1
00:00:00,300 --> 00:00:07,020
And once we have discussed in theory how we can send back the token, let's try doing that in the post,

2
00:00:07,020 --> 00:00:15,000
man, so we're the logging every time I send a successful request, meaning where the username and password

3
00:00:15,330 --> 00:00:20,810
are valid values instead of empty strings, then of course, we're getting back the token.

4
00:00:21,240 --> 00:00:26,580
And of course, all this time I'm creating what John would just understand that every time we're getting

5
00:00:26,580 --> 00:00:29,910
that unique token and what we want to do.

6
00:00:30,840 --> 00:00:36,240
Take this token, copy this one, and, of course, don't worry, later we'll set it up with different

7
00:00:36,240 --> 00:00:39,390
usernames the moment there's really no need for that.

8
00:00:39,720 --> 00:00:41,820
And then back in the dashboard.

9
00:00:42,180 --> 00:00:45,840
So in our guest request, we're not looking for the body.

10
00:00:46,170 --> 00:00:47,870
We're looking for letters.

11
00:00:48,210 --> 00:00:53,460
And in the following projects, I'll show you how we can do that dynamically, in part because, of

12
00:00:53,460 --> 00:00:57,720
course, when it comes to bigger project is going to get annoying really fast.

13
00:00:58,070 --> 00:01:02,910
You'll have to all the time copy and paste those tokens just to test something out.

14
00:01:03,220 --> 00:01:05,700
But in this project, yes, we'll do this manually.

15
00:01:05,940 --> 00:01:09,810
So, again, we are in the dashboard, not throughout.

16
00:01:09,960 --> 00:01:11,310
Of course it is getting all that.

17
00:01:11,550 --> 00:01:17,340
And then we're looking for headers and their name is going to be the authorization one.

18
00:01:17,730 --> 00:01:20,460
Then we want to set it equal to Barer.

19
00:01:21,000 --> 00:01:21,810
That's the name.

20
00:01:21,940 --> 00:01:28,470
And you have to follow this to the tee so better and then copy and paste the token.

21
00:01:28,560 --> 00:01:31,830
So now of course if we send yeah.

22
00:01:31,830 --> 00:01:34,290
We get the value, blah, blah, blah, we have the number.

23
00:01:34,530 --> 00:01:40,830
But what's more interesting, if we go back to the dashboard and if you log request headers, you'll

24
00:01:40,830 --> 00:01:45,930
see something really cool where if I go with a request, like I said, headers.

25
00:01:46,440 --> 00:01:48,030
Now let me send one more time.

26
00:01:48,060 --> 00:01:49,890
Again, the token is still valid.

27
00:01:50,160 --> 00:01:52,590
We have 30 days, so everything is going to work.

28
00:01:52,800 --> 00:01:54,930
If I scroll up, check it out.

29
00:01:54,930 --> 00:01:57,270
We have authorization hattar.

30
00:01:57,630 --> 00:02:04,050
And then of course I have the bearer and this is the value and this is what we'll do in the following

31
00:02:04,050 --> 00:02:04,530
videos.

32
00:02:04,860 --> 00:02:08,880
We'll extract this and actually validate.

33
00:02:09,000 --> 00:02:13,350
And if it is valid, only then we'll send back the data.

34
00:02:13,560 --> 00:02:15,540
We are the actual user name.

35
00:02:15,870 --> 00:02:21,510
The moment, of course we just have John Doe, but eventually we'll set up where whatever user name

36
00:02:21,720 --> 00:02:23,340
gets sent back to the front end.

37
00:02:23,640 --> 00:02:31,470
Well, that one will send back here because that will showcase that we only access the specific resources

38
00:02:31,650 --> 00:02:34,690
that the user has, not just some random ones.

