1
00:00:00,330 --> 00:00:06,780
All right, and once the logon and register are in place, as far as the last thing we need is off middleware,

2
00:00:07,090 --> 00:00:13,470
where we can verify the token and if everything is correct and get the user ready and pass it along

3
00:00:13,470 --> 00:00:17,400
to the job, right now, the functionality is going to be exactly the same.

4
00:00:17,400 --> 00:00:22,020
Like in the previous project, I might just use different variable names here and there.

5
00:00:22,440 --> 00:00:29,580
And to answer your question, yes, I'll purposely retype everything from scratch just because I find

6
00:00:29,590 --> 00:00:33,390
repetition to be very important aspect of learning.

7
00:00:33,720 --> 00:00:37,410
Now, if you don't agree with my opinion, essentially you have two options.

8
00:00:37,680 --> 00:00:42,150
You can just copy and paste the code from the previous project and I'll show you, of course, where

9
00:00:42,150 --> 00:00:49,410
you can get it in a second or make this a challenge and try to recreate everything from scratch yourself.

10
00:00:49,710 --> 00:00:55,200
And of course, if you get stuck, utilize the previous project code or this video lecture.

11
00:00:55,500 --> 00:00:57,660
And of course, the code that I'm talking about is this one.

12
00:00:58,170 --> 00:01:05,610
If you navigate the folder number five, the JWT basics one, and then more specifically, if you look

13
00:01:05,610 --> 00:01:10,330
in the middleware, of course, you'll find the middleware that we are about to set up.

14
00:01:10,710 --> 00:01:14,520
And of course, I'll close everything and I'll start from scratch.

15
00:01:14,820 --> 00:01:20,570
So I'm looking in a start looking for the middleware and I'm going to go for my authentication one.

16
00:01:21,000 --> 00:01:23,130
And first, let's start with imports.

17
00:01:23,250 --> 00:01:25,440
And essentially we're looking for the user first.

18
00:01:25,680 --> 00:01:26,850
So that's going to be our model.

19
00:01:26,860 --> 00:01:31,560
So it's going to require and I believe this was two levels up.

20
00:01:31,920 --> 00:01:36,470
So let me look in my models and of course, user.

21
00:01:36,480 --> 00:01:37,340
OK, that's good.

22
00:01:37,680 --> 00:01:41,630
Then I want to go with my JWT because of course we want to verify the token.

23
00:01:42,000 --> 00:01:43,050
So let's go over here.

24
00:01:43,050 --> 00:01:46,320
Would require and the package name is just a web token.

25
00:01:46,680 --> 00:01:53,580
And the last thing that I want is the unauthenticated error, which of course is coming from my errors.

26
00:01:53,880 --> 00:01:59,030
And this is the case probably where it's going to be faster if I just copy and paste.

27
00:01:59,040 --> 00:02:00,840
So let me take a look at it next year.

28
00:02:01,380 --> 00:02:04,440
And of course, the name is right here.

29
00:02:04,860 --> 00:02:08,060
So let me import this from my errors.

30
00:02:08,400 --> 00:02:11,009
And again, I think I'll have to go to levels up.

31
00:02:11,310 --> 00:02:16,470
So let me take a look at the require and we're looking at the errors folder.

32
00:02:16,890 --> 00:02:21,450
And since we have indexed, yes, you already know that we don't need to specify the path.

33
00:02:21,690 --> 00:02:23,220
Would you simply say errors?

34
00:02:23,670 --> 00:02:29,340
And with all of this in place now, of course, what we want to do is go with const off.

35
00:02:29,340 --> 00:02:30,720
So that's going to be our middleware.

36
00:02:30,840 --> 00:02:35,070
And of course, there's going to be a function and it's going to be looking for three things.

37
00:02:35,330 --> 00:02:38,460
The Iraq war as an unknown.

38
00:02:38,460 --> 00:02:43,230
As far as the function body, remember, the first thing we want to do is check for water.

39
00:02:43,590 --> 00:02:50,070
So let's add here to comment and we're looking for header first for the authorization one, and then

40
00:02:50,070 --> 00:02:52,530
we want to check whether it starts with bare.

41
00:02:52,770 --> 00:02:55,950
So first I'm going to set up the variable and I'll say auth.

42
00:02:57,760 --> 00:03:04,780
And that is equal to require earth and the authorization won, of course, and then after that, I'm

43
00:03:04,780 --> 00:03:12,070
looking for your statement and here I want to check if it doesn't exist, if there is no better, then

44
00:03:12,070 --> 00:03:16,020
of course, we'll throw the error or if it doesn't start with better.

45
00:03:16,450 --> 00:03:22,360
So let's go over here with our header and we'll go it starts with.

46
00:03:22,480 --> 00:03:26,020
So, of course, that's the JavaScript method that we can use on a string.

47
00:03:26,260 --> 00:03:31,270
And then we go with Barer and in some setups you'll see the space it as well.

48
00:03:31,660 --> 00:03:37,300
But darn, honestly, it doesn't really matter because remember, once we are done with a statement,

49
00:03:37,510 --> 00:03:39,000
we're still getting the token.

50
00:03:39,220 --> 00:03:44,530
And if there's going to be no space, then of course the token won't make sense.

51
00:03:44,530 --> 00:03:46,330
We won't be able to verify the token.

52
00:03:46,480 --> 00:03:47,800
We're splitting the token anyway.

53
00:03:48,220 --> 00:03:50,590
And let's go over here with throwing you.

