1
00:00:00,330 --> 00:00:01,200
Not bad, not bad.

2
00:00:01,240 --> 00:00:07,860
We can register a user, we can almost log in, and the reason why I say almost because of course moment,

3
00:00:07,860 --> 00:00:12,660
as long as there's some kind of value for the password, we're actually sending back the token.

4
00:00:12,960 --> 00:00:14,060
So now let's fix that.

5
00:00:14,310 --> 00:00:16,890
Let's actually compare the password.

6
00:00:17,220 --> 00:00:21,500
And this is that interesting thing where you might be like, OK, but wait a minute.

7
00:00:21,900 --> 00:00:26,280
Back when we were registering because we were hashing this password, correct.

8
00:00:26,580 --> 00:00:28,740
We want to gentled and then hash.

9
00:00:29,040 --> 00:00:34,950
And the deal is following where essentially we have our library, we have the package decryption.

10
00:00:35,310 --> 00:00:44,790
And in the bigger package, of course, there is a function by the name of COMPAR and it compares the

11
00:00:44,790 --> 00:00:45,720
hashed passwords.

12
00:00:45,750 --> 00:00:48,030
So again, it's a one way street.

13
00:00:48,390 --> 00:00:50,640
Once we hash the password, that's it.

14
00:00:51,090 --> 00:00:57,780
But with COMPAR method, we compare those hashed passwords and of course if they match awesome, we

15
00:00:57,780 --> 00:01:01,740
send back the token and user has successfully logged in.

16
00:01:02,040 --> 00:01:06,540
And of course, keep in mind that we can set up this functionality right over here.

17
00:01:06,690 --> 00:01:12,050
But why we wouldn't want to do that if we already know how to set up the instance method.

18
00:01:12,220 --> 00:01:19,520
So instead of jamming more code in the login controller, we'll simply go here and I'll say user schema.

19
00:01:20,250 --> 00:01:22,500
And of course, we need to go with methods.

20
00:01:22,830 --> 00:01:28,290
And as far as the name, I'm going to go with check password or compar password.

21
00:01:28,410 --> 00:01:30,110
Again, naming is really up to you.

22
00:01:30,540 --> 00:01:36,600
In my case, I'm going to go maybe would compare password sounds a little bit more sophisticated and

23
00:01:36,630 --> 00:01:42,150
this is going to be a sync function and the function is going to be looking for one argument.

24
00:01:42,420 --> 00:01:47,100
And that of course, is going to be the password that's coming with a request.

25
00:01:47,430 --> 00:01:50,220
And I'm just going to name this one candidate password.

26
00:01:51,700 --> 00:01:58,260
And password and that as far as the functioning body, I want to come up with some kind of variable

27
00:01:58,270 --> 00:02:05,440
and like I said, we'll call this is a match and we'll set it equal to await weight because we can run

28
00:02:05,440 --> 00:02:09,289
the compare method asynchronously and say, oh, wait.

29
00:02:09,580 --> 00:02:11,380
Can the package name is be corrupt?

30
00:02:11,380 --> 00:02:11,790
Of course.

31
00:02:12,100 --> 00:02:19,870
And then the method name is Compar and then in the compare will pass in two things will pass in the

32
00:02:19,870 --> 00:02:20,590
password.

33
00:02:20,740 --> 00:02:27,610
So the candidate password, essentially the password that is coming in with a request and after the

34
00:02:27,610 --> 00:02:34,730
column of course will get the password from the document, of course the one that is already saved in

35
00:02:34,730 --> 00:02:35,350
the database.

36
00:02:35,680 --> 00:02:40,000
So let's go back to the compare and we'll just go with the candidate password.

37
00:02:40,240 --> 00:02:45,460
So again, the one that's coming in with the request and of course, in order to access the document

38
00:02:45,460 --> 00:02:49,660
password, we simply go with that and we provide the password.

39
00:02:49,960 --> 00:02:53,290
And then where we want to return from the function is the match.

40
00:02:53,320 --> 00:02:56,440
So say here, return and is match.

41
00:02:56,740 --> 00:03:02,280
And once we have the function in place now, we're simply want to go back to all jurors.

42
00:03:02,560 --> 00:03:09,370
And if we can see that we have the user, we also want to set up one more if statement where we'll check

43
00:03:09,370 --> 00:03:10,090
the password.

44
00:03:10,410 --> 00:03:16,510
So now, of course, I can move this comment down and I can say if there is a user, I also want to

45
00:03:16,510 --> 00:03:23,080
check whether the password matches and we can do that by going with const and then come up with some

46
00:03:23,080 --> 00:03:23,770
kind of variable.

47
00:03:24,070 --> 00:03:25,990
Is password correct.

48
00:03:26,320 --> 00:03:31,420
And of course, we need to go with a weight because our function is to synchronise, then we're looking

49
00:03:31,420 --> 00:03:32,700
for the user.

50
00:03:32,890 --> 00:03:38,350
So of course this only happens if we have a user, we don't have the user, then we right away send

51
00:03:38,350 --> 00:03:44,140
back invalid credentials and in here we'll go check or I'm sorry, compar password.

