1
00:00:00,180 --> 00:00:00,630
Beautiful.

2
00:00:00,780 --> 00:00:07,800
Once we've got the general structure in place now, let's actually set it up that we can check for a

3
00:00:07,800 --> 00:00:16,620
token with this token value and then if the token is not present or the token is invalid, then we throw

4
00:00:16,620 --> 00:00:17,940
back the 401.

5
00:00:18,510 --> 00:00:25,710
So let's go to authenticate user and then if the token is present.

6
00:00:25,810 --> 00:00:28,020
Well, first of all, let me remove else.

7
00:00:28,290 --> 00:00:29,280
We're not going to need that.

8
00:00:30,310 --> 00:00:39,400
And I'm here, I'm is going to go with Pro new customer, so if Duncan is not present and I sign up

9
00:00:39,430 --> 00:00:47,170
here, I need to add error and we're looking for on authenticated error might just say authentication

10
00:00:47,170 --> 00:00:49,030
failed or invalid.

11
00:00:49,720 --> 00:00:52,510
So invalid, let's say about one.

12
00:00:52,660 --> 00:00:59,450
So if there is no token, let's say if we have logged out or if the user hasn't registered or logged

13
00:00:59,470 --> 00:01:02,370
in, then this is what will spam.

14
00:01:02,650 --> 00:01:10,180
Now, if the token is present one, let's set up try catch and we need to go with const payload.

15
00:01:10,200 --> 00:01:11,920
So that's the payload that I'm looking for.

16
00:01:12,640 --> 00:01:16,480
This is something that is token valid will return.

17
00:01:17,020 --> 00:01:17,540
Nine.

18
00:01:17,560 --> 00:01:19,660
We need to go with this token valid.

19
00:01:19,960 --> 00:01:26,560
And if you remember, I set it up as an object now as I'm looking at it, probably in these cases,

20
00:01:26,570 --> 00:01:27,730
this was an overkill.

21
00:01:27,940 --> 00:01:30,940
I could have just went with a straight up parameter.

22
00:01:31,240 --> 00:01:34,990
Since there's not multiple arguments, but hey, it is what it is.

23
00:01:35,320 --> 00:01:36,880
So in this case, I have the object.

24
00:01:36,880 --> 00:01:44,830
So just to make sure that we don't get any bugs at a objects or curly braces and then the token.

25
00:01:45,020 --> 00:01:49,520
So this is what we'll be passing them and then I'm going to be looking for the payload.

26
00:01:49,540 --> 00:01:51,370
Now, if everything is correct.

27
00:01:52,460 --> 00:01:53,960
I should get back what?

28
00:01:54,560 --> 00:02:00,950
Well, whatever we're passing here, correct, so payload is equal to our user, to our user token.

29
00:02:01,390 --> 00:02:07,100
I'm not going to add a few more properties, like when it was created, when it's going to expire and

30
00:02:07,100 --> 00:02:08,009
all that stuff.

31
00:02:08,389 --> 00:02:14,090
So why don't we first just log what we have as a payload and then we'll decide what we're passing along

32
00:02:14,570 --> 00:02:15,980
as a user?

33
00:02:16,280 --> 00:02:23,960
Now, if everything is correct, when I'm president to the next middle or which are in our case are

34
00:02:23,960 --> 00:02:26,150
the get our users and get single user.

35
00:02:26,480 --> 00:02:29,270
Now, if there is an error, I want to do the same thing.

36
00:02:30,080 --> 00:02:34,160
I want to go with custom error and authentication invalid.

37
00:02:34,580 --> 00:02:40,010
So now let's navigate back to our postman and we successfully already logged in.

38
00:02:40,010 --> 00:02:42,050
At least I did as John.

39
00:02:42,650 --> 00:02:46,760
So now let me just do that one more time, just in case.

40
00:02:47,090 --> 00:02:48,410
So I have my cookies.

41
00:02:48,530 --> 00:02:49,370
OK, awesome.

42
00:02:49,820 --> 00:02:53,930
And now we want to go to your get all users or get single user doesn't really matter.

43
00:02:54,350 --> 00:02:58,160
And if we send, our should get back the response.

44
00:02:58,430 --> 00:02:59,180
Awesome idea.

45
00:02:59,600 --> 00:03:06,080
And then if I take a look at the console, I can see that this is the data, but I passed in when I

46
00:03:06,320 --> 00:03:06,950
logged in.

47
00:03:07,790 --> 00:03:12,530
So this is my cookie name, user I.D. URL.

48
00:03:12,830 --> 00:03:17,690
And like I said, when it expires and when it was issued and my cache.

49
00:03:18,630 --> 00:03:25,560
The way I'm going to do it, I'm going to go with Iraq user is equal to an object and let's just do

50
00:03:25,560 --> 00:03:29,610
the same thing like we did with user token where essentially.

51
00:03:30,710 --> 00:03:31,700
If we take a look.

52
00:03:32,590 --> 00:03:35,350
Where it was, where it was, I think it was an off controller.

53
00:03:35,680 --> 00:03:40,120
I was looking for these properties, the name user I.D., I don't know.

54
00:03:40,660 --> 00:03:45,880
So what I'm going to do here, I'm just going to copy this and then copy and paste.

55
00:03:46,330 --> 00:03:52,150
And here we just need to change it around where it's not going to be in the user.

56
00:03:52,150 --> 00:03:53,230
It's going to be in the payload.

57
00:03:53,560 --> 00:03:55,780
Now, if you want, you can also do structure here.

58
00:03:56,050 --> 00:04:02,140
That's also an option where you can simply go with name, user I.D. and roll.

59
00:04:02,290 --> 00:04:04,480
So these are three things that I'm looking for.

60
00:04:05,080 --> 00:04:06,940
I'm will just pass it along.

61
00:04:07,390 --> 00:04:12,760
Say that name is equal to name URLs equal to roll and user I.D. is equal to years, right?

62
00:04:13,180 --> 00:04:14,800
That's really your option.

63
00:04:14,800 --> 00:04:15,820
How you want to set it up.

64
00:04:16,360 --> 00:04:17,529
Going to go with roll.

65
00:04:17,920 --> 00:04:24,420
So now on request object, I'm going to have my user, which is going to be very useful when we were

66
00:04:24,430 --> 00:04:30,220
going to get the single user when we want to check the roll, which we're going to do in the next video

67
00:04:30,550 --> 00:04:32,230
and all that cool stuff.

68
00:04:32,650 --> 00:04:36,850
So last thing I want to do in this video go to off controller.

69
00:04:38,170 --> 00:04:40,270
Sorry, user controller, my bad.

70
00:04:40,660 --> 00:04:44,560
So in the user controller now if you want, you can do it here.

71
00:04:45,250 --> 00:04:46,300
It's kind of the same thing.

72
00:04:46,600 --> 00:04:50,920
I just want to log the user on request just so I can see that it exists.

73
00:04:50,920 --> 00:04:58,480
So Iraq, that user on again, navigate back to the postman or make a request.

74
00:04:58,990 --> 00:05:01,870
And voila, I have my John here.

75
00:05:02,260 --> 00:05:05,550
I'm named John User I.D. and you can read the rest.

76
00:05:05,560 --> 00:05:14,520
And if you can see same thing, we have successfully set up our first authentication level for bejust

77
00:05:14,770 --> 00:05:18,910
authenticate the users with our user exist.

78
00:05:19,420 --> 00:05:22,960
Our next step is actually to check for the admin.

79
00:05:23,230 --> 00:05:31,710
There's, like I said, some routes OK that all users is going to be restricted to only the admins.

