If this article is to be believed, they are storing user passwords in plaintext.
import { compare } from "bcrypt";
If I wanted harden this setup, my next consideration would be either having a separate microservice that's purely responsible for auth, or using 3rd party provider like Cognito.