54
00:03:50,890 --> 00:03:54,460
And of course, we're looking for an authenticated error.

55
00:03:54,790 --> 00:03:59,800
And as far as the text, let's go with authentication, an invalid.

56
00:04:00,220 --> 00:04:03,460
And, you know, we also need to add here async.

57
00:04:03,790 --> 00:04:05,630
So let's add over here async.

58
00:04:05,680 --> 00:04:08,770
Now we're checking for the header as well as the bearer.

59
00:04:08,980 --> 00:04:13,000
And if one of them is false, then of course, we throw there.

60
00:04:13,450 --> 00:04:15,880
And once we're done with that, let's go with our token.

61
00:04:16,029 --> 00:04:20,040
So it's a token is equal to all header.

62
00:04:20,230 --> 00:04:26,320
And then I remember we're splitting it and we're splitting it on the empty space and then we're looking

63
00:04:26,320 --> 00:04:28,810
for the second value and that's why we go with one.

64
00:04:29,140 --> 00:04:35,610
So we turn this into array and then we're looking for the second item in Iraq and this is what I'm saying.

65
00:04:35,620 --> 00:04:40,000
So even if you mendis this on here, just check for the better.

66
00:04:40,390 --> 00:04:48,400
If the user has sent Barer and then right away token, well, this one won't make sense because basically

67
00:04:48,400 --> 00:04:49,420
this will be undefined.

68
00:04:49,840 --> 00:04:52,870
We won't be able to split the string.

69
00:04:53,050 --> 00:04:56,080
And of course, if that's the case, we won't be able to verify.

70
00:04:56,380 --> 00:04:57,440
Hopefully that is clear.

71
00:04:57,460 --> 00:04:59,890
So let's go here would try catch.

72
00:05:00,160 --> 00:05:04,080
And then as far as the tribe block, we'll try to get the payload.

73
00:05:04,420 --> 00:05:10,780
So let's say over here, payload and remember, the method name is JWT and Verify.

74
00:05:11,080 --> 00:05:12,970
And here we want to pass in two things.

75
00:05:12,970 --> 00:05:15,340
We want to pass in the token comma.

76
00:05:15,550 --> 00:05:22,540
And then of course, we're looking for process that and we and then JWT underscore secret.

77
00:05:22,960 --> 00:05:28,830
And of course, once I have the payload, I just want to pass it along to the job routes.

78
00:05:29,200 --> 00:05:36,460
And in order to do that, will add a comment, attach the user to the job.

79
00:05:37,150 --> 00:05:42,160
And then as far as the logic, we can simply set up a that user.

80
00:05:42,400 --> 00:05:45,910
So I'm right away setting up the property on request object.

81
00:05:46,390 --> 00:05:52,600
And as far as the values in there, I'm going to go with user ID and not just my preference and then

82
00:05:52,600 --> 00:05:53,860
I'll go payload.

83
00:05:54,010 --> 00:05:56,200
So this is what I'm getting back from the verify.

84
00:05:56,500 --> 00:05:59,890
And of course in there I'll have the user ID as well.

85
00:06:00,310 --> 00:06:06,690
And technically we won't use the name, but just for testing, I'll pass in the name as well.

86
00:06:06,970 --> 00:06:11,500
So let's say your name and again, we're looking for payload and then that name.

87
00:06:11,500 --> 00:06:16,660
And again, if you're a little bit confused, essentially in here, we're just getting the payload that

88
00:06:16,660 --> 00:06:18,460
we're setting up in around.

89
00:06:18,790 --> 00:06:25,840
So if we take a look at our index routes, I'm sorry, not the next round if we're looking at the authorized.

90
00:06:26,700 --> 00:06:32,670
And notice here, when we are creating the Jessan Web talking right now, of course, the functionality,

91
00:06:32,670 --> 00:06:35,210
the actual functionality is in the models.

92
00:06:35,210 --> 00:06:40,440
So it may go over there in the user essentially of this, as is what we're passing in.

93
00:06:40,800 --> 00:06:43,560
We're passing in the user as well as the name.

94
00:06:43,950 --> 00:06:47,900
So in the authentication middleware, of course, this is what we're getting back.

95
00:06:48,150 --> 00:06:53,010
And again, this is just for testing essentially in our controllers, in the job controllers.

96
00:06:53,310 --> 00:06:55,440
Of course, we'll just use the other day.

97
00:06:55,530 --> 00:07:01,290
But since I want to showcase that this is actually the same user also passed in the name here as well.

98
00:07:01,590 --> 00:07:06,540
And then as far as the catch, well, we have the error and we can just throw it.

99
00:07:06,780 --> 00:07:11,400
We can just say over here, throw new and we'll go with our error.

100
00:07:11,610 --> 00:07:14,250
And essentially the text is going to be exactly the same.

101
00:07:14,250 --> 00:07:18,120
So I don't just take it from here and copy and paste.

102
00:07:18,240 --> 00:07:23,040
And before I let you go, of course, remember that we need to do two things.

103
00:07:23,250 --> 00:07:29,160
We need to export the off as well as we need to invoke the next, because otherwise we won't get to

104
00:07:29,160 --> 00:07:30,210
the job else anyway.

105
00:07:30,600 --> 00:07:32,490
So let's go here with the next first.

106
00:07:32,680 --> 00:07:41,640
So now, of course, we pass along the user to the job and we need to go with module exports and then

107
00:07:41,670 --> 00:07:48,570
we're looking for us and I'll set up the actual middleware as well as to start out in the next video.

