1
00:00:00,330 --> 00:00:05,090
All right, and welcome to our next adventure, the JSON Web Tokens Basics Project.

2
00:00:05,670 --> 00:00:11,880
So far in our project, all the results were public, meaning anyone can access them and use them however

3
00:00:11,880 --> 00:00:12,450
they please.

4
00:00:13,050 --> 00:00:16,129
But of course, that's not how we want to set up apps in real world.

5
00:00:16,770 --> 00:00:21,970
I don't want random people to access my data, and I bet you probably feel exactly the same way.

6
00:00:22,530 --> 00:00:30,630
So how we can restrict the access, while I'm glad you asked, a very popular method is using JWT or

7
00:00:30,630 --> 00:00:31,590
just on Web tokens.

8
00:00:32,159 --> 00:00:35,930
And for the sake of simplicity, just think of them as long strings.

9
00:00:36,300 --> 00:00:38,910
And of course, they are way more complex than that.

10
00:00:38,910 --> 00:00:41,240
But let's just not worry about that right now.

11
00:00:41,760 --> 00:00:43,070
And the idea is falling.

12
00:00:43,290 --> 00:00:48,560
Imagine we have to use a dashboard and a login or register out.

13
00:00:49,170 --> 00:00:56,070
Now, Dashboard is protected so I can click all day long on get data, but I'll have no access to the

14
00:00:56,070 --> 00:01:03,930
info and only if I login, I get the token and only once I have the token I can access the secret info,

15
00:01:04,140 --> 00:01:06,740
which in this case is just going to be a random number.

16
00:01:07,110 --> 00:01:12,980
So let's try it out and have the dashboard clearly says here now talk in prison and check it out.

17
00:01:13,140 --> 00:01:15,350
Not authorized to access this route.

18
00:01:15,660 --> 00:01:21,600
And again, I can click all day long and I can showcase that in the console where we're getting these

19
00:01:22,050 --> 00:01:23,460
four or one errors.

20
00:01:23,790 --> 00:01:29,880
But I'll have no access to the data now in order to access the data because I need to login.

21
00:01:30,270 --> 00:01:34,800
And of course, this is just going to be a simple version where I just need to provide some kind of

22
00:01:34,800 --> 00:01:35,280
values.

23
00:01:35,670 --> 00:01:39,280
If I won't provide the then I'll get the four hundred one.

24
00:01:39,660 --> 00:01:43,530
So this is going to be a bad request and I still don't get the token.

25
00:01:43,920 --> 00:01:48,480
So let's go up and say user name and I'm just going to go with my John.

26
00:01:48,750 --> 00:01:50,910
And again, you just need to provide some kind of ours.

27
00:01:51,300 --> 00:01:53,590
Doesn't really matter in a later project.

28
00:01:53,610 --> 00:01:55,800
Of course it will matter what we provide there.

29
00:01:55,800 --> 00:01:58,650
But in this case, we just need to provide something.

30
00:01:59,010 --> 00:02:03,030
And only if I do that, then I send it here.

31
00:02:03,270 --> 00:02:04,890
Notice user created.

32
00:02:05,160 --> 00:02:06,810
So now, of course, I have no errors.

33
00:02:07,140 --> 00:02:10,870
And also in the local storage, I'm going to get the token file.

34
00:02:10,949 --> 00:02:13,590
Don't worry about the front end, local storage and all that.

35
00:02:13,800 --> 00:02:16,370
I'll talk about it in more detail later.

36
00:02:16,590 --> 00:02:22,740
Just think that you're getting the token and once the token is present and of course we can clearly

37
00:02:22,740 --> 00:02:30,810
see that here we the text of token present, then we can make as many requests as we want in order to

38
00:02:30,810 --> 00:02:31,560
get our data.

39
00:02:31,890 --> 00:02:35,340
Then as long as the token is valid, we are good to go.

40
00:02:35,730 --> 00:02:42,540
Now, if we can, I'll try to submit and then out of the token, then again, we're back to the not

41
00:02:42,540 --> 00:02:43,690
authorized this route.

42
00:02:43,920 --> 00:02:49,290
Now, the reason why I made this project so simple and straightforward is because it's crucial that

43
00:02:49,290 --> 00:02:50,910
you grasp the main concept.

44
00:02:51,450 --> 00:02:57,900
If you do, I guarantee you you'll breeze through the upcoming project, even though they will be way

45
00:02:57,900 --> 00:02:59,250
more complex than this.

46
00:02:59,790 --> 00:03:08,550
Just always remember, if a valid token is present in the request, the user can access specific info.

47
00:03:08,850 --> 00:03:14,250
Now, not all of the info, of course, you can only access the info that belongs to you.

48
00:03:14,580 --> 00:03:17,850
So you of just randomly come here and get my data.

49
00:03:18,120 --> 00:03:22,350
But still, if the token is present, you can get that specific data.

50
00:03:22,560 --> 00:03:29,550
But if we have a restricted route, so keep in mind that logging is not restricted, anyone can try

51
00:03:29,550 --> 00:03:30,030
to log in.

52
00:03:30,030 --> 00:03:38,430
But if we do have the restricted route like we have with Dashboard, if the token is not present or

53
00:03:38,730 --> 00:03:45,930
it's not valid, then the server in this case, that's of course, us will kick back the error response.

54
00:03:45,960 --> 00:03:54,000
And that's how essentially we restrict access to certain routes, a certain resources.

