1
00:00:00,720 --> 00:00:09,410
And once we have discussed the general principles of JWT, now let's try to issue one in the project

2
00:00:10,050 --> 00:00:14,700
and first of all, we want to do is import of the package now and again.

3
00:00:14,700 --> 00:00:16,890
The package for is this one.

4
00:00:17,840 --> 00:00:19,320
Jason WebSocket.

5
00:00:19,680 --> 00:00:22,290
And of course, we want to send it to some kind of variable.

6
00:00:22,470 --> 00:00:25,950
So I'm going to go with JWT is equal to require.

7
00:00:26,340 --> 00:00:28,380
And of course, we're looking for a package.

8
00:00:29,100 --> 00:00:36,180
And once we have the package after the F, assuming that both of these values are provided, we want

9
00:00:36,180 --> 00:00:39,690
to create a new token and we do that in the following way.

10
00:00:40,020 --> 00:00:42,220
So we come up with some kind of variable in this case.

11
00:00:42,240 --> 00:00:45,030
Again, it's going to be a token, pretty straightforward.

12
00:00:45,420 --> 00:00:47,520
And then we go with JWT.

13
00:00:47,700 --> 00:00:54,270
So the package name and then we're looking for the same method and not in the same method.

14
00:00:55,220 --> 00:00:56,910
We want to provide three values.

15
00:00:57,560 --> 00:01:05,470
We want to provide a payload, a JWT secret essentially is just a secret strength.

16
00:01:05,840 --> 00:01:10,910
And then the options now when it comes to payload, you go with object.

17
00:01:11,180 --> 00:01:13,890
And pretty much in here you can pass whatever you want.

18
00:01:14,270 --> 00:01:15,330
Sky's the limit.

19
00:01:15,590 --> 00:01:17,060
Now, please remember one thing.

20
00:01:17,060 --> 00:01:23,860
You don't want to send back some kind of confidential information, so don't stick a password over here.

21
00:01:24,320 --> 00:01:27,310
That is a very, very, very bad practice.

22
00:01:27,530 --> 00:01:29,100
Now, what normally gets sent back?

23
00:01:29,420 --> 00:01:37,490
Well, if we're creating a user ID is very helpful because then later on when we're authenticating the

24
00:01:37,490 --> 00:01:40,180
request, we can check for the user.

25
00:01:40,460 --> 00:01:48,620
If I'm creating a user and that user is checking for some kind of resources, we only provide resources

26
00:01:49,010 --> 00:01:50,610
that belong to the user.

27
00:01:51,320 --> 00:02:00,260
So in our task manager application, we only provide tasks that belong to the user and as a result,

28
00:02:00,530 --> 00:02:08,330
only the user who created the task, for example, can hear it or delete it and hopefully get the gist.

29
00:02:09,139 --> 00:02:13,970
So in here, I'm just going to go with username I was already provided over here.

30
00:02:14,240 --> 00:02:18,080
So that's why I'm standing back and like I said, normally send back the idea.

31
00:02:18,080 --> 00:02:24,170
But since we don't have the connection to the database, I'll create a dummy one from the scratch.

32
00:02:24,440 --> 00:02:30,170
I'll simply go with it and then I'll go with new date and say, get time.

33
00:02:30,170 --> 00:02:35,030
And let me just add a comment just so it's clear that this is only for Demo.

34
00:02:35,300 --> 00:02:42,200
And once I have both of the comments, first all of the ID and I just want to mention here that when

35
00:02:42,200 --> 00:02:47,270
it comes to payloads, it's a good idea to keep them small because the bigger the payload, the more

36
00:02:47,270 --> 00:02:48,790
data you're sending over the wire.

37
00:02:49,220 --> 00:02:55,280
And of course, as a result, for someone with bad Internet connection or user experience might not

38
00:02:55,280 --> 00:02:56,040
be the best one.

39
00:02:56,360 --> 00:02:58,220
So that's about it for the payload.

40
00:02:58,490 --> 00:03:01,550
And then we want to provide that JWT secret.

41
00:03:01,880 --> 00:03:07,730
So we go here with a comma and we right away want to set it up in our dot enemy.

42
00:03:08,120 --> 00:03:10,580
So of course, we need to create one from the scratch.

43
00:03:10,970 --> 00:03:17,570
And in the star, we're going to go with new file dot EMV and then we need to come up with a variable

44
00:03:17,570 --> 00:03:17,930
name.

45
00:03:18,140 --> 00:03:22,790
And in my case, I'm going to go with JWT underscore secret.

