1
00:00:00,550 --> 00:00:01,090
Wonderful.

2
00:00:01,420 --> 00:00:03,580
We can authenticate our user.

3
00:00:04,059 --> 00:00:07,810
So now let's work on authorizing the permissions.

4
00:00:08,380 --> 00:00:13,630
And I want to start from the very, very scratch where I'm just going to create a function.

5
00:00:14,110 --> 00:00:18,180
And technically, if you want, you can set up a separate middleware file.

6
00:00:18,190 --> 00:00:24,100
But in my case, I'm going to do it in the same one just so I don't have to deal with requiring all

7
00:00:24,100 --> 00:00:24,370
that.

8
00:00:24,760 --> 00:00:26,530
So I'm going to go here with authorized.

9
00:00:27,690 --> 00:00:29,880
Authorize and permissions.

10
00:00:30,480 --> 00:00:37,860
That's going to be my middleware missions over here, and eventually we'll look for arguments, but

11
00:00:37,860 --> 00:00:38,490
not for now.

12
00:00:38,610 --> 00:00:46,110
We'll just Hakone in the first video, and let's just start with log and we're going to be looking for

13
00:00:46,110 --> 00:00:46,980
some kind of text.

14
00:00:47,190 --> 00:00:50,940
And I'm just going to say I've been around now.

15
00:00:51,480 --> 00:00:53,210
I will need a few things here.

16
00:00:53,220 --> 00:00:55,230
I'll need a rock rise.

17
00:00:55,440 --> 00:00:59,340
And now eventually we'll return a function from this function.

18
00:00:59,340 --> 00:01:02,400
But let's not get carried away for now.

19
00:01:02,400 --> 00:01:05,970
I just want to go next because I do want to pass this to the next middleware.

20
00:01:06,270 --> 00:01:12,570
So if we're successful, if it is an admin, when we'll pass it on to the next round, if not, then

21
00:01:12,570 --> 00:01:13,800
we'll throw an error.

22
00:01:14,280 --> 00:01:17,340
And for the time being, I just want to see whether everything works.

23
00:01:17,340 --> 00:01:25,020
So go with authorized permissions run and we want to navigate to our user route, I believe so.

24
00:01:25,020 --> 00:01:30,540
We're going to go here, user route and notice where we're getting the authenticate user.

25
00:01:30,930 --> 00:01:34,380
I also want to look for authorized permissions.

26
00:01:34,680 --> 00:01:39,090
And like I said, eventually we will pass some arguments, but not for now.

27
00:01:39,480 --> 00:01:44,850
Now I just want to go to get all users, since that's the route where I want to implement.

28
00:01:45,180 --> 00:01:47,820
And the placement here is very, very important.

29
00:01:48,270 --> 00:01:55,500
We want to first authenticate the user and only then we want to check for the admin again.

30
00:01:55,500 --> 00:02:01,620
Let me repeat, we first want to authenticate the user and only then will check for alignment because

31
00:02:02,160 --> 00:02:09,660
in the authorized permissions in this middleware right away, access that right doc user, and we'll

32
00:02:09,660 --> 00:02:11,070
just check for URL.

33
00:02:11,370 --> 00:02:12,840
I got very, very important.

34
00:02:13,290 --> 00:02:16,680
So the way we set it up, we have multiple middleware.

35
00:02:17,430 --> 00:02:23,430
Either you can set up array or you can just add a comma here and you can say authorized permissions.

36
00:02:23,730 --> 00:02:27,120
I'll let me send them one more time, and I just want to see this console.log.

37
00:02:27,150 --> 00:02:29,970
I just want to see that everything works very adamant around.

38
00:02:30,480 --> 00:02:35,640
So let's go here to get all users again at this point doesn't really matter what you have.

39
00:02:36,150 --> 00:02:37,680
I think in my case, I have John.

40
00:02:37,980 --> 00:02:38,910
So let me send it.

41
00:02:39,300 --> 00:02:44,370
And if you see in the council admin route provided we can proceed to the next step.

42
00:02:44,730 --> 00:02:45,760
What is the next step?

43
00:02:45,780 --> 00:02:47,130
Well, in first video?

44
00:02:47,400 --> 00:02:50,160
Well, just hard code will simply say, Hey.

45
00:02:51,090 --> 00:02:58,580
If the role is admin on a record user, awesome when we proceed to the rollout, what is the about?

46
00:02:58,590 --> 00:03:00,310
Well, this guy's got all users.

47
00:03:00,330 --> 00:03:02,730
If not, then we'll throw error.

48
00:03:02,790 --> 00:03:03,450
What error?

49
00:03:03,780 --> 00:03:08,970
Well, we haven't created that one yet, because that is not on authenticated.