52
00:03:44,320 --> 00:03:46,270
Of course I went with sophisticated name.

53
00:03:46,550 --> 00:03:52,390
Then we pass in the password that we're getting from the user and now of course we want to do the same

54
00:03:52,390 --> 00:03:59,620
thing where we want to check if the password is correct, then of course we just return a token and

55
00:03:59,620 --> 00:04:00,030
all that.

56
00:04:00,310 --> 00:04:07,060
If not, then we'll throw the error and I'll just speed this up and copy and paste and we'll do the

57
00:04:07,060 --> 00:04:07,660
same thing.

58
00:04:08,080 --> 00:04:13,990
If the password is false, meaning if we get back is match as false.

59
00:04:14,290 --> 00:04:18,829
And of course we'll just throw this error and now it's going to start out in the postman.

60
00:04:19,149 --> 00:04:24,720
So at this point I have email as well as the password and they should be correct.

61
00:04:24,730 --> 00:04:25,660
So let's send it here.

62
00:04:25,900 --> 00:04:28,480
And of course I get back the response.

63
00:04:28,480 --> 00:04:35,830
But if I start messing with the values, for example, if I go with a wrong email now, of course I'll

64
00:04:35,830 --> 00:04:37,470
get involved credentials.

65
00:04:37,720 --> 00:04:43,870
So let's send it back to twenty three and then if we do the same thing with the password, we'll also

66
00:04:43,870 --> 00:04:45,610
get back the same message.

67
00:04:45,880 --> 00:04:48,850
So now this year we have this involved credentials.

68
00:04:49,060 --> 00:04:54,940
Now if I provide the correct values, the correct email as well as the password and of course everything

69
00:04:54,940 --> 00:04:57,050
is great and we get back to talking.

70
00:04:57,400 --> 00:05:03,160
Now lastly, you're probably wondering, OK, but why did you check over here right in the controller?

71
00:05:03,590 --> 00:05:08,440
Because technically, we need to understand that, yes, if there is no email, of course, we'll get

72
00:05:08,440 --> 00:05:09,460
that Mongo's error.

73
00:05:09,460 --> 00:05:09,820
Correct.

74
00:05:10,210 --> 00:05:13,570
Well, let me show you something, so I'll comment this one out.

75
00:05:13,900 --> 00:05:17,370
So basically now we're not checking for empty volumes.

76
00:05:17,770 --> 00:05:19,720
And let me provide a correct one.

77
00:05:19,750 --> 00:05:24,970
Let me say that, yeah, the correct email is going to be Peter 23 euro area.

78
00:05:25,300 --> 00:05:27,070
But I'll remove the password.

79
00:05:27,880 --> 00:05:31,690
And essentially, once I send, I get back this a response, but it is empty.

80
00:05:32,140 --> 00:05:34,420
So let's go over the reasons.

81
00:05:34,420 --> 00:05:35,320
Why is that happening?

82
00:05:35,650 --> 00:05:39,520
Well, if we take a look at the user, of course, we have to compare one.

83
00:05:39,880 --> 00:05:42,250
And this one will throw an error.

84
00:05:42,670 --> 00:05:46,900
It will throw an error because, of course, we're passing in the empty value, correct?

85
00:05:47,170 --> 00:05:47,740
Back in.

86
00:05:48,120 --> 00:05:48,420
Yes.

87
00:05:48,460 --> 00:05:49,900
We're getting back the password.

88
00:05:49,900 --> 00:05:57,850
But password is just empty string and we are getting the error and we are actually handling better in

89
00:05:57,850 --> 00:05:58,660
our error.

90
00:05:59,380 --> 00:06:01,390
So let's go back over here to our handler.

91
00:06:01,630 --> 00:06:03,250
We are handling it over here.

92
00:06:03,250 --> 00:06:08,260
And I can actually show guys that can go log and we can cancel log the error.

93
00:06:08,710 --> 00:06:11,860
And again, let me send one more time and console.

94
00:06:11,860 --> 00:06:12,970
You will see the error.

95
00:06:13,100 --> 00:06:18,760
And again, it is thrown by our library now this year, legal arguments on the fine.

96
00:06:18,940 --> 00:06:24,070
And I just find it easier to check it right over here or something.

97
00:06:24,070 --> 00:06:27,460
We'll learn later to set up a validation later.

98
00:06:27,580 --> 00:06:30,220
And again, that is all coming up for the time being.

99
00:06:30,520 --> 00:06:36,640
I just find it easier to check for that error right here for assumptive hours and then just send back

100
00:06:36,640 --> 00:06:39,760
the response instead of chasing it in our handler.

101
00:06:39,880 --> 00:06:41,350
And that's just my preference.

102
00:06:41,350 --> 00:06:44,440
Of course, if you don't like the setup, you don't have to use it.

103
00:06:44,740 --> 00:06:50,020
But that's my explanation for using this by request over here.

104
00:06:50,320 --> 00:06:51,190
Hopefully everything is.

105
00:06:51,470 --> 00:06:56,380
As far as the register and logging and now, of course, we can move on to our next step.

