1
00:00:00,270 --> 00:00:07,770
And once we have fixed the email issue next, let's work on the role and we'll knock out both of these

2
00:00:07,770 --> 00:00:14,820
in this video and effectively in this project, what's going to be different is the fact that users

3
00:00:14,820 --> 00:00:15,780
have roles.

4
00:00:16,170 --> 00:00:20,310
So by default, all of the users will have user all.

5
00:00:21,230 --> 00:00:27,050
But we can also manually change it here in a database and set it up as an admin.

6
00:00:27,320 --> 00:00:28,640
Now why do we want to do that?

7
00:00:29,060 --> 00:00:34,970
Well, because admins will have more privileges that will be able to view all their users.

8
00:00:35,120 --> 00:00:40,820
Maybe take a look at specific user account, even though it's technically not their account.

9
00:00:41,150 --> 00:00:46,570
And more importantly, we can add, remove and deal everything with the product.

10
00:00:46,610 --> 00:00:49,160
So when it comes to users, they can leave reviews.

11
00:00:49,670 --> 00:00:54,830
They can make orders, but they're not going to be able to add products in our current setup.

12
00:00:55,130 --> 00:00:57,080
Yes, everything works nicely.

13
00:00:57,890 --> 00:01:00,770
Where we have, we're all user for David.

14
00:01:01,430 --> 00:01:10,280
But there's also a little issue where technically from the postman, I can send it and I can add role

15
00:01:10,280 --> 00:01:10,940
as admin.

16
00:01:11,120 --> 00:01:18,130
So if I go back here and if I says Susan, I'm Susan and gmail.com and the password will still be secret.

17
00:01:18,140 --> 00:01:24,200
But if I add the role and I said, it's equal to your admin, I'm actually going to be successful because

18
00:01:24,200 --> 00:01:31,460
if you're a member in our user model over here, these are two possible options.

19
00:01:31,790 --> 00:01:36,650
So we have Adam as well as the user and our share, our successful.

20
00:01:36,680 --> 00:01:41,660
You can make an argument that normally this is going to be controlled by the frontend.

21
00:01:42,230 --> 00:01:44,500
So that's a typical register for notice.

22
00:01:44,510 --> 00:01:52,460
Of course, I don't have anywhere the user option because I don't want my users to register as correct,

23
00:01:52,790 --> 00:01:58,070
because what happens in most cases will have way more privileges than the users.

24
00:01:58,610 --> 00:02:03,650
So that's the answer number one, where in most cases is going to be controlled by the frontend.

25
00:02:03,650 --> 00:02:10,910
But if we want to make our back end a little bit more secure, we can also go back to the auth controller

26
00:02:11,570 --> 00:02:16,940
and instead of just dumping everything like we're doing over here would erect that body, we can pull

27
00:02:16,940 --> 00:02:18,830
out the values that we're looking for.

28
00:02:19,250 --> 00:02:26,300
So where I'm just structuring the email, I also look for a name and also for password for both of these

29
00:02:26,300 --> 00:02:26,570
things.

30
00:02:27,110 --> 00:02:30,500
And not when I'm creating that new user.

31
00:02:31,130 --> 00:02:37,730
What I want to do is just pass in the object and whatever properties that I want.

32
00:02:38,180 --> 00:02:46,220
So I'm going to name, email and password and check it out, even if somebody passes here, arrow.

33
00:02:46,790 --> 00:02:48,020
It's not going to get to the user.

34
00:02:48,620 --> 00:02:52,730
So users by default will be set up as users.

35
00:02:53,730 --> 00:03:02,190
Like we have over here in a model, and only if we manually go back to the model to be and we out of

36
00:03:02,190 --> 00:03:03,540
there, then we're successful.

37
00:03:03,870 --> 00:03:07,860
Now, of course, you can create a dashboard with a different application where you can change that.

38
00:03:08,190 --> 00:03:09,570
I mean, that's a different topic.

39
00:03:10,110 --> 00:03:13,980
What I want to do right now is just go to the users in my MongoDB.

40
00:03:14,580 --> 00:03:15,690
I want to refresh.

