1
00:00:00,390 --> 00:00:00,900
Beautiful.

2
00:00:01,290 --> 00:00:09,060
And once we've got some roads that we can actually authenticate now, let's start working on the authentication

3
00:00:09,060 --> 00:00:17,430
middleware and we'll start with the general structure and then slowly we proceed to more complex steps.

4
00:00:17,950 --> 00:00:24,360
The first, I just want to set up the middleware that will stick in front of both routes will just check

5
00:00:24,540 --> 00:00:25,770
with our token exist.

6
00:00:26,100 --> 00:00:27,960
And here are some logs and all that.

7
00:00:28,410 --> 00:00:33,570
Then we'll set up the functionality where we'll check whether the token is valid.

8
00:00:33,810 --> 00:00:34,770
So that's the next step.

9
00:00:35,100 --> 00:00:38,880
And then we'll authorize based on permissions.

10
00:00:38,880 --> 00:00:41,130
Because again, I know I said this already before.

11
00:00:41,580 --> 00:00:45,690
Get all users is only only only for admin.

12
00:00:46,230 --> 00:00:51,450
I don't want Susan to see all the users of my application or your application, for that matter.

13
00:00:51,600 --> 00:00:53,250
And I've got nothing against Susan.

14
00:00:54,000 --> 00:00:55,800
Hopefully, you understand it's just an example.

15
00:00:56,250 --> 00:01:00,390
So let's go back and we're looking for middleware.

16
00:01:00,570 --> 00:01:07,500
Now, I already added authentication file because that's what we did in a previous project, but I just

17
00:01:07,500 --> 00:01:11,310
go over the steps just so we all are on the same page.

18
00:01:11,340 --> 00:01:13,200
First, we want to do some import.

19
00:01:13,860 --> 00:01:18,630
We want to import custom error because we will throw some errors as well.

20
00:01:18,750 --> 00:01:21,270
Eventually, we'll check whether the token is valid.

21
00:01:22,200 --> 00:01:30,060
Remember, reverse sucker or we're here is talking about the one with JWT Verify.

22
00:01:30,540 --> 00:01:37,380
So since, well, we used both in the middle order, let's go back and let's say it comes custom custom

23
00:01:37,380 --> 00:01:39,780
error that is coming from my errors.

24
00:01:41,010 --> 00:01:46,680
So here I go to one level up and we're in the air, and the second thing is.

25
00:01:47,520 --> 00:01:56,850
And since I'm exporting from the utos, I can just go is Duncan Rowland and choir, and I'm looking

26
00:01:57,360 --> 00:02:03,210
for my utos to levels up or I keep saying two levels, basically what I mean, it's two dots.

27
00:02:03,210 --> 00:02:05,730
And then I'm looking in the Utah software.

28
00:02:06,210 --> 00:02:07,590
That's not too confusing.

29
00:02:07,770 --> 00:02:09,389
Then we want to set up the middleware.

30
00:02:09,960 --> 00:02:19,560
So let's go here with Konst, and I'm going to call this one authenticate user, authenticate user,

31
00:02:20,160 --> 00:02:22,500
and it's going to be a sync function.

32
00:02:23,220 --> 00:02:28,800
We're going to be looking for Iraq arrives and we need to have been next as well because we want to

33
00:02:28,800 --> 00:02:34,110
pass into the next middleware, a.k.a. our actual roots here.

34
00:02:34,500 --> 00:02:38,180
Therefore, make sure to check out the next in the function body.

35
00:02:38,190 --> 00:02:41,700
Like I said, let's start very simply if you're a member in the app.

36
00:02:41,790 --> 00:02:48,550
Yes, I had that dummy around now since we signed our cookies with process.

37
00:02:48,550 --> 00:02:50,850
Got the we JWT secret.

38
00:02:51,980 --> 00:02:54,350
Where were the token located?

39
00:02:55,130 --> 00:02:56,910
It is in the signed cookies.

40
00:02:57,420 --> 00:02:59,120
Not just regular cookies and cookies.

41
00:02:59,570 --> 00:03:05,660
Therefore, in the middle where I want to check is the token present because we do have the log out

42
00:03:05,660 --> 00:03:06,620
functionality correct?

43
00:03:06,840 --> 00:03:17,570
So let's go back side token here, not as equal to Yurek when signed cookies and cookies and then token,

44
00:03:17,930 --> 00:03:19,880
that's the name that I gave to my cookie.

45
00:03:20,150 --> 00:03:20,480
Correct.

46
00:03:20,660 --> 00:03:27,110
So if you have a different name for different property, then we simply want to check whether it's present.

47
00:03:27,110 --> 00:03:28,320
And for now, we'll just cancel.

48
00:03:28,560 --> 00:03:30,110
Again, this is just the structure.

49
00:03:31,130 --> 00:03:33,500
Way you can clearly see how everything works.

50
00:03:33,500 --> 00:03:34,430
So let's go log.

51
00:03:34,670 --> 00:03:42,040
So if it's not present error, no token present, and eventually we'll take some more drastic steps.

52
00:03:42,050 --> 00:03:42,770
Not for now.

53
00:03:43,460 --> 00:03:50,050
And if it is present, then let's just say token present and then we can proceed to the next little

54
00:03:50,050 --> 00:03:50,200
while.

55
00:03:50,210 --> 00:03:52,880
Now, since my typing is terrible, I'm not going to take that.

56
00:03:52,880 --> 00:03:54,380
I'm just going to say token present.