50
00:03:09,540 --> 00:03:11,880
Remember, unauthenticated is 401.

51
00:03:12,420 --> 00:03:19,430
If we take a look at the errors, this one is for a one we want to do right now is four or three where

52
00:03:19,440 --> 00:03:21,180
the access is forbidden.

53
00:03:21,540 --> 00:03:28,050
So first, let's start very basic where we'll just go here in the function.

54
00:03:28,500 --> 00:03:33,930
And I'll say if rec user, since I have access to it, that's the whole point.

55
00:03:34,500 --> 00:03:38,190
Since this is the second middleware, I already have access to this one.

56
00:03:38,700 --> 00:03:46,650
So I'll say here, if rect user role is not equal to admin, then I'll throw the error.

57
00:03:47,040 --> 00:03:49,920
Now, we haven't created the forbidden yet, correct?

58
00:03:50,430 --> 00:03:58,560
So first, we want to go to the errors in there or create a new file, and I'm going to go for an authorized.

59
00:03:59,590 --> 00:04:04,450
Right, Jess, we want to take the on authenticated code.

60
00:04:05,350 --> 00:04:11,800
Copy and paste here, and then we'll still look for custom API, so that's our main class.

61
00:04:12,220 --> 00:04:14,560
We'll still do the same thing, but.

62
00:04:15,540 --> 00:04:18,810
In this case, it's going to be called on authorized.

63
00:04:19,860 --> 00:04:21,630
So let's go here with on.

64
00:04:22,760 --> 00:04:29,870
Authorised like so online, we want to explore that, and then we also want to change the code here.

65
00:04:30,230 --> 00:04:35,780
Like I said, it's not going to be for a one, it's going to be four or three, which is forbidden.

66
00:04:36,230 --> 00:04:37,040
We save it.

67
00:04:37,550 --> 00:04:42,440
And back in the U.S., in the errors, we want to create a new one.

68
00:04:43,280 --> 00:04:45,560
So call this one on authorized.

69
00:04:46,620 --> 00:04:50,120
Let's say on authorized and you know what?

70
00:04:51,020 --> 00:04:54,080
Since I want to be the sample, but I'm just going to copy and paste.

71
00:04:54,560 --> 00:04:58,940
So say on authorized from unauthorized.

72
00:04:59,570 --> 00:05:02,120
So the same file here unauthorized.

73
00:05:02,570 --> 00:05:04,040
And then we want to export.

74
00:05:04,460 --> 00:05:09,530
So now in the authentication middleware, we'll have that error as well.

75
00:05:09,920 --> 00:05:14,150
So in here, I'll say, if it's not a admin, then what I want to do.

76
00:05:14,960 --> 00:05:24,260
I want to throw you and let's just say custom error dot, and I'm looking for unauthorized error.

77
00:05:24,590 --> 00:05:27,350
And here, let's just say on authorized.

78
00:05:29,120 --> 00:05:30,500
To access this route.

79
00:05:30,650 --> 00:05:37,740
And once we have a voice in place now, only the admin, I'm going to be able to see all the users.

80
00:05:37,760 --> 00:05:38,960
Let's test it out.

81
00:05:39,380 --> 00:05:39,950
Let's go back.

82
00:05:39,980 --> 00:05:40,560
Let's send it.

83
00:05:40,580 --> 00:05:41,630
Like I said, I logged in.

84
00:05:41,630 --> 00:05:42,260
I was in John.

85
00:05:42,470 --> 00:05:45,590
Sorry, if I go back here and if I log in to Susan.

86
00:05:47,120 --> 00:05:49,670
I should have no access to the rest of the users.

87
00:05:49,970 --> 00:05:52,130
Let me log in, get back my cookie.

88
00:05:52,580 --> 00:05:53,180
Great.

89
00:05:53,420 --> 00:05:59,900
But if I want to see all the users, I should get back unauthorized access to this route, which is

90
00:05:59,900 --> 00:06:00,530
just awesome.

91
00:06:00,830 --> 00:06:09,410
So first, we check for the user in general, whether user exists and then we check whether the user

92
00:06:09,410 --> 00:06:10,250
is admin.

93
00:06:10,520 --> 00:06:18,710
So if I log out, so I'm sure here, if I just send it and if I'll try to get all the users, then I'll

94
00:06:18,710 --> 00:06:20,780
get authentication valid.

95
00:06:21,230 --> 00:06:25,910
And if you see the same responses in the postman, we're moving in the right direction.

96
00:06:26,630 --> 00:06:34,610
The next thing that I want to do is to make this function the authorized permission to accept arguments,

97
00:06:34,970 --> 00:06:36,040
and I'll go over.

98
00:06:36,050 --> 00:06:38,000
Why is that important in next video?

