1
00:00:00,360 --> 00:00:00,760
Beautiful.

2
00:00:01,170 --> 00:00:08,010
We now know how to hash user passwords, and if we take a look at our registered user steps, essentially

3
00:00:08,010 --> 00:00:13,980
we just need to generate a token which should sound already familiar since we spend the entire project

4
00:00:13,980 --> 00:00:14,370
on that.

5
00:00:14,790 --> 00:00:16,620
And we'll be good to go, right?

6
00:00:17,010 --> 00:00:18,630
Well, yes and no.

7
00:00:18,960 --> 00:00:19,790
That's true.

8
00:00:19,950 --> 00:00:21,570
We don't have much left.

9
00:00:21,990 --> 00:00:26,510
But if we take a look at our controller, it's getting somewhat busy.

10
00:00:26,880 --> 00:00:33,930
So if we'll keep on adding more functionality and just keep jamming the code in the controller, eventually

11
00:00:33,930 --> 00:00:36,760
it's going to get bloated and way hard to manage.

12
00:00:37,140 --> 00:00:38,860
Now, what's the solution, you might ask?

13
00:00:39,210 --> 00:00:44,880
Well, another set of middleware only in this case we're talking about the mongoose middleware.

14
00:00:45,330 --> 00:00:47,130
But just keep one thing in mind.

15
00:00:47,460 --> 00:00:50,940
The end result is going to be exactly the same.

16
00:00:51,300 --> 00:00:57,920
We'll still hash users passwords is just the logic will be stored nicely in a separate place.

17
00:00:58,350 --> 00:01:03,090
And since I want to show you the entire documentation, I'm going to navigate back.

18
00:01:03,330 --> 00:01:07,650
We're looking for a middleware and of course, you can read, yada, yada, yada.

19
00:01:07,650 --> 00:01:08,880
We have pre and post.

20
00:01:08,880 --> 00:01:10,830
So before and after hooks.

21
00:01:11,190 --> 00:01:16,740
And essentially we're looking for pre and more specifically, pre save.

22
00:01:17,040 --> 00:01:21,990
And the way we set it up, we have the scheme in our case, of course, that is going to be our user

23
00:01:21,990 --> 00:01:22,350
schema.

24
00:01:22,680 --> 00:01:24,460
Then we go with pre.

25
00:01:24,540 --> 00:01:27,800
So that's the syntax and we're looking for save.

26
00:01:28,260 --> 00:01:36,870
So before we save the document and that in the callback function, this is where we can access the properties

27
00:01:36,870 --> 00:01:39,270
in a document and do some exciting stuff.

28
00:01:39,660 --> 00:01:46,680
And of course, since this is a middleware, then we just go with next and once we're done we pass it

29
00:01:46,680 --> 00:01:48,010
on to the next middleware.

30
00:01:48,270 --> 00:01:50,460
Now, also Shergar with async awaits.

31
00:01:50,460 --> 00:01:52,020
So this is coming up.

32
00:01:52,020 --> 00:01:55,650
First, let's just focus on this next one over here.

33
00:01:56,010 --> 00:01:59,430
And essentially what we want to do is take the B script.

34
00:01:59,850 --> 00:02:04,500
We'll just save a little bit of time and we will go to our models.

35
00:02:04,830 --> 00:02:06,780
We're looking for use and one, of course.

36
00:02:07,140 --> 00:02:09,000
And then here, let's copy and paste.

37
00:02:09,000 --> 00:02:10,199
We have the script.

38
00:02:10,530 --> 00:02:11,730
Let's keep on scrolling.

39
00:02:11,730 --> 00:02:13,080
OK, that's our setup.

40
00:02:13,410 --> 00:02:16,630
And here this is where we want to go with our schema.

41
00:02:16,650 --> 00:02:20,550
So before we set up the model, we'll go with user schema.

42
00:02:20,650 --> 00:02:21,690
That's the name, of course.

43
00:02:21,990 --> 00:02:25,020
Then we're looking for pre and then save.

44
00:02:25,230 --> 00:02:26,010
So precise.

45
00:02:26,370 --> 00:02:32,760
And since we'll use a wait right away, set it up as a sink and then let's go with function.

46
00:02:33,120 --> 00:02:41,100
And I highly, highly, highly suggest using the good old function keyword value because that way this

47
00:02:41,100 --> 00:02:43,310
will be scoped to our document.

48
00:02:43,680 --> 00:02:49,410
So if you'll go with our functions, if you're familiar with them, you know that as far as coping with

49
00:02:49,650 --> 00:02:55,350
a very different set of rules in this case, if we use the good old function, that's why you'll see

50
00:02:55,350 --> 00:02:56,580
that in a box as well.

51
00:02:57,100 --> 00:03:00,260
This will always point to our document.

52
00:03:00,480 --> 00:03:02,370
So let's go with our function.

53
00:03:03,150 --> 00:03:06,870
And it is a nice let's pass in the next, of course.

54
00:03:07,230 --> 00:03:09,050
And then remember the functionality.

55
00:03:09,270 --> 00:03:10,660
What are we looking for over here?

56
00:03:11,070 --> 00:03:13,770
Well, I want to generate the salt.

