1
00:00:00,330 --> 00:00:06,480
And as far as the syntax for hashing the password goes, something like this more first, we want to

2
00:00:06,480 --> 00:00:11,480
import the library, of course, and we're looking for the McRib jars again.

3
00:00:11,490 --> 00:00:19,530
Please keep in mind that Laburnum be creped Jass, don't install the beaker one and then wonder why

4
00:00:19,530 --> 00:00:20,240
you have bugs.

5
00:00:20,580 --> 00:00:23,930
So again, the name of the libraries be courageous.

6
00:00:23,940 --> 00:00:29,100
And the only reason why I'm telling you not because I fully understand that it's very easy to mix them

7
00:00:29,100 --> 00:00:29,280
up.

8
00:00:29,700 --> 00:00:36,870
And once we have access to the library, instead of dumping the entire body with our name, email and

9
00:00:36,870 --> 00:00:41,420
password, we want to create a new temporary user object.

10
00:00:41,760 --> 00:00:45,180
And in here I'll just pull out the values from the body.

11
00:00:45,180 --> 00:00:45,990
So my apologies.

12
00:00:46,020 --> 00:00:52,200
We already have this code, but I removed it with a bad request, so now I'll have to retype it one

13
00:00:52,200 --> 00:00:52,590
more time.

14
00:00:52,590 --> 00:00:55,980
So we'll look for name, email and password.

15
00:00:56,250 --> 00:01:03,720
And all of that is coming from Barack Dogberry and that I want to set up the stamp user object.

16
00:01:03,960 --> 00:01:10,530
And of course, keep in mind that in the temp user, all three properties need to be there, otherwise

17
00:01:10,530 --> 00:01:11,560
we'll get back there.

18
00:01:11,700 --> 00:01:14,490
So, of course, in here, I'm passing that by now.

19
00:01:14,490 --> 00:01:20,130
I want to set up a new object and you'll see why I'm telling you that in a second.

20
00:01:20,520 --> 00:01:27,030
And effectively, I first want to set up the password and then I'll go over line by line and explain

21
00:01:27,270 --> 00:01:28,170
what's happening.

22
00:01:28,350 --> 00:01:35,170
So let's start over here with const temp user and we'll use the sixth thing where I'll go.

23
00:01:35,200 --> 00:01:38,190
The name is equal to name and emails, equal to email.

24
00:01:38,220 --> 00:01:42,060
And what I want to do here is set up also a password.

25
00:01:42,360 --> 00:01:49,230
But password will be equal to a hash password, which of course the moment we don't have and not set

26
00:01:49,230 --> 00:01:57,270
up the hash password, we need to run through methods we need to run gentled and then the actual hash

27
00:01:57,270 --> 00:01:57,750
method.

28
00:01:58,110 --> 00:02:04,500
And first I want to create a variable and I'll say, Sult, we have an option of running them asynchronously.

29
00:02:04,710 --> 00:02:07,350
So I'll just go with a weight that I'm looking for.

30
00:02:07,350 --> 00:02:15,110
Decrypt and like I said, the method name is Jan Salt and then we want to pass in the number of value.

31
00:02:15,840 --> 00:02:19,440
Again, I'll explain all of this in great detail in a second.

32
00:02:19,830 --> 00:02:24,110
And then once we have the salt, then we want to create that hashed password.

33
00:02:24,390 --> 00:02:33,090
So let's say over here, Hashd and Password and we'll go with a white van Beek crypt again, decrypt.

34
00:02:33,420 --> 00:02:35,970
And the method name in this case is Hash.

35
00:02:36,330 --> 00:02:42,750
And we need to pass them through things we want to pass in the password we want to hash as well as the

36
00:02:42,750 --> 00:02:45,630
random bytes, which essentially is that's old.

37
00:02:45,870 --> 00:02:48,870
So let's start over here with password, the line comma.

38
00:02:49,050 --> 00:02:56,250
Then we pass in the salt and now where we have the password in the temp user, instead of directly using

39
00:02:56,250 --> 00:02:59,130
the password, we'll go with hash password.

40
00:02:59,310 --> 00:03:04,800
And now, of course, instead of dumping the entire body, we'll go with that again.

41
00:03:04,800 --> 00:03:08,520
We want to spread them out and then we'll go with the user.

42
00:03:08,790 --> 00:03:16,320
And once we save all of this, I'll hop over to the postman and let's try to send the request.

43
00:03:16,890 --> 00:03:23,430
So in here, we need to keep in mind here things first, the fact that we have set up for unique emails.

44
00:03:23,790 --> 00:03:29,610
So if we'll try to send the same email, we'll get the error response.

45
00:03:29,850 --> 00:03:30,650
That's number one.

