1
00:00:00,240 --> 00:00:00,810
Wonderful.

2
00:00:01,230 --> 00:00:08,910
So our basic set up works really well, where we check for the user role, if it is an admin of AI and

3
00:00:08,910 --> 00:00:17,070
we proceed to the next middleware, which is currently our all user out, if not, then we throw our

4
00:00:17,340 --> 00:00:19,980
on authorized error, which is four or three.

5
00:00:20,040 --> 00:00:29,730
But as our applications grow bigger, we need to understand one thing we're not always going to be admin

6
00:00:30,300 --> 00:00:31,170
and user.

7
00:00:31,920 --> 00:00:33,720
There's going to be multiple roles.

8
00:00:34,380 --> 00:00:43,290
And if we want to make our authorized permission function more dynamic, essentially, if in the user

9
00:00:43,290 --> 00:00:49,980
accounts, I want to specifically say, well, which users are going to be authorized to that specific

10
00:00:49,980 --> 00:00:57,540
root meaning, which users with certain roles when we want to pass in the arguments correct what essentially?

11
00:00:58,500 --> 00:01:04,950
I'm going to invoke this function in this case, and in there, I'll pass in what user is allowed,

12
00:01:05,310 --> 00:01:10,710
whether that is an admin, whether that is an owner and stuff along those lines.

13
00:01:11,220 --> 00:01:11,610
Correct.

14
00:01:12,150 --> 00:01:13,560
Now here's the problem, though.

15
00:01:13,950 --> 00:01:17,550
Now I'm invoking this function right there.

16
00:01:18,030 --> 00:01:20,800
So if you want to see what's going to happen?

17
00:01:20,820 --> 00:01:23,870
Well, let's go back and don't worry that we don't have the owner.

18
00:01:24,430 --> 00:01:27,060
Again, this is just to showcase what's going to happen.

19
00:01:27,330 --> 00:01:29,280
First of all, get right away.

20
00:01:29,580 --> 00:01:31,320
Authorized permissions.

21
00:01:31,560 --> 00:01:33,450
Well, you know, this was my mistake.

22
00:01:33,460 --> 00:01:33,810
Sorry?

23
00:01:34,050 --> 00:01:35,040
Let me invoke it.

24
00:01:35,430 --> 00:01:41,970
But we'll still get the error where we get roll of undefined because what we need to keep in mind that

25
00:01:42,360 --> 00:01:46,560
once I hear these arguments, that's it.

26
00:01:47,040 --> 00:01:48,420
I invoke dysfunction.

27
00:01:48,660 --> 00:01:51,180
I invoke the authorized permission.

28
00:01:51,480 --> 00:01:58,350
So it's not like I'm getting the Iraq War as an next when express hits the road.

29
00:01:58,600 --> 00:02:02,010
No, we right away and look dysfunctional, and this is very, very important.

30
00:02:02,370 --> 00:02:07,260
And this is also the question that I'm getting in my React course, where you on quick handlers and

31
00:02:07,260 --> 00:02:08,610
then you invoke the function.

32
00:02:08,789 --> 00:02:11,020
Students are asking, Well, what's the problem?

33
00:02:11,039 --> 00:02:18,450
Why do we have to refactor our code and hopefully get this where in this case, it's not like with authenticate

34
00:02:18,450 --> 00:02:24,720
user where we're getting the reference of the function and then we invoke it when we hit the road in

35
00:02:24,720 --> 00:02:27,270
this case, since I have to pass in these arguments.

36
00:02:27,570 --> 00:02:30,960
We invoke this right away when the application starts.

37
00:02:31,320 --> 00:02:36,930
And just the shock is that if I'm going to go back to authentication, I'll remove the code since we'll

38
00:02:36,930 --> 00:02:39,960
have to create from scratch anyway or here.

39
00:02:40,320 --> 00:02:46,740
And if I'll just log my roles and the way I'll do that, I'm just going to use a rest operator.

40
00:02:47,220 --> 00:02:49,380
So we'll go here with three dots, then the rest.

