1
00:00:00,360 --> 00:00:06,780
And just to complete our initial cookie setup up, let's also discuss secure and signed flags.

2
00:00:07,470 --> 00:00:15,870
Now, when it comes to secure option, it restricts browsers to send cookies only over the TPS, which

3
00:00:15,870 --> 00:00:17,220
obviously is better.

4
00:00:17,730 --> 00:00:26,250
And as far as signed, cookie will still be visible, but with signature so it can detect if the client

5
00:00:26,250 --> 00:00:27,570
modify the cookie.

6
00:00:28,020 --> 00:00:30,000
So let's try to set it up.

7
00:00:30,360 --> 00:00:36,480
I'm going to go back to attach cookies response and where I have the cookies option.

8
00:00:36,960 --> 00:00:42,330
We're going to go with secure, but we're going to keep in mind that while we're testing, we're working

9
00:00:42,660 --> 00:00:44,670
in the deep correct.

10
00:00:45,150 --> 00:00:52,320
So the way around that is essentially to set up a condition that if we're production, yes, we'll use

11
00:00:52,320 --> 00:00:54,630
the secure, if not fine.

12
00:00:54,660 --> 00:01:02,520
We can use the actual DPI basically while we're developing and we will access that is by using process

13
00:01:03,240 --> 00:01:08,710
data entry and the name is node and underscore envy.

14
00:01:09,360 --> 00:01:11,100
So that's going to be the environment variable.

15
00:01:11,430 --> 00:01:15,330
And if it is in the production, then this will be true.

16
00:01:16,140 --> 00:01:19,200
And if it is in development, then of course it will be false.

17
00:01:19,410 --> 00:01:26,060
So there will be still able to send the cookies in development, but in production only over the ITPS,

18
00:01:26,070 --> 00:01:30,360
and we'll discuss this one more once we get to actual deployment.

19
00:01:30,840 --> 00:01:37,530
And also lastly, we want to set up the signed and we'll just go it signed equal to true.

20
00:01:37,950 --> 00:01:40,380
Let's say I on with four.

21
00:01:40,380 --> 00:01:41,370
We can do anything.

22
00:01:41,670 --> 00:01:43,800
We also need to go back to the app.

23
00:01:43,890 --> 00:01:44,370
Yes.

24
00:01:44,910 --> 00:01:50,490
And where we have the cookie parser, we want to pass in the signature.

25
00:01:51,180 --> 00:01:54,640
And you can use the same way how we used widget abilities.

26
00:01:54,720 --> 00:01:56,040
Remember, we're here.

27
00:01:56,400 --> 00:01:58,410
We have our JWT secret.

28
00:01:58,680 --> 00:02:04,440
So essentially we all use the same environment variable because at the very end of the project, we'll

29
00:02:04,440 --> 00:02:05,970
set up a more secure one.

30
00:02:06,330 --> 00:02:13,410
So we want to go back to objets where we have the cookie parser, where we invoke it will pass in as

31
00:02:13,410 --> 00:02:18,940
an argument process, data entry and then JWT secret.

32
00:02:18,990 --> 00:02:22,230
So now we're signing our cookies.

33
00:02:22,470 --> 00:02:22,860
Correct.

34
00:02:23,250 --> 00:02:26,430
Now the only difference right now is I'm going to uncomment.

35
00:02:27,430 --> 00:02:31,840
We're I'm sorry, I'm going to comment this out, and I'll show you that as far as accessing it.

36
00:02:32,350 --> 00:02:39,400
We'll have to use all the different syntax where once we sign the cookie, it's going to be available

37
00:02:39,880 --> 00:02:41,830
in the signed cookies.

38
00:02:42,190 --> 00:02:43,810
Not just in Iraq, but cookies.

39
00:02:44,260 --> 00:02:48,470
So as far as access, we go here with signed and cookies.

40
00:02:48,490 --> 00:02:51,010
So Iraq signed cookies.

41
00:02:51,370 --> 00:02:53,320
Let's save it and let's test it out.

42
00:02:53,530 --> 00:02:55,720
So let me go back to the registered user.

43
00:02:56,320 --> 00:02:58,630
And in this case, I'm going to go with Chris, I guess.

44
00:02:59,610 --> 00:03:06,000
Chris Chris at the email dot com, I guess after this video, I do need to remove my users.

45
00:03:06,270 --> 00:03:06,810
OK?

46
00:03:06,840 --> 00:03:10,260
We send the kooky awesome out here.

47
00:03:10,380 --> 00:03:11,700
Everything works really well.

48
00:03:12,000 --> 00:03:15,740
Be secure is false because we are still in development.

49
00:03:15,750 --> 00:03:24,900
And if I go to the testing route and if I send, if we go back to our server in a console, I can still

50
00:03:24,960 --> 00:03:25,800
see the token.

51
00:03:26,340 --> 00:03:29,340
That means that our setup works correctly.

