilter.test(email)) {
err(res, "Requested email is not email type", "FormatValidation", "validateEmail");
const users ="users");
try {
const user = await users.findOne({email});
if (user) {
res.send({ message: "The email is already used" });
} catch(e) {
err(res, "Failed to find user", "DatabaseError", "checkEmailInUse");
try {
const user = await makeUser(res, users, email, password);
res.send({ message: "POST signup request OK", user });
} catch(e) {
err(res, "Failed to make user", "DatabaseError", "makeUser");