41
00:02:49,410 --> 00:02:55,230
So essentially, this is going to collect everything that I'm passing in here, which is going to be

42
00:02:55,230 --> 00:02:56,580
an argument and a user.

43
00:02:57,420 --> 00:03:04,770
And if I just log the arrest one like so you'll see that we get this result right away.

44
00:03:05,140 --> 00:03:10,680
We'll still get an error because again, Express is looking for a callback function.

45
00:03:10,920 --> 00:03:13,620
And what we do here, we are right away, invoke it.

46
00:03:13,650 --> 00:03:19,320
But if you scroll up, you should see in the console admin and an order.

47
00:03:19,710 --> 00:03:22,890
So we're correctly passing here these two values.

48
00:03:23,400 --> 00:03:27,330
And eventually, there will be a functionality that checks for those roles.

49
00:03:27,330 --> 00:03:31,950
And only if the user role matches one of them, then we're good to go.

50
00:03:32,700 --> 00:03:37,770
But now we have to handle this callback thing because Express is yelling at us.

51
00:03:38,370 --> 00:03:41,070
Express is like, Hey, listen, I need a callback function.

52
00:03:41,400 --> 00:03:43,830
So how can we fix this mess?

53
00:03:44,190 --> 00:03:51,330
Well, from this authorized permission, since we invoke there and then we want to return a function.

54
00:03:52,080 --> 00:03:56,910
And then that function will have access to rec rise and next.

55
00:03:57,180 --> 00:03:58,020
So let's try it out.

56
00:03:58,440 --> 00:03:59,530
Let's go back over here.

57
00:03:59,550 --> 00:04:05,670
We'll still look for all the arguments with an operator that still stays the same.

58
00:04:06,420 --> 00:04:13,260
What do we want to do from this function is to return another function so that we reverse function will

59
00:04:13,350 --> 00:04:16,709
be used as a callback here for Express.

60
00:04:17,070 --> 00:04:21,959
I know I'm repeating the same thing probably 20000 times, but this is extremely important.

61
00:04:22,380 --> 00:04:27,460
And also, I keep getting the same questions from the students in multiple courses about this issue.

62
00:04:27,480 --> 00:04:33,990
So I'm thinking that I really need to spend more time on this one and maybe be a little bit more annoying

63
00:04:33,990 --> 00:04:34,650
than usual.

64
00:04:35,100 --> 00:04:38,940
So let's go here with Rick Rose and next.

65
00:04:39,390 --> 00:04:44,700
So this is a function that we're returning as a callback now and now in here.

66
00:04:45,180 --> 00:04:48,960
As far as the functionality, I want to set up that if condition.

67
00:04:49,590 --> 00:04:52,410
And if you want, you can keep it as a rest.

68
00:04:52,980 --> 00:04:55,200
But I'm just going to rename it as rose again.

69
00:04:55,200 --> 00:04:58,230
The more important one is this one, the arrest operator.

70
00:04:58,530 --> 00:05:02,190
So this is going to collect all these values that we're passing in.

71
00:05:03,070 --> 00:05:11,680
And not I'm just going to check if the array includes the roll rock user has or here in the record user

72
00:05:11,700 --> 00:05:16,430
because we still have access to it, then we will proceed to the next one.

73
00:05:16,450 --> 00:05:19,690
If not, then we'll throw that unauthorized.

74
00:05:19,690 --> 00:05:22,870
Or I was not going to look like, I'll say, if roles.

75
00:05:22,930 --> 00:05:24,440
So that's my area over here.

76
00:05:25,000 --> 00:05:25,500
Grow up.

77
00:05:25,510 --> 00:05:26,620
This is the same, right?

78
00:05:26,660 --> 00:05:29,620
So I can use includes methadone it.

79
00:05:29,980 --> 00:05:38,530
I can say if it does not include the role that is on the user object so that user and role van will

80
00:05:38,530 --> 00:05:39,250
throw the error.

81
00:05:39,550 --> 00:05:40,160
What error?

82
00:05:40,390 --> 00:05:41,260
Well, the same one.

83
00:05:41,260 --> 00:05:45,340
So say it all new and not custom error dot.

