1
00:00:00,270 --> 00:00:00,810
Wonderful.

2
00:00:01,290 --> 00:00:08,220
And once we're done setting up our authorized permissions function, now I want to work, I'm probably

3
00:00:08,220 --> 00:00:13,720
the easiest route ever, but I just want to give you a little intro.

4
00:00:13,740 --> 00:00:15,690
Why is it necessary to have this drug?

5
00:00:15,690 --> 00:00:15,990
Why?

6
00:00:15,990 --> 00:00:22,410
Essentially, it is useful and you see on your front end, you'll be refreshing the application, correct?

7
00:00:22,980 --> 00:00:30,300
Whether that is when the user just gets there, or maybe for some reason user navigates, I don't know,

8
00:00:30,330 --> 00:00:32,640
using the URL bar or something like that.

9
00:00:33,240 --> 00:00:36,420
And therefore it's very useful to have a route that quickly checks.

10
00:00:37,420 --> 00:00:38,770
Well, is there user?

11
00:00:39,220 --> 00:00:41,860
And if it is a user, what's the name?

12
00:00:42,160 --> 00:00:44,440
What is the role and all that cool stuff?

13
00:00:44,830 --> 00:00:52,300
So as you're looking at this application, notice that the first thing it does once we refresh it makes

14
00:00:52,300 --> 00:00:53,350
this get root.

15
00:00:53,770 --> 00:00:55,240
And what is the URL?

16
00:00:55,370 --> 00:01:02,110
Well, are ever and one users and then show me and essentially it gets back for one.

17
00:01:02,440 --> 00:01:05,110
And that means that there is no user currently.

18
00:01:05,110 --> 00:01:10,690
But if I change my mind, if I go with my friend, Mr. John Logan.

19
00:01:12,120 --> 00:01:17,310
And if I type in my password, I should get back my user.

20
00:01:17,560 --> 00:01:18,410
I'm older, John.

21
00:01:18,630 --> 00:01:19,500
Yada yada yada.

22
00:01:19,830 --> 00:01:22,980
And if we refresh right now, we are successful.

23
00:01:23,280 --> 00:01:26,100
So essentially we give back the correct user.

24
00:01:26,400 --> 00:01:33,150
So if I go here to the network now again, the first thing that we do is make a request to the show

25
00:01:33,150 --> 00:01:33,360
me.

26
00:01:33,690 --> 00:01:35,430
And in this case, it is successful.

27
00:01:35,820 --> 00:01:39,270
It is 200 and we get right away the data.

28
00:01:39,570 --> 00:01:45,370
Now why it's so useful because it doesn't even query the database how we can do that.

29
00:01:45,390 --> 00:01:47,790
Well, we take a look at the authentication.

30
00:01:48,390 --> 00:01:49,260
What is over here?

31
00:01:50,040 --> 00:01:50,760
It's our user.

32
00:01:51,060 --> 00:01:51,420
Correct.

33
00:01:51,720 --> 00:01:58,980
So as far as show me, I can just quickly say, Hey, authenticate this without using authenticate user

34
00:01:59,400 --> 00:02:03,360
and then grabbing the properties that we get back from the cookie.

35
00:02:03,810 --> 00:02:09,509
If the user is there, essentially if the token is still valid around beautiful, well, this is my

36
00:02:09,509 --> 00:02:09,900
user.

37
00:02:10,289 --> 00:02:12,930
That's the name, that's the role and all that stuff.

38
00:02:12,930 --> 00:02:15,480
So I can right away showcase on a frontend.

39
00:02:15,990 --> 00:02:23,200
If the user has logged in, if the token has expired, then we'll throw back the error and then frontend.

40
00:02:23,430 --> 00:02:24,600
OK, there is another user.

41
00:02:24,600 --> 00:02:27,010
I don't have to worry about that functionality.

42
00:02:27,030 --> 00:02:27,990
How do we set that up?

