 
  
  const token = jwt.sign(
            { userId: user.userId, username: user.username, email: user.email },
            process.env.JWT_SECRET,
            {
              expiresIn: '30 days',
            }
          )
          res.setHeader('Set-Cookie', serialize('token', token, { path: '/' }))
          res.redirect(307, `/activate/${hash}`)
          res.end();