1
00:00:00,270 --> 00:00:00,690
All right.

2
00:00:00,720 --> 00:00:07,830
And once we can successfully register user knowledge, issue a JSON web token so that we can start restricting

3
00:00:07,830 --> 00:00:10,200
access to certain resources.

4
00:00:10,770 --> 00:00:18,930
And just to jog your memory, if you remember jobs API, that's the token that we're going to be sending

5
00:00:18,930 --> 00:00:19,230
back.

6
00:00:19,740 --> 00:00:23,190
Remember, in our response, we send back the token.

7
00:00:23,730 --> 00:00:30,330
And then in the following requests, the user was including that token.

8
00:00:30,990 --> 00:00:35,730
So if I take a look at the request headers, I will see a bear.

9
00:00:36,180 --> 00:00:37,890
I'm not going to be the value of the token.

10
00:00:38,460 --> 00:00:42,900
So start with the same setup and then we'll introduce the cookies.

11
00:00:43,350 --> 00:00:44,970
Now, as far as our checklist.

12
00:00:46,030 --> 00:00:52,290
We need to remember that we used package by the name of Jason, what token provided we have two functions

13
00:00:52,300 --> 00:00:58,240
one for creating a token and the value sign, and the second one is verify.

14
00:00:58,630 --> 00:00:59,830
Now this one is a bonus.

15
00:00:59,830 --> 00:01:03,640
For now, we will create this one later once we actually have a log in wrong.

16
00:01:04,030 --> 00:01:07,840
But if you remember how to verify, that's also very, very neat.

17
00:01:08,350 --> 00:01:10,490
And then don't worry about these two right now.

18
00:01:10,900 --> 00:01:17,490
We'll deal with them the very end of the video, and I want to start setting everything up in the off

19
00:01:17,500 --> 00:01:23,970
controller and then we'll move our code into the Utah so we can reuse it in different projects.

20
00:01:24,450 --> 00:01:32,080
The first one I want is to require the package, and I'm going to call this JWT is equal to require.

21
00:01:32,440 --> 00:01:37,120
And if you remember the package, your name was JSON web token.

22
00:01:37,660 --> 00:01:42,070
When we scroll down and once we're successful, we create the user.

23
00:01:42,490 --> 00:01:44,650
Now it's also issue a token.

24
00:01:45,370 --> 00:01:47,440
So I'm going to come up with some kind of name.

25
00:01:47,680 --> 00:01:54,790
It's going to be a token one and we're going to go with JWT and then sine function.

26
00:01:55,210 --> 00:01:57,180
And here we need to pass in three values.

27
00:01:57,190 --> 00:01:58,780
We need to pass in the payload.

28
00:01:59,650 --> 00:02:06,340
So basically what we will be sending, and it's very useful to send the idea because you'll use it to

29
00:02:06,340 --> 00:02:07,450
access the resources.

30
00:02:07,870 --> 00:02:14,590
In our case, we also want to pass in the role because we'll have some role based authentication.

31
00:02:15,070 --> 00:02:19,690
And then just for kicks, I'll also pass the name and this is going to make sense a little bit later.

32
00:02:20,140 --> 00:02:22,270
Once will create a show me around.

33
00:02:22,390 --> 00:02:24,160
So don't worry about it right now.

34
00:02:24,670 --> 00:02:28,030
And as far as the payload actually want to set up a token user.

35
00:02:28,390 --> 00:02:34,630
So I don't want to tag this entire user and stick it in there as a payload because we have sensitive

36
00:02:34,630 --> 00:02:36,980
information, we have the password and all that.

37
00:02:37,510 --> 00:02:41,830
So I think it's a better approach if we go with a token user.

38
00:02:42,790 --> 00:02:48,730
And here we specifically say, well, what properties we want to set up, and I want to set up a name,

39
00:02:49,210 --> 00:02:57,310
so user name one comma user I.D. that's going to be equal to user and then we'll go with underscore

40
00:02:57,310 --> 00:02:57,600
80.

41
00:02:57,850 --> 00:03:00,520
And then lastly, remember, we also have a role.

42
00:03:01,030 --> 00:03:03,620
So let's go with use URL run.

43
00:03:03,940 --> 00:03:08,290
I want to take this token user and stick it in as a payload.

44
00:03:08,890 --> 00:03:11,830
And for the time being, I'll just code the secret.

45
00:03:12,310 --> 00:03:15,850
I'm going to go with JWT secret.

46
00:03:16,510 --> 00:03:18,850
And then lastly, we want to set up the options.

47
00:03:19,760 --> 00:03:25,040
And it's very useful to say, you know, how long it's going to expire and we're going to go it expires

48
00:03:25,040 --> 00:03:25,250
in.

49
00:03:26,220 --> 00:03:28,470
And let's set it up as one day.

50
00:03:28,800 --> 00:03:29,820
Let's save it.

51
00:03:30,330 --> 00:03:32,070
Now we have our token.

52
00:03:32,490 --> 00:03:39,180
And what I want to do right now, as far as the response I want to go with user is equal to my token

53
00:03:39,180 --> 00:03:39,540
user.

54
00:03:39,930 --> 00:03:45,930
So instead of sending back the entire object, sending back the token user with only the three properties.

55
00:03:46,290 --> 00:03:48,240
And I also want to passing the token.

56
00:03:48,840 --> 00:03:54,480
So we'll go here with token and now I want to navigate back to my or to me.

57
00:03:55,600 --> 00:04:00,100
The lead, both of the users, and then let me get to the postman.

58
00:04:00,550 --> 00:04:00,940
Two years.

59
00:04:00,970 --> 00:04:08,860
Good old Susan Sundered in response, not only I can see the name user I.D. and role, which is adamant

60
00:04:08,860 --> 00:04:15,010
because she's the first user, but we also get a token, which is just awesome.

61
00:04:15,340 --> 00:04:22,960
Now I'm not going to configure the postman to set up the birth token because in the next few years we'll

62
00:04:22,960 --> 00:04:27,930
set up our cookies where the cookies will send the JWT.

63
00:04:27,940 --> 00:04:32,710
So it seems like an overkill to repeat all of the steps if you're going to see the token.

64
00:04:33,010 --> 00:04:33,490
Awesome.

65
00:04:33,820 --> 00:04:41,230
Now we can proceed to the next steps, and what I want to do next is to set up two variables in the

66
00:04:41,260 --> 00:04:41,790
entry.

67
00:04:42,400 --> 00:04:47,590
So let's run over here and I want to add JWT correct with this silly string.

68
00:04:47,740 --> 00:04:48,430
And don't worry.

69
00:04:48,730 --> 00:04:53,500
Right before we push this up to the production, we'll set it up as a proper value.

70
00:04:53,920 --> 00:05:01,390
And I also want to set it up a variable by the name of JWT Lifetime and set it equal to one day.

71
00:05:01,420 --> 00:05:06,610
Now I'm going to do that in between the videos, just so I don't have to remove my password and all

72
00:05:06,610 --> 00:05:06,850
that.

73
00:05:07,420 --> 00:05:08,980
And I suggest you do the same.

74
00:05:09,130 --> 00:05:16,540
So go to that and we create two variables with whatever values you think are necessary, and then you

75
00:05:16,540 --> 00:05:19,060
can move on to the next video next.

76
00:05:19,060 --> 00:05:21,100
VIDEO We'll refactor the code.

77
00:05:22,040 --> 00:05:28,370
We're a little more less functionality where we create the token and verify token into the UTOS folder.