41
00:03:16,600 --> 00:03:21,970
And here, first, they'll remove both of them just so can start from scratch.

42
00:03:22,570 --> 00:03:22,960
So.

43
00:03:23,940 --> 00:03:28,620
And let's try to add one more time, Susan, with an amen.

44
00:03:29,520 --> 00:03:34,890
So let's go back to the post man at Senate notice here, how she's a writer where all of you, sir.

45
00:03:35,250 --> 00:03:42,090
And only if I go back here and manually change it from user to aberrant or whatever.

46
00:03:42,690 --> 00:03:44,310
And of course, we can do that.

47
00:03:44,310 --> 00:03:50,280
So in this case, I would click on a pencil for user and I would just set it up as admin.

48
00:03:50,790 --> 00:03:57,540
Now there's another thing that I want to show you how we can technically set up our first user as an

49
00:03:57,540 --> 00:04:03,780
argument, and in the process, we'll learn a method by the name of code documents that we can use on

50
00:04:03,780 --> 00:04:04,140
model.

51
00:04:04,170 --> 00:04:05,730
So let me remove one more time.

52
00:04:06,360 --> 00:04:07,830
So I'm not here.

53
00:04:08,100 --> 00:04:12,330
So technically, yes, she's an admin and all that, but we'll actually remove her.

54
00:04:13,660 --> 00:04:21,100
Now we want to go back to the controller, and here we want to go above every user, basically above

55
00:04:21,100 --> 00:04:25,960
the line where we create the user and we want to make a comment.

56
00:04:26,320 --> 00:04:31,420
And essentially, I want to create a new variable is first first count.

57
00:04:31,880 --> 00:04:39,790
Now that is equal to a weight and lateral years, the user model and on the user model, we have actually

58
00:04:39,790 --> 00:04:42,550
a function by the name of count documents.

59
00:04:43,120 --> 00:04:45,970
Now what's neat about conduct means we're going to pass in the filter object.

60
00:04:46,570 --> 00:04:52,420
So technically, we can count documents based on some kind of condition, just like we're doing with

61
00:04:52,420 --> 00:04:54,010
find one or find and all that.

62
00:04:54,460 --> 00:04:56,800
Now, in this case, I don't want to use any condition.

63
00:04:57,190 --> 00:05:02,140
I'm just passing the empty object and essentially about just means that I'm going to be getting all

64
00:05:02,150 --> 00:05:04,480
documents if I have the document.

65
00:05:05,050 --> 00:05:08,890
Now, if this is equal to no, that means that another user's correct.

66
00:05:09,190 --> 00:05:11,650
So that means that this is going to be the first account.

67
00:05:11,700 --> 00:05:19,870
And if it is the first account, I can also set up the role and second row is equal to and is first

68
00:05:19,870 --> 00:05:20,290
account.

69
00:05:20,740 --> 00:05:25,990
If that is the case, if this is actually true, then the role will be admin.

70
00:05:26,530 --> 00:05:29,350
And if not, it's going to be a user.

71
00:05:29,610 --> 00:05:33,730
OK, so so let's say it here, and we can also pass the role.

72
00:05:34,270 --> 00:05:35,260
So let's set it up.

73
00:05:35,710 --> 00:05:43,630
And now if I go back to the postman and if I tried here, one more time to set up Susan, as you can

74
00:05:43,630 --> 00:05:45,190
see, I mean is not valid.

75
00:05:45,190 --> 00:05:47,860
Enum value was right here.

76
00:05:48,340 --> 00:05:51,610
I'm sorry it is admin, but sign it one more time.

77
00:05:51,760 --> 00:05:53,230
And now she's an admin.

78
00:05:53,390 --> 00:05:56,260
Now, if I'm going to go back here and if I'm going to say Peter.

79
00:05:57,560 --> 00:06:00,920
Peter, and but still try to do this.

80
00:06:01,040 --> 00:06:01,400
Correct.

81
00:06:01,770 --> 00:06:04,990
So what Senate and I'll still get back to you again.

82
00:06:05,030 --> 00:06:12,650
The goal of this video was just to showcase multiple approaches you can take when it comes to user roles.