46
00:03:30,650 --> 00:03:36,390
And number two, remember, when we're setting up the password, the basic password, we also add the

47
00:03:36,390 --> 00:03:40,320
max length since I wanted to showcase that, we have that folder.

48
00:03:40,560 --> 00:03:46,560
Now, in this case, of course, we will get an error because the hash value is going to be way longer

49
00:03:46,680 --> 00:03:47,580
than 12.

50
00:03:47,850 --> 00:03:48,810
So let's try it out.

51
00:03:48,810 --> 00:03:49,890
Let's send it.

52
00:03:50,010 --> 00:03:55,140
And like I said, we will get an error where the max length is twelve.

53
00:03:55,140 --> 00:03:58,830
And of course, this is the hashed password value.

54
00:03:59,160 --> 00:04:05,340
And in order to fix that, of course, we just need to go to our user model and then remove the max

55
00:04:05,340 --> 00:04:05,730
length.

56
00:04:05,740 --> 00:04:11,310
Like I said, I added this just so I can see that we have this option, or of course, in our case,

57
00:04:11,550 --> 00:04:13,110
we are not going to use it.

58
00:04:13,470 --> 00:04:18,899
And then once I fix that, then the another bug is going to be that we have a unique email.

59
00:04:19,170 --> 00:04:26,010
So if I send with John a Gmail account, of course I'm going to get an error, which pretty much tells

60
00:04:26,010 --> 00:04:28,500
me that I have manual error.

61
00:04:28,830 --> 00:04:32,430
And more specifically, there is an issue with an email.

62
00:04:32,580 --> 00:04:37,990
And this is the case where, again, we'll work on the custom error messages in a second.

63
00:04:38,250 --> 00:04:44,580
Now, we simply want to change the John to John one at Gmail dot com.

64
00:04:44,820 --> 00:04:50,190
And once I send check it out now, of course, I'm getting back to user now.

65
00:04:50,310 --> 00:04:53,310
It's still not a good idea to send back the password.

66
00:04:53,460 --> 00:04:56,630
So that's also something that I will work on a little bit later.

67
00:04:56,940 --> 00:04:59,460
Now, the good news is that if we navigate.

68
00:04:59,460 --> 00:04:59,660
Right.

69
00:04:59,820 --> 00:05:08,430
Out to our Mongo DB, and if we take a look, you'll see our second user with a email of John one.

70
00:05:08,680 --> 00:05:11,640
And of course now the password is passion.

71
00:05:12,120 --> 00:05:18,210
And what that means is that even if someone breaks into our database and steals all the data instead

72
00:05:18,210 --> 00:05:25,020
of actual passwords, they'll get the hashed ones, which prevents them from easily reusing them later.

73
00:05:25,590 --> 00:05:28,300
Now, that doesn't mean that you shouldn't protect your database.

74
00:05:28,650 --> 00:05:29,260
Of course not.

75
00:05:29,280 --> 00:05:30,330
That's not what I'm saying.

76
00:05:30,570 --> 00:05:37,950
Just make sure that you always, always ask your passwords and never, ever, ever stored them as strings.

77
00:05:38,310 --> 00:05:46,410
And as far as the code, if we take a look at all Jass in line nine, we generate Sult, which essentially

78
00:05:46,410 --> 00:05:48,630
just means random bytes.

79
00:05:48,900 --> 00:05:52,500
And we do that by running the method gem salt.

80
00:05:52,830 --> 00:05:55,550
And in there we provide a number of rounds.

81
00:05:55,890 --> 00:05:58,880
So how many random bytes will get?

82
00:05:59,220 --> 00:06:02,860
And of course the bigger the number, the more random bytes will get.

83
00:06:03,120 --> 00:06:08,370
And of course that also means that the more secure our password is going to be.

84
00:06:08,680 --> 00:06:14,840
But we also need to keep in mind the more rounds you have, the more processing power is going to require.

85
00:06:15,150 --> 00:06:19,400
And therefore, I just went with 10, which I believe is a default one.

86
00:06:19,620 --> 00:06:24,710
And trust me, that is already a very, very secure password.

87
00:06:25,050 --> 00:06:32,340
And then, of course, we take that salt so those random bites and we pass in the hash and hash method

88
00:06:32,340 --> 00:06:34,880
is simply looking for the password.

89
00:06:35,010 --> 00:06:37,930
So the password we want to hash as well as the salt.

90
00:06:38,190 --> 00:06:44,460
And once we provide both those values, as a result, we get back that hashed password and of course,

91
00:06:44,460 --> 00:06:48,150
that one we can safely store in our database.

92
00:06:48,180 --> 00:06:51,150
So we're just added to our user and we're good to go.