84
00:05:45,550 --> 00:05:48,610
And then we're looking for unauthorized error.

85
00:05:48,640 --> 00:05:49,960
And let's do the same thing.

86
00:05:50,320 --> 00:05:50,950
My apologies.

87
00:05:50,950 --> 00:05:53,950
I probably shouldn't have deleted it.

88
00:05:53,950 --> 00:06:01,090
But hey, it is what it is authorized to access worse or out.

89
00:06:01,390 --> 00:06:02,950
Let's save it here.

90
00:06:03,370 --> 00:06:05,800
And then I also want to set up next, correct?

91
00:06:06,100 --> 00:06:11,590
So we're returning this function and then right outside the f block.

92
00:06:11,860 --> 00:06:14,530
We're going to go next and then I'll work it.

93
00:06:14,860 --> 00:06:15,920
So now what happens?

94
00:06:16,180 --> 00:06:17,800
We'll check for drawls.

95
00:06:18,840 --> 00:06:27,390
If one of the rolls matches to whatever, we have, 40 user awesome user will have access to the data

96
00:06:27,660 --> 00:06:32,280
to the root, if not valid, will kick back with unauthorized error.

97
00:06:32,580 --> 00:06:40,800
And like I said, the whole point for this refactoring was so we can set up here whatever users we want.

98
00:06:41,370 --> 00:06:46,030
So eventually we might have some world, not just admin, not just user.

99
00:06:46,080 --> 00:06:49,350
Maybe there is going to be some other roles like, for example, owner.

100
00:06:49,830 --> 00:06:55,330
So in this case, again, it's not really going to matter because we don't have the owner, but just

101
00:06:55,330 --> 00:06:58,160
to showcase why we would want to refactor the code.

102
00:06:58,170 --> 00:06:59,850
I added this owner as well.

103
00:07:00,240 --> 00:07:01,880
So now let's go back to the post, man.

104
00:07:01,890 --> 00:07:07,920
I do want to log in as John first, just to show you that we can access the rout so I can see all the

105
00:07:07,920 --> 00:07:08,390
users.

106
00:07:08,400 --> 00:07:08,880
Why?

107
00:07:09,090 --> 00:07:11,550
Well, because I'm an admin now.

108
00:07:11,580 --> 00:07:16,530
If I walk out or, you know, talking, just log in right away and doesn't really matter.

109
00:07:17,190 --> 00:07:18,420
I just say Susan here.

110
00:07:18,810 --> 00:07:19,950
Secret, awesome.

111
00:07:20,250 --> 00:07:23,160
And if I'll try to get all the users with Susan?

112
00:07:23,430 --> 00:07:24,630
Nope, no.

113
00:07:24,630 --> 00:07:25,050
Can do.

114
00:07:25,350 --> 00:07:32,760
Now, of course, if I go back to the user Route 75, I say, yeah, not only admin, but also a user

115
00:07:32,760 --> 00:07:35,890
can do that well, right, and we should be successful.

116
00:07:36,330 --> 00:07:43,080
So hopefully it is clear why we have to return a function because we invoke authorized permissions right

117
00:07:43,080 --> 00:07:48,750
when we start a program, and that's why we have to return a function from it.

118
00:07:49,170 --> 00:07:52,920
And then we just check whatever roles are being passed in.

119
00:07:53,160 --> 00:07:54,250
So we use rest.

120
00:07:54,270 --> 00:07:54,840
Operator.

121
00:07:54,840 --> 00:08:00,510
We collect all the values and then we return the function, which is going to be used as that callback

122
00:08:00,510 --> 00:08:00,870
function.

123
00:08:01,290 --> 00:08:09,180
And then I just check whether the user role that is currently trying to access the root matches, any

124
00:08:09,180 --> 00:08:15,300
of the roles that I have in the right, if it doesn't, then we have four or three if everything is

125
00:08:15,300 --> 00:08:15,720
correct.

126
00:08:15,900 --> 00:08:20,370
We proceed to the next middleware, which is our guest.

127
00:08:20,380 --> 00:08:21,690
Get all users are out.

