1
00:00:00,300 --> 00:00:06,540
And as far as verification goes, something like this where if you take a look at the docks of the package,

2
00:00:06,870 --> 00:00:14,130
the Jets and we're talking one, you'll see that one of the options we have is using try catch and then

3
00:00:14,130 --> 00:00:16,110
we just need to come up with some kind of variable name.

4
00:00:16,110 --> 00:00:20,790
In my case, I'm going to go with Decoded, and that is equal to the package.

5
00:00:21,030 --> 00:00:27,000
So JWT now the method name is Verify and here we need to pass in Devourers.

6
00:00:27,330 --> 00:00:29,070
We need to pass in the token.

7
00:00:29,880 --> 00:00:33,550
And then the second value is that secret strength.

8
00:00:33,960 --> 00:00:40,250
So again, we go with our process data entry and the JWT.

9
00:00:40,260 --> 00:00:45,750
And if there's some kind of error, for example, the token might be expired.

10
00:00:46,050 --> 00:00:48,520
We'll handle that in the block.

11
00:00:48,930 --> 00:00:50,220
And what do we want to do?

12
00:00:50,250 --> 00:00:53,130
Well, we want to throw another custom error.

13
00:00:53,340 --> 00:00:59,000
And this is going to be the case where I'll show you that vague response where, again, we'll throw

14
00:00:59,010 --> 00:01:02,370
custom error if we're not able to verify the token.

15
00:01:02,730 --> 00:01:08,290
And as far as the response will say, not authorized to access this route, hopefully this is clear.

16
00:01:08,610 --> 00:01:11,930
So we try to verify if there's any kind of issue.

17
00:01:12,090 --> 00:01:15,200
We throw another custom error.

18
00:01:15,450 --> 00:01:18,470
And in this case, we go with not authorized to access the drought.

19
00:01:18,840 --> 00:01:24,990
And again, the code is still for one, because that is out of the question.

20
00:01:25,590 --> 00:01:31,650
And then, of course, if we're successful and we just keep on typing because all the data is going

21
00:01:31,650 --> 00:01:33,210
to be in this decoded.

22
00:01:33,450 --> 00:01:34,890
Now, what data, you might ask?

23
00:01:34,890 --> 00:01:38,430
Well, let's go with the control log and let's check it out together.

24
00:01:38,580 --> 00:01:40,170
So let's log one more time.

25
00:01:40,620 --> 00:01:41,970
Let's send it here.

26
00:01:42,480 --> 00:01:49,320
And now, of course, I can see that I get back my username as well as other two properties issued at

27
00:01:49,560 --> 00:01:51,150
an expiration.

28
00:01:51,330 --> 00:01:59,370
And of course, all of this is coming from our payload, the one that we passed over here when we signed

29
00:01:59,400 --> 00:02:00,180
the token.

30
00:02:00,400 --> 00:02:05,850
So, of course, you can imagine that if the name is going to be different for the user name, of course,

31
00:02:06,030 --> 00:02:10,030
this value will also change and by accessing that value.

32
00:02:10,229 --> 00:02:13,240
Now, of course, we can set up a dynamic response.

33
00:02:13,500 --> 00:02:14,750
So what do we do over here?

34
00:02:15,570 --> 00:02:19,290
We just say, OK, we have access to the decoded one.

35
00:02:19,620 --> 00:02:26,610
So let's take our code and just move it up, place it in the try block and line instead of just cancel

36
00:02:26,670 --> 00:02:27,110
logging.

37
00:02:27,450 --> 00:02:29,260
I'll keep the random one and all that.

38
00:02:29,280 --> 00:02:32,790
Don't worry, there's going to be a little bit different setup in a second anyway.

39
00:02:33,060 --> 00:02:36,960
But instead of John Doe, we'll go over here with Decoded.

40
00:02:37,320 --> 00:02:39,840
And what is the property that I'm looking for on the object?

41
00:02:40,080 --> 00:02:42,320
Of course, that is the user name.

42
00:02:42,330 --> 00:02:44,730
So we just go back over here to the user name.

