1
00:00:00,210 --> 00:00:00,700
Wonderful.

2
00:00:00,720 --> 00:00:07,950
And once we have tackled, we were all issue as well as alternative way to set up the Antman, but pretty

3
00:00:07,950 --> 00:00:10,110
much done with the trip ones.

4
00:00:10,630 --> 00:00:17,040
And next, we want to handle the passport because if you remember our initial project where we were

5
00:00:17,040 --> 00:00:23,310
setting up the passwords, I said should never, ever, ever save passwords as a string, then this

6
00:00:23,310 --> 00:00:24,900
is exactly what I'm doing right now.

7
00:00:25,470 --> 00:00:29,310
And just to jog your memory, we have multiple ways how we can set it up.

8
00:00:29,700 --> 00:00:33,270
We can definitely set up those functions in the hotels and all that.

9
00:00:33,750 --> 00:00:39,210
But it's also very nifty, set up in a pre safe, OK.

10
00:00:39,480 --> 00:00:43,800
And here I'm typing a user schema, but of course, is going to work with any schema.

11
00:00:44,610 --> 00:00:50,820
And I believe this was kept over here when we need to remember that when it comes to the hook, the

12
00:00:50,820 --> 00:00:54,930
callback function will point to a user and learn.

13
00:00:55,350 --> 00:01:00,710
The most important here is setting up the script with Jen, Salt and hash.

14
00:01:00,990 --> 00:01:06,290
So if you want, you can set them up in UTOS and then just utilize them in the controller.

15
00:01:06,300 --> 00:01:09,780
But in my case, I'll set up one in a pretty safe hook.

16
00:01:10,050 --> 00:01:16,320
So that's the one will generate the hashed password and second one compered password is just going to

17
00:01:16,320 --> 00:01:20,160
be one of the methods that we have on the document.

18
00:01:20,790 --> 00:01:28,320
So let's go back to our user and here all the way in the bottom, and you're not sure we before we do

19
00:01:28,320 --> 00:01:30,480
anything, we want to get the B script.

20
00:01:30,780 --> 00:01:37,680
So let's get the library that is responsible for hashing the passwords, and we'll go here with b script

21
00:01:37,830 --> 00:01:39,420
that is equal to require.

22
00:01:40,260 --> 00:01:42,810
And then we're looking for B script jazz.

23
00:01:42,990 --> 00:01:45,360
That was very, very important with animal.

24
00:01:45,360 --> 00:01:51,830
Scroll down and we'll just say over here, user schema, let's set up that pre-book.

25
00:01:52,020 --> 00:01:53,040
So preset.

26
00:01:53,490 --> 00:01:58,050
So before we save the document, we want to do is hash the password.

27
00:01:58,380 --> 00:02:01,200
And here I'm going to go with async keyword.

28
00:02:01,560 --> 00:02:03,330
Then we'll pass in the function.

29
00:02:03,840 --> 00:02:11,460
And like I showcased in the read me, remember this point back to the user.

30
00:02:11,910 --> 00:02:15,420
So every time I would use this, that just means a user.

31
00:02:15,720 --> 00:02:20,040
And in the later mongooses versions, we don't need to even pass in next.

32
00:02:20,370 --> 00:02:22,350
So first, we want to generate the salt.

33
00:02:22,620 --> 00:02:25,590
So a number of rounds just so it's more secure.

34
00:02:25,590 --> 00:02:30,930
So we're going to go here with a wait b script and the function name is John Salt.

35
00:02:31,390 --> 00:02:34,020
And typically 10 rounds is very, very good.

36
00:02:34,470 --> 00:02:36,730
Then we want to target this dot password.

37
00:02:36,810 --> 00:02:37,140
Why?

38
00:02:37,540 --> 00:02:41,640
Well, because that's the key we have here, the password one.

39
00:02:41,910 --> 00:02:45,090
So this that password is going to be equal to.

40
00:02:45,570 --> 00:02:48,090
And then we again stick away in front of it.

41
00:02:48,480 --> 00:02:51,070
We say decrypt when hash.

42
00:02:51,090 --> 00:02:57,630
So we asked the password and the first parameter we need to pass in is the current password, and the

43
00:02:57,630 --> 00:02:59,550
second one is the salt.