46
00:03:23,090 --> 00:03:29,270
And when it comes to value in this application, I'm just going to go with something really simple as

47
00:03:29,270 --> 00:03:32,010
J w secret part.

48
00:03:32,130 --> 00:03:41,300
Let me grab the comment that I left here just for demo in production use long, complex and guessable

49
00:03:41,450 --> 00:03:42,350
string value.

50
00:03:42,680 --> 00:03:47,020
And when it comes to more complex projects, I'll show you how we can create one.

51
00:03:47,300 --> 00:03:55,190
So let me just take this one out and I think I'll just leave that in the control order right below the

52
00:03:55,190 --> 00:03:55,670
payload.

53
00:03:55,670 --> 00:04:02,570
Small comment where again, you always, always, when it comes to production, why have them long,

54
00:04:02,570 --> 00:04:04,280
complex and guessable?

55
00:04:04,670 --> 00:04:05,420
In this case?

56
00:04:05,420 --> 00:04:08,200
We're just cheating because I don't want to bother with that.

57
00:04:08,210 --> 00:04:11,360
So we go with variable and then some kind of value.

58
00:04:11,540 --> 00:04:17,300
And now, of course, we just need to go back to the controller here and remember, we can access it

59
00:04:17,480 --> 00:04:19,720
with process data envy.

60
00:04:19,970 --> 00:04:26,660
And then more specifically, we're looking for JWT and underscore secret.

61
00:04:27,080 --> 00:04:34,460
And if you're confused or just wondering why we're so fussy about this JWT secret strength, if you

62
00:04:34,460 --> 00:04:41,120
recall the JSON Web tokens structure video, this is the secret that is used to sign our tokens and

63
00:04:41,120 --> 00:04:47,690
therefore it's a good practice to only keep it on a server and make it more complex than our current

64
00:04:47,960 --> 00:04:49,300
JWT secret.

65
00:04:49,860 --> 00:04:56,240
Just keep in mind that if someone gets a hold of your key, they can start signing tokens on your behalf.

66
00:04:56,570 --> 00:04:58,720
And that's definitely not the spot you want to be in.

67
00:04:59,210 --> 00:05:04,820
As you can say, even in undocks, they suggest your 256 bit secret.

68
00:05:05,150 --> 00:05:10,400
And like I already mentioned in the following project, I'll show you where and how we can set up a

69
00:05:10,400 --> 00:05:12,830
proper secret value in real time.

70
00:05:13,160 --> 00:05:16,790
And then the last thing we want to provide is options.

71
00:05:17,060 --> 00:05:22,430
And we're going to go with expires in option and set it equal to thirty days.

72
00:05:22,910 --> 00:05:27,650
And I'll come back and talk about the expressions and all that a little bit later.

73
00:05:27,980 --> 00:05:35,120
So once we have a token now, of course we want to change our response where instead of the string we're

74
00:05:35,120 --> 00:05:37,010
going to go with actual status.

75
00:05:37,340 --> 00:05:38,540
So set it up over here.

76
00:05:38,540 --> 00:05:39,170
Two hundred.

77
00:05:40,090 --> 00:05:46,390
Than that, and of course, we're going to be looking for the judge on here and then let's just add

78
00:05:46,480 --> 00:05:51,400
here a message and say user created, user created.

79
00:05:51,400 --> 00:05:55,070
And this is the case where the front end is using that message.

80
00:05:55,510 --> 00:05:58,450
So I strongly suggest keeping it the same way.

81
00:05:58,720 --> 00:06:01,170
And then we'll go with Token.

82
00:06:01,510 --> 00:06:07,000
So effectively we have our token and now we just want to send back to the user.

83
00:06:07,330 --> 00:06:11,140
So once we save, we're going to go back to the login one.

84
00:06:11,380 --> 00:06:15,940
And in this case, I'll try one more time providing empty values.

85
00:06:16,180 --> 00:06:19,570
And of course, in that case, I get back my error one.

86
00:06:19,810 --> 00:06:28,000
But if I go here and if I said John and secret, I should get back my Jason.

87
00:06:28,000 --> 00:06:29,980
We're talking and of course I do.

88
00:06:30,260 --> 00:06:33,160
And it's really cool if you take this value.

89
00:06:34,010 --> 00:06:40,550
And just head back to the website and just copy and paste, what do you know, of course, now I have

90
00:06:40,700 --> 00:06:46,130
a username, some kind of fake ID, and this is going to be the expression.

91
00:06:46,430 --> 00:06:50,990
So as you can see, this is the payload that we're sending.