43
00:02:28,020 --> 00:02:36,210
Well, first we navigate to use the roots and what do we need to use authenticate user middleware,

44
00:02:36,210 --> 00:02:36,600
correct?

45
00:02:36,600 --> 00:02:38,760
Because that's the one that gets us.

46
00:02:39,030 --> 00:02:40,710
We request that user.

47
00:02:41,010 --> 00:02:44,190
So let's go here, authenticate user.

48
00:02:44,220 --> 00:02:45,930
Now, I don't want to add permissions.

49
00:02:46,380 --> 00:02:47,730
This is for all of them.

50
00:02:47,910 --> 00:02:51,000
This is for admin, user, owner or whatever.

51
00:02:51,600 --> 00:02:55,110
And then we want to go back to our roots.

52
00:02:55,860 --> 00:02:57,870
Sorry, controllers more precisely.

53
00:02:58,110 --> 00:02:59,460
Or use your controller.

54
00:02:59,670 --> 00:03:02,190
Where is the current user right here?

55
00:03:02,490 --> 00:03:04,290
Where is the user sitting?

56
00:03:04,590 --> 00:03:13,350
It's sitting on a request, so I can simply say here, read that status, status or passing status codes.

57
00:03:14,340 --> 00:03:15,150
Say OK.

58
00:03:15,390 --> 00:03:22,410
And then as far as the JSON in my cache, I'll set up the user object and I'll set it equal to record

59
00:03:22,440 --> 00:03:22,740
user.

60
00:03:22,740 --> 00:03:24,570
Can you send direct redirect user?

61
00:03:24,570 --> 00:03:25,260
Yes, of course.

62
00:03:25,380 --> 00:03:26,640
It's just on my frontend.

63
00:03:26,640 --> 00:03:32,220
I usually check for the user and then the rest of the properties instead of the entire object that I'm

64
00:03:32,220 --> 00:03:33,150
getting back again.

65
00:03:33,360 --> 00:03:34,560
That is just my preference.

66
00:03:34,570 --> 00:03:41,190
So now if we go back to the postman where we have the current user, if I send without providing any

67
00:03:41,190 --> 00:03:43,230
parameters, that's very, very important.

68
00:03:43,230 --> 00:03:44,190
We're not doing anything.

69
00:03:44,190 --> 00:03:45,300
We're not providing anything.

70
00:03:45,300 --> 00:03:46,770
We don't have to make a post request.

71
00:03:47,130 --> 00:03:51,660
That said, I get back that I have to Susan if log in is John.

72
00:03:52,050 --> 00:03:52,710
What do you think?

73
00:03:52,710 --> 00:03:53,640
I'll see you over there.

74
00:03:54,240 --> 00:03:55,140
I'll see John.

75
00:03:55,770 --> 00:03:58,440
And there all will be admin.

76
00:03:58,620 --> 00:03:59,880
Hopefully, this makes sense.

77
00:04:00,000 --> 00:04:03,180
Or will you see why it's so cool to have this around?

78
00:04:03,540 --> 00:04:06,750
And hopefully you can see that we are not querying a database.

79
00:04:06,840 --> 00:04:10,790
We are just getting the user that we placed in a token.

80
00:04:10,800 --> 00:04:16,920
And that's why it was very, very important for us to only add the properties and that token that are

81
00:04:16,920 --> 00:04:17,640
not sensitive.

82
00:04:17,730 --> 00:04:22,200
You definitely don't want to send back password this way or anything along those lines.

83
00:04:22,230 --> 00:04:22,770
Notice here.

84
00:04:23,220 --> 00:04:24,390
I just get the name.

85
00:04:24,390 --> 00:04:29,230
I get the user I.D., which is very, very useful for my upcoming request as well as the.

86
00:04:29,520 --> 00:04:30,570
Can you add more stuff?

87
00:04:30,600 --> 00:04:31,560
Yes, of course you can.

88
00:04:31,950 --> 00:04:33,780
So just keep this in mind.

89
00:04:34,090 --> 00:04:36,300
And now we can move on to the next step.

