1
00:00:00,390 --> 00:00:04,900
Remember how I suggested to think of JWT as long strings?

2
00:00:05,240 --> 00:00:07,710
Well, of course, it's way more complex than that.

3
00:00:08,130 --> 00:00:14,250
So now let's spend a few minutes on the JWT structure and then, of course, we'll dive back into the

4
00:00:14,250 --> 00:00:14,640
code.

5
00:00:15,060 --> 00:00:20,580
And a very good resource is set by the name of JWT eyehole.

6
00:00:21,000 --> 00:00:28,530
Again, the URL is JWT eyehole and more specifically, we're interested in two pages, the introduction

7
00:00:28,530 --> 00:00:30,410
on the debugger.

8
00:00:30,570 --> 00:00:35,520
And I'll start with introduction and I'm not going to read the entire thing line by line.

9
00:00:35,740 --> 00:00:38,010
That just seems a big waste of your time.

10
00:00:38,280 --> 00:00:40,380
But I do want to point out some things here and there.

11
00:00:40,740 --> 00:00:44,900
As always, if you are interested in learning more, you know already where to find it.

12
00:00:45,480 --> 00:00:50,100
And the first thing that I want to point out is the sentence where it says all this information can

13
00:00:50,100 --> 00:00:54,580
be verified and trusted because it is digitally signed.

14
00:00:54,900 --> 00:00:57,840
So this is what I was saying in the previous video.

15
00:00:58,230 --> 00:01:04,650
And essentially we do that using the secret and the algorithm and we'll learn more about them in a few

16
00:01:04,650 --> 00:01:05,060
seconds.

17
00:01:05,430 --> 00:01:06,840
So I just keep on scrolling.

18
00:01:06,860 --> 00:01:12,780
They say when you should use tokens, check out of the area and this is going to be the structure for

19
00:01:12,780 --> 00:01:13,110
the Web.

20
00:01:13,590 --> 00:01:17,340
And like I said, the result is going to look like a large string.

21
00:01:17,340 --> 00:01:19,710
But of course, it's way more complex than that.

22
00:01:19,920 --> 00:01:26,150
And essentially an address on Web token we have in the header payload as well as the signature.

23
00:01:26,610 --> 00:01:32,730
And when it comes to header consists of two parts and one is going to be the type of token and of course,

24
00:01:32,730 --> 00:01:34,740
we're going to go with JWT.

25
00:01:34,980 --> 00:01:40,860
And the second one is going to be the algorithm that is used, of course, to create that signature.

26
00:01:41,280 --> 00:01:48,990
Then this one gets encoded with base64 Yoro, a code, this one, and then we have the payload in the

27
00:01:48,990 --> 00:01:49,500
payload.

28
00:01:49,510 --> 00:01:51,300
This is where we place the information.

29
00:01:52,080 --> 00:01:58,830
And as an example, we can place here the ID of the user that just signed on or logged in or registered

30
00:01:58,830 --> 00:01:59,430
or whatever.

31
00:01:59,840 --> 00:02:06,660
Then we send back the token, the entire token with that payload back to the front and then the front

32
00:02:06,660 --> 00:02:08,430
end, send it back to us.

33
00:02:08,430 --> 00:02:11,050
And then when we decode, we get that idea.

34
00:02:11,640 --> 00:02:18,200
And essentially what that means is that if the user has some kind of resource, we access right away

35
00:02:18,210 --> 00:02:21,370
resources that belong to only that user.

36
00:02:21,660 --> 00:02:28,500
So essentially, if you create some kind of resource, only you can access it or modify it or whatever.

37
00:02:28,900 --> 00:02:34,140
And we keep crawling, keep on scrolling and I'll talk about the payload, of course, when we actually

38
00:02:34,410 --> 00:02:35,670
create our own token.

39
00:02:36,030 --> 00:02:39,470
This is just an example of what we can send back again.

40
00:02:39,510 --> 00:02:43,640
This also gets encoded with base64, your URL.

41
00:02:44,010 --> 00:02:46,260
And then lastly, we have the signature.

42
00:02:46,750 --> 00:02:53,220
And as far as the signature, this is where the algorithm is used and one that is specified in the header.

43
00:02:53,610 --> 00:02:57,470
And then we add here the secret to sign our token.

44
00:02:57,930 --> 00:03:02,150
And as far as the secret, this is something that we'll have to keep on the server.

45
00:03:02,850 --> 00:03:08,410
And again, I'll talk about when we actually create our own signature.

46
00:03:08,730 --> 00:03:15,840
So once we set up our first token, then I'll talk about it, how and where we should store the secret

47
00:03:15,840 --> 00:03:16,170
value.

48
00:03:16,230 --> 00:03:22,410
And the idea is we have the algorithm, we have the encoded header as well as the payload.

49
00:03:22,650 --> 00:03:28,680
Then we take the secret string value that is always going to be only on the server.

50
00:03:29,070 --> 00:03:34,260
And then we sign this one and then once we sign, this is going to be a result.

51
00:03:34,530 --> 00:03:38,490
So essentially, this is what we're sending back to the front end.

52
00:03:38,610 --> 00:03:44,070
And after that, we have a bunch of useful information of how we can send back a token from the front

53
00:03:44,070 --> 00:03:44,240
end.

54
00:03:44,550 --> 00:03:49,310
And this is something, again, we'll cover a little bit later once we already create our token.

55
00:03:49,440 --> 00:03:54,480
So we'll swing back and I'll discuss what is the bare and all this cool stuff.

56
00:03:54,780 --> 00:03:57,630
And as far as the structure, I think we're pretty much done.

57
00:03:57,940 --> 00:04:02,190
I just want to showcase in the bugger that, of course, we have to talk.

58
00:04:02,190 --> 00:04:09,120
And like I said, this is the signed token, the encoded one, and this is what we're sending back to

59
00:04:09,120 --> 00:04:09,640
the front end.

60
00:04:09,870 --> 00:04:11,950
So this is what the front end will receive.

61
00:04:12,450 --> 00:04:14,140
Now, once we decode.

62
00:04:14,160 --> 00:04:14,820
There you go.

63
00:04:15,090 --> 00:04:17,310
You'll have information about that user.

64
00:04:17,640 --> 00:04:20,760
So you'll have some kind of idea, maybe a name.

65
00:04:20,760 --> 00:04:25,770
And when it was issued and of course, later, we'll do something with that data.

66
00:04:26,100 --> 00:04:32,340
So this is the idea that we're looking for the user ready and then we can use this site to access the

67
00:04:32,340 --> 00:04:35,280
database resources and all that stuff.

68
00:04:35,520 --> 00:04:37,480
Hopefully we're clear on the structure.

69
00:04:38,040 --> 00:04:44,190
So now we can take a look at the package we'll use to sign and decode our tokens.