57
00:03:14,100 --> 00:03:14,550
Correct.

58
00:03:14,820 --> 00:03:17,280
And of course, I want to get the password.

59
00:03:17,880 --> 00:03:21,300
And just so we get comfortable, let's write it from the scratch.

60
00:03:21,600 --> 00:03:23,040
So let's go to the user one.

61
00:03:23,460 --> 00:03:26,140
And essentially I want to go with const salts.

62
00:03:26,140 --> 00:03:28,200
So now we're generating those random bytes.

63
00:03:28,200 --> 00:03:32,340
So let's just go over here with a wait and then be creped.

64
00:03:32,610 --> 00:03:37,890
And of course the function name was InGen Salt and I'm not going to go twenty rounds, I'm going to

65
00:03:37,890 --> 00:03:38,910
go with ten here.

66
00:03:39,390 --> 00:03:46,110
And as far as the password, well this is where the callback function comes into play, where in this

67
00:03:46,110 --> 00:03:49,110
function this will point to the document.

68
00:03:49,470 --> 00:03:54,990
So when we type this over here, basically what we're talking about is our document before I want to

69
00:03:54,990 --> 00:03:59,430
save document, what do we want to accomplish while we want to hash the password?

70
00:03:59,430 --> 00:03:59,770
Correct.

71
00:04:00,150 --> 00:04:03,990
So what we can do, we can go with this dot and we're looking for password.

72
00:04:04,370 --> 00:04:10,270
Of course, this is over here and we simply want to go with a wait and we want to hash it.

73
00:04:10,440 --> 00:04:13,440
We want to go with a weight, then be corrupt.

74
00:04:13,650 --> 00:04:20,820
And then, of course, the method name is hash and then we're looking for that password.

75
00:04:20,820 --> 00:04:26,800
So our current password for saving and line, we pass insult and that's it.

76
00:04:26,910 --> 00:04:28,020
That's all we have to do.

77
00:04:28,350 --> 00:04:31,010
And once we're done with the functionality, what's left?

78
00:04:31,020 --> 00:04:33,870
Well, we want to pass it on to the next middleware.

79
00:04:34,140 --> 00:04:37,200
So we just go with next and we invoke it.

80
00:04:37,440 --> 00:04:38,400
And now check it out.

81
00:04:38,760 --> 00:04:44,730
If we take a look at our controller, since we're not sending the bad request here anyway, I don't

82
00:04:44,730 --> 00:04:47,070
really need all these lines of code.

83
00:04:47,520 --> 00:04:48,020
That's it.

84
00:04:48,270 --> 00:04:55,140
I simply want to take my body just like we had before with dot, dot, dot, dot, dot, body and everything

85
00:04:55,140 --> 00:04:57,570
else is taken care of over here.

86
00:04:57,840 --> 00:04:59,400
And you have to agree that.

87
00:04:59,820 --> 00:05:04,290
This is much cleaner and nicer to work with, so let's go back.

88
00:05:05,130 --> 00:05:12,070
And then, like I said, I'm not interested in any of these things over here, and we'll simply go down

89
00:05:12,130 --> 00:05:18,060
that that that body, I'm still sending the user just because I want to showcase that will be hacking

90
00:05:18,060 --> 00:05:18,560
the password.

91
00:05:18,570 --> 00:05:22,380
But don't worry, that's also not a good practice to send back the password.

92
00:05:22,380 --> 00:05:25,400
So we won't do that in a few seconds.

93
00:05:25,620 --> 00:05:27,660
So let's go back to our postman.

94
00:05:28,170 --> 00:05:31,220
We want to send it and check it out.

95
00:05:31,230 --> 00:05:33,260
We have John Rejon, blah, blah, blah.

96
00:05:33,450 --> 00:05:35,910
And of course, we have our highest value.

97
00:05:36,060 --> 00:05:37,700
So functionality still works.

98
00:05:37,980 --> 00:05:40,060
And the last thing that I want to cover in this video.

99
00:05:40,320 --> 00:05:44,090
Notice the ducks in Mongo's 5.0, blah, blah, blah.

100
00:05:44,100 --> 00:05:51,060
Next, we can go with a single point, one that simply means that back in our user, one can just remove

101
00:05:51,060 --> 00:05:51,270
it.

102
00:05:51,840 --> 00:05:55,560
And what they're telling us in the is that it's still going to work.

103
00:05:55,570 --> 00:05:57,330
So it's the set out in this case.

104
00:05:57,330 --> 00:06:01,740
I'm going to go with John, too, since remember, we have those unique emails.

105
00:06:02,010 --> 00:06:03,150
Let's send it.

106
00:06:03,420 --> 00:06:05,100
And we still get the response.

107
00:06:05,370 --> 00:06:06,690
So we know that that works.

108
00:06:06,990 --> 00:06:13,020
And if I go to my database now, of course, I should have quite a few users already there.

109
00:06:13,420 --> 00:06:18,660
We have hashed passwords apart from the first one was that is where the secret is.

110
00:06:18,990 --> 00:06:22,740
And now I can remove it and we are good to go now.

111
00:06:22,740 --> 00:06:27,630
We can hash the password, but we're doing that using the Mongo's middleware.