43
00:02:45,000 --> 00:02:47,730
And if I navigate, get back to the postman.

44
00:02:47,940 --> 00:02:50,990
Now, of course, once I send, I'll get back to John.

45
00:02:51,270 --> 00:02:58,300
So let's go the steps in the postman first and then we'll try it out in the front and in our application.

46
00:02:58,530 --> 00:03:01,170
So first, let's go with login again.

47
00:03:01,170 --> 00:03:05,430
I'll try to login without providing the user name.

48
00:03:05,430 --> 00:03:10,440
For example, I send it over here now of course to have please provide email password.

49
00:03:10,680 --> 00:03:12,120
So that was that first check.

50
00:03:12,420 --> 00:03:19,050
So if we are successful here, if I provide Peter, then of course I'll get back my token.

51
00:03:19,480 --> 00:03:20,000
Awesome.

52
00:03:20,220 --> 00:03:27,390
And I can see that the user has been created and we want to go to the dashboard and where we have authorization

53
00:03:27,390 --> 00:03:27,800
header.

54
00:03:28,170 --> 00:03:34,050
Now I want to change this around where instead of this value, I got to just make sure there's that

55
00:03:34,050 --> 00:03:34,500
space.

56
00:03:34,780 --> 00:03:36,090
That's a big deal here.

57
00:03:36,330 --> 00:03:38,100
We'll provide this value instead.

58
00:03:38,490 --> 00:03:39,560
And of course, I have.

59
00:03:39,570 --> 00:03:40,410
Hello, Peter.

60
00:03:40,620 --> 00:03:43,470
And then again, some random lucky number.

61
00:03:43,770 --> 00:03:47,990
And if everything works in a postman, it should also work on the front end.

62
00:03:48,150 --> 00:03:49,500
So let's try it out over here.

63
00:03:49,740 --> 00:03:50,610
Let's refresh.

64
00:03:50,850 --> 00:03:56,670
Of course, we can see no tokens present and here I'll just try to get the token without providing devourers

65
00:03:56,670 --> 00:03:58,500
and of course, not successful.

66
00:03:59,010 --> 00:04:05,160
So I get back the error and therefore I'm going to go with honor and then again, some kind of dummy

67
00:04:05,160 --> 00:04:05,760
password.

68
00:04:05,910 --> 00:04:07,050
We send it now.

69
00:04:07,050 --> 00:04:07,890
We're successful.

70
00:04:08,190 --> 00:04:09,720
User has been created.

71
00:04:09,960 --> 00:04:12,300
Of course, I can see that token is present.

72
00:04:12,510 --> 00:04:16,450
Often times the token is going to be in local storage and of course it is.

73
00:04:16,500 --> 00:04:21,420
So now, of course, when we're making those following requests now the token is present.

74
00:04:21,750 --> 00:04:23,450
So we're successful now.

75
00:04:23,460 --> 00:04:26,550
We can clearly see our user name online.

76
00:04:26,550 --> 00:04:28,260
We're getting those around them.

77
00:04:28,890 --> 00:04:35,040
So all the following requests are going to be successful as long as we provide a token.

78
00:04:35,220 --> 00:04:42,180
And since Token is in the local storage, of course, we can always access when we make it and then

79
00:04:42,180 --> 00:04:44,700
we're good to go now if we remove it.

80
00:04:44,700 --> 00:04:51,780
And in this case, I just set up the functionality that if the user tries to get the token without providing

81
00:04:51,780 --> 00:04:56,730
devourers, then I just wipe out the token in the local storage.

82
00:04:56,730 --> 00:04:59,600
So if we go back, notice, it's actually empty now.

83
00:04:59,660 --> 00:05:04,660
Not saying that that's always going to be set up on a front end is just something that I used in this

84
00:05:04,660 --> 00:05:04,900
case.

85
00:05:05,200 --> 00:05:07,760
So now if we go back again, we don't have to talk.

86
00:05:07,770 --> 00:05:12,170
And so we get this not authorized to access this route.