57
00:03:54,830 --> 00:03:58,370
And then most importantly, we go with next.

58
00:03:59,150 --> 00:04:05,600
Then we want to go with module exports and we want to export authenticate user.

59
00:04:06,700 --> 00:04:16,540
And then we have two options since I know that all my views are out, we'll need the user authentication

60
00:04:16,600 --> 00:04:17,380
technically.

61
00:04:18,399 --> 00:04:24,520
I can run over two objects and stick it in front of the user or not.

62
00:04:24,670 --> 00:04:26,530
That is not my preference.

63
00:04:27,310 --> 00:04:33,490
I prefer setting up everything in the user route because that way I can clearly see, OK, I'm checking

64
00:04:33,490 --> 00:04:39,060
for the user as well as the admin, because admin as a sign on, it's going to be a separate function.

65
00:04:39,070 --> 00:04:42,310
Again, let me repeat, that is my preference.

66
00:04:42,700 --> 00:04:43,690
You don't have to do that.

67
00:04:44,320 --> 00:04:51,470
All of these user routes will need authentication, so technically you can't have here in front.

68
00:04:51,490 --> 00:04:53,680
And remember, we covered up in jobs API.

69
00:04:54,130 --> 00:04:57,040
If you don't, please go back because I do cover it there.

70
00:04:57,580 --> 00:05:04,090
But in this case, I'm going to go to user route and now I want to get authenticate user.

71
00:05:04,290 --> 00:05:11,350
So let's go here or call this authenticate user because that's the name they're looking for acquire.

72
00:05:11,650 --> 00:05:12,910
I want to go to middleware.

73
00:05:14,000 --> 00:05:14,780
So let's see.

74
00:05:15,380 --> 00:05:22,970
So we're here, and in this case, I there need to be a specific authentication and then where I get

75
00:05:22,970 --> 00:05:25,610
all users and get single user.

76
00:05:25,820 --> 00:05:29,930
Let's add that middleware for now, let's leave these ones alone.

77
00:05:30,440 --> 00:05:31,970
So go here with.

78
00:05:33,090 --> 00:05:34,710
Authenticates the user.

79
00:05:37,830 --> 00:05:39,280
Or I'm sorry, user.

80
00:05:39,540 --> 00:05:40,830
Yes, that's more correct.

81
00:05:41,990 --> 00:05:43,070
And let's get it here.

82
00:05:43,650 --> 00:05:45,020
Let's copy and paste.

83
00:05:46,070 --> 00:05:48,590
And let me just check it out if.

84
00:05:49,550 --> 00:05:51,380
My memory serves me correct.

85
00:05:52,160 --> 00:05:52,940
We logged out.

86
00:05:53,330 --> 00:05:54,650
I don't see any cookies.

87
00:05:55,010 --> 00:06:04,430
So now if I'm trying to access all the users, I should see in counsel error, no token present.

88
00:06:04,460 --> 00:06:08,510
Now, of course, when I wrote it, it's not the really correct.

89
00:06:08,900 --> 00:06:11,220
So and here, let's just add else.

90
00:06:11,270 --> 00:06:12,800
Again, this is just for time being.

91
00:06:13,280 --> 00:06:13,870
My apologies.

92
00:06:13,880 --> 00:06:15,800
Of course, there's going to be two hours now.

93
00:06:16,460 --> 00:06:17,390
So let's go back.

94
00:06:17,750 --> 00:06:18,680
Rookie mistake.

95
00:06:19,070 --> 00:06:20,390
So now I have error.

96
00:06:20,510 --> 00:06:22,130
No token present.

97
00:06:22,510 --> 00:06:23,780
So now everything is correct.

98
00:06:23,780 --> 00:06:24,560
There's no token.

99
00:06:24,830 --> 00:06:26,360
So we get the log.

100
00:06:26,930 --> 00:06:32,240
And now if I'm going to go back in the off and I'm going to log in as John.

101
00:06:33,320 --> 00:06:40,340
I should get the log in the console, the token is present so I can take a look at all the users, and

102
00:06:40,340 --> 00:06:42,530
I can also take a look at one user.

103
00:06:42,630 --> 00:06:42,920
Yep.

104
00:06:43,500 --> 00:06:44,020
Present.

105
00:06:44,420 --> 00:06:51,590
And let's say I want to take a look at Peter's profile for single user, and I'm in good shape.

106
00:06:51,740 --> 00:06:52,490
I got back to.

107
00:06:53,590 --> 00:06:56,950
Peter and I can also see that the token is present.

108
00:06:57,310 --> 00:07:05,080
So those are our first steps where we just want to check the token in sign tokens because we signed

109
00:07:05,080 --> 00:07:05,320
them.

110
00:07:05,560 --> 00:07:08,170
If you don't send them, then it's just going to be in the cookies.

111
00:07:08,950 --> 00:07:10,660
Very, very important distinction.

112
00:07:10,950 --> 00:07:16,690
Sanctuaries are going to be in record sign cookies, regular cookies if you don't sign them and they're

113
00:07:16,690 --> 00:07:18,540
just going to be in the cookies.

114
00:07:18,550 --> 00:07:21,100
And the reason why I'm looking here for a token.

115
00:07:21,760 --> 00:07:25,210
Well, because I named your token, so that's my object.

116
00:07:25,720 --> 00:07:26,650
Hopefully, that's clear.

117
00:07:27,130 --> 00:07:32,140
So now I can work on more complex functionality.