44
00:02:59,940 --> 00:03:01,950
So now we are hashing our passwords.

45
00:03:02,430 --> 00:03:08,170
And while we're at it, let's also set up a function that will compare those hash passwords.

46
00:03:08,190 --> 00:03:11,460
Because remember, hashing is a one way street.

47
00:03:11,880 --> 00:03:14,430
Once we hash the password, that's it.

48
00:03:14,880 --> 00:03:16,020
It's done, it's hashed.

49
00:03:16,350 --> 00:03:22,020
And the only thing we can do is take again the string value hash and then compare it.

50
00:03:22,140 --> 00:03:26,250
That's the only way for us to find out whether the password is exactly the same.

51
00:03:26,550 --> 00:03:28,170
So in here, let's go with the user schema.

52
00:03:28,560 --> 00:03:29,910
We're looking for methods.

53
00:03:30,030 --> 00:03:32,310
And so I want that on my user.

54
00:03:32,580 --> 00:03:37,320
So on the user instance, I will go here with CP. password.

55
00:03:38,920 --> 00:03:40,930
That is equal to my missing function again.

56
00:03:41,840 --> 00:03:43,630
And let's just go with function.

57
00:03:43,930 --> 00:03:51,580
And if you remember, we use the good old keyword, the function keyword, because that way this will

58
00:03:51,580 --> 00:03:54,070
point to the user with arrow functions.

59
00:03:54,090 --> 00:03:54,820
That's not the case.

60
00:03:55,300 --> 00:03:57,400
And here, virtually all pass in.

61
00:03:57,400 --> 00:04:05,380
The argument is going to be that candidate password, basically the one that the user is typing in when

62
00:04:05,380 --> 00:04:06,580
he or she is registering.

63
00:04:06,970 --> 00:04:13,750
So candidate admin just makes sure that I'm spelling correctly because spelling is always my soft spot.

64
00:04:13,960 --> 00:04:17,230
So let's go here with candidate password spelling and typing.

65
00:04:17,350 --> 00:04:21,399
Those are my two best qualities I should say is magic.

66
00:04:21,399 --> 00:04:23,320
And of course, I'm using the air quotes right now.

67
00:04:23,350 --> 00:04:31,390
When I say qualities and we'll go with a wait b script, then we'll use CP. That's another method and

68
00:04:31,390 --> 00:04:38,020
we want to pass here, use the candidate password and reverse that password and then we want to return

69
00:04:38,020 --> 00:04:38,710
is match.

70
00:04:39,160 --> 00:04:42,970
So if it is a match, then we'll return true.

71
00:04:42,970 --> 00:04:47,410
If not, then worked on the Pulse so that we will be able to compare the passwords.

72
00:04:47,950 --> 00:04:48,400
So now.

73
00:04:49,320 --> 00:04:51,360
I want to go back to the Mongol one more time.

74
00:04:51,900 --> 00:04:52,890
Let me go here.

75
00:04:53,770 --> 00:04:54,640
Let me refresh.

76
00:04:55,180 --> 00:04:56,980
Just so we start from scratch.

77
00:04:57,730 --> 00:05:01,360
And what I want to do is to remove everything.

78
00:05:02,250 --> 00:05:08,800
So Susan goes, So let's beat her and then let's try to make them one more time.

79
00:05:09,220 --> 00:05:11,440
In this case, I'll remove the admin clearly.

80
00:05:11,440 --> 00:05:12,370
See what is happening.

81
00:05:12,520 --> 00:05:13,690
So let's save it here.

82
00:05:14,500 --> 00:05:16,230
Let's say that we want to send beta.

83
00:05:16,780 --> 00:05:20,170
OK, our cell password right now is awesome.

84
00:05:20,680 --> 00:05:21,280
Beautiful.

85
00:05:21,300 --> 00:05:23,040
And let's do the same thing here.

86
00:05:23,620 --> 00:05:25,990
We Susan Susan.

87
00:05:26,950 --> 00:05:31,090
And we can clearly see that the role was on for Peter, because that's the first one.

88
00:05:31,570 --> 00:05:34,090
And then Susan is a user.

89
00:05:34,490 --> 00:05:40,930
And what's really called that password is still hashed nice and how it can proceed to just how much

90
00:05:40,940 --> 00:05:41,350
tokens.

