1
00:00:00,390 --> 00:00:00,790
Beautiful.

2
00:00:01,200 --> 00:00:07,700
And in order to get to this valley, just have to do a little bit of JavaScript magic and also have

3
00:00:07,710 --> 00:00:12,400
to throw a few of the errors if the values are not provided.

4
00:00:12,870 --> 00:00:19,940
So in Dashboard, first, I want to assign that authorization HAUETER to some kind of variable and case.

5
00:00:19,950 --> 00:00:24,000
I'm going to go with all header and then I'm looking for a request.

6
00:00:24,540 --> 00:00:29,650
And then of course headers like I said, and line we're looking for the authorization one.

7
00:00:30,150 --> 00:00:37,410
So once I have access to the header, then I want to check whether it actually exists because maybe

8
00:00:37,750 --> 00:00:41,910
user is sending a request without the header altogether.

9
00:00:42,180 --> 00:00:50,430
And if it exists, whether it starts with a bear and then the space, then this is very, very important

10
00:00:50,670 --> 00:00:56,370
that the syntax is exact because if it's not going to be exact, then of course all of this loses the

11
00:00:56,370 --> 00:00:56,720
meaning.

12
00:00:56,820 --> 00:01:06,600
So let's say here if I'm off header, so if it doesn't exist or the author and starts with, that's

13
00:01:06,600 --> 00:01:09,630
the method that we can use on JavaScript strings.

14
00:01:09,990 --> 00:01:17,170
And here I just want to say, if it doesn't start with the bear, then of course we'll throw the error.

15
00:01:17,670 --> 00:01:25,710
So if there is no authorization header or it doesn't start with barer, then of course we'll throw our

16
00:01:25,890 --> 00:01:26,900
custom error.

17
00:01:27,450 --> 00:01:30,990
So I'll just add here BRX and then the space.

18
00:01:31,440 --> 00:01:38,280
Now, if that is the case, what we can do well, we can throw our own custom error and not speed this

19
00:01:38,280 --> 00:01:38,490
up.

20
00:01:38,730 --> 00:01:44,250
I'm just going to copy and paste we're throwing there and normally you're going to be way, more way

21
00:01:44,250 --> 00:01:44,760
than this.

22
00:01:45,060 --> 00:01:52,290
But in this case, since we're of course, just testing the WTS, I'll say here now, Tolkan provided

23
00:01:52,560 --> 00:01:57,600
in that case, if you hit some kind of roadblock, at least you know where the error is coming from.

24
00:01:57,600 --> 00:02:03,240
And when it comes to text, normally it's going to be along the lines of invalid credentials to access

25
00:02:03,240 --> 00:02:03,780
the throughout.

26
00:02:04,140 --> 00:02:10,190
And as far as the status code instead of four hundred, it's going to be a moral one.

27
00:02:10,350 --> 00:02:13,260
So that is not a bad request.

28
00:02:13,480 --> 00:02:16,040
That is actually the authentication error.

29
00:02:16,260 --> 00:02:21,420
But again, in this case, just to make it easier, if you need to debug, I'm going to go with no token

30
00:02:21,420 --> 00:02:26,970
provided line as far as the error, we're going to go with four hundred and one.

31
00:02:27,300 --> 00:02:31,780
And of course, in order to test that out, why don't we go back and line?

32
00:02:31,800 --> 00:02:37,290
I'm just going to uncheck the authorization just so we can actually see what we get back.

33
00:02:37,530 --> 00:02:39,600
And once we click, check it out.

34
00:02:39,880 --> 00:02:43,790
Now we have a message no token provided and what is there?

35
00:02:44,130 --> 00:02:46,370
Of course error is four hundred and one.

36
00:02:46,770 --> 00:02:53,660
Now, if I go back to the authorization letter and if I send now, I can see something went wrong.

37
00:02:54,060 --> 00:02:55,410
Try again later.

38
00:02:55,600 --> 00:02:55,880
Hmm.

39
00:02:56,100 --> 00:02:56,940
That's interesting.

40
00:02:57,210 --> 00:03:02,820
I double check my code and yes, of course it starts with not start with.

41
00:03:03,210 --> 00:03:04,650
Let me try one more time.

42
00:03:05,340 --> 00:03:07,140
Let's send and there you go.

43
00:03:07,260 --> 00:03:08,390
Now of course we have hello.

44
00:03:08,400 --> 00:03:10,860
John Doe and of course the secret as well.

45
00:03:11,070 --> 00:03:16,770
And once we have passed the first stage now I just want to get that token and we can access it in a

46
00:03:16,770 --> 00:03:17,460
falling way.

47
00:03:17,730 --> 00:03:23,670
Where I'm going to go with constuction is equal to auth header and then we want to split it again.

48
00:03:23,670 --> 00:03:28,980
This is a string, so we split it on a space and we're looking for the second value.

49
00:03:29,460 --> 00:03:36,480
And if you want to double check, let's go with Token and let's come to log it just so we are on the

50
00:03:36,480 --> 00:03:37,080
same page.

51
00:03:37,290 --> 00:03:38,580
So let's send one more time.

52
00:03:38,580 --> 00:03:40,860
And as I know, there's a tiny mark there as well.

53
00:03:41,220 --> 00:03:45,390
And you should see in the console a token.

54
00:03:45,900 --> 00:03:50,550
And I'm also going to fix it over here when I want to say your lucky number.

55
00:03:51,060 --> 00:03:56,790
And once we have all of this in place now, of course, we just need to set up the verification where,

56
00:03:56,820 --> 00:04:00,420
yes, we got back the token from the front end.

57
00:04:00,630 --> 00:04:05,730
However, now we want to verify whether the token is actually valid.

