1
00:00:00,210 --> 00:00:00,690
Beautiful.

2
00:00:01,020 --> 00:00:08,650
And once we can get the current user next, I want to work on update user password functionality and

3
00:00:08,650 --> 00:00:09,630
the steps are following.

4
00:00:09,900 --> 00:00:16,020
First, I want to tell you right from the get go that it's going to be almost identical to a logging

5
00:00:16,020 --> 00:00:16,379
user.

6
00:00:16,560 --> 00:00:21,930
So if you get stuck, feel free to go and take a peek how we set that one up.

7
00:00:22,560 --> 00:00:27,630
First, I want you to add authenticate user middleware to they're out.

8
00:00:27,810 --> 00:00:35,520
We only want authenticated users to access it, and we'll also grab the user ID from that user.

9
00:00:36,240 --> 00:00:42,470
Then we want to check for old password and new password that are going to be coming in in the rock that

10
00:00:42,510 --> 00:00:42,930
body.

11
00:00:43,230 --> 00:00:46,980
If one of them is missing, we'll throw 400 again.

12
00:00:46,980 --> 00:00:51,450
Just my preference that we remember that we'll still get the humongous error.

13
00:00:51,450 --> 00:00:57,330
If one of them is going to be missing, one will look for that user user ID.

14
00:00:57,600 --> 00:01:02,010
So look for user using the user I.D. that is on the right.

15
00:01:02,010 --> 00:01:11,130
That user will check if the old password matches with the password using User CP. Password.

16
00:01:11,640 --> 00:01:18,690
So old password is going to be the one that is currently storing database if no match will go with 401.

17
00:01:19,200 --> 00:01:26,580
So say, hey, invalid credentials and then if everything is geared, we set the user password equal

18
00:01:26,580 --> 00:01:27,570
to a new password.

19
00:01:27,900 --> 00:01:33,540
And at the very, very end, we're going to go here with User Dot Save.

20
00:01:33,690 --> 00:01:40,560
So we'll go with a wait user that save option that also saves our instance.

21
00:01:40,650 --> 00:01:43,140
So let's start working on that.

22
00:01:43,590 --> 00:01:51,300
First, I want to go to user roots and like I said, I want to add my authenticate user in front of

23
00:01:51,300 --> 00:01:53,250
the shroud for two reasons.

24
00:01:53,260 --> 00:01:57,030
First, I only want authenticated users to access it.

25
00:01:57,310 --> 00:01:59,400
That's number one and number two.

26
00:01:59,940 --> 00:02:03,450
I want to get the user that is on record.

27
00:02:03,600 --> 00:02:07,620
Back user will then want to navigate user controller.

28
00:02:08,100 --> 00:02:10,110
They're looking for update user.

29
00:02:10,229 --> 00:02:14,760
And like I said in the record body, or I'm sorry, not update user.

30
00:02:15,090 --> 00:02:15,720
My apologies.

31
00:02:16,260 --> 00:02:17,010
I've been double checked.

32
00:02:17,020 --> 00:02:18,510
So this is update user password.

33
00:02:18,510 --> 00:02:20,100
Yes, I misspoke.

34
00:02:20,450 --> 00:02:21,430
Let me take a look.

35
00:02:21,450 --> 00:02:21,780
Yep.

36
00:02:21,990 --> 00:02:27,420
Over here, I want to check whether there is an old password in your passwords or old password.

37
00:02:28,590 --> 00:02:32,820
As well as in new password, both of them are coming in in the Iraq body.

38
00:02:33,300 --> 00:02:37,200
Let's say that one, then let's throw an error if one of them is missing.

39
00:02:37,380 --> 00:02:44,190
And just to speed this up, we're going to go, you're my controller and I'm just checking here whether

40
00:02:44,190 --> 00:02:46,890
one of them is missing or animals that are there.

41
00:02:47,280 --> 00:02:51,300
Now, of course, I just need to change your values that I'm checking for.

42
00:02:51,720 --> 00:02:53,190
It's not going to be old password.

43
00:02:53,370 --> 00:02:53,820
Well, I'm sorry.

44
00:02:53,820 --> 00:02:54,840
It's not going to be email.

45
00:02:55,410 --> 00:02:59,340
It's going to be old password and your password and your password.

46
00:02:59,830 --> 00:03:03,900
And as far as the error message, I'm just going to say, please provide both.

47
00:03:05,600 --> 00:03:06,860
Oh, flowers.

48
00:03:07,850 --> 00:03:09,800
You want to be a bit more explicit.

49
00:03:10,250 --> 00:03:11,210
That's really up to you.

50
00:03:12,130 --> 00:03:16,170
When we want to get the user using find one.

51
00:03:16,270 --> 00:03:21,150
So let's say it costs user is equal to wait, wait.

52
00:03:22,240 --> 00:03:25,150
And we're looking for users to find one.

53
00:03:25,960 --> 00:03:30,880
And I want to look for daddy, I'll say where the ID matches that.

54
00:03:31,810 --> 00:03:41,890
Of the record that user user I.D. And in this case, I'm not going to check whether user exists because

55
00:03:41,890 --> 00:03:44,470
there is no functionality for us to move the user.

56
00:03:45,510 --> 00:03:46,410
And if.

57
00:03:47,210 --> 00:03:53,690
We can pass authenticate user that means Duncan exists, and that also means that in that token, there

58
00:03:53,690 --> 00:03:55,980
should be a user with a valid.

59
00:03:56,780 --> 00:03:59,390
Now what I do want to check for, though, is the password.

60
00:03:59,780 --> 00:04:02,060
I'll say Konst is password correct?

61
00:04:02,450 --> 00:04:02,810
Yes.

62
00:04:02,810 --> 00:04:03,800
Password correct.

63
00:04:04,100 --> 00:04:07,160
And this is again coming from a v long in around.

64
00:04:07,170 --> 00:04:07,850
So await.

65
00:04:08,780 --> 00:04:12,980
And we're going to go with the user and remember instance method compare.

66
00:04:13,970 --> 00:04:17,209
Password and we just want to pass in the old password.

67
00:04:17,660 --> 00:04:19,640
It's very important we're not passing in the new one.

68
00:04:20,060 --> 00:04:22,070
Now if there is some kind of issue.

69
00:04:22,430 --> 00:04:25,970
So say if and is password correct?

70
00:04:26,210 --> 00:04:29,930
If that's not the case, then again would go throw new.

71
00:04:31,130 --> 00:04:32,060
Custom error.

72
00:04:32,950 --> 00:04:36,400
Than that, and we're looking for unauthenticated.

73
00:04:36,640 --> 00:04:42,760
So say, hey, you're trying to do something that you're not allowed since your password doesn't match.

74
00:04:43,240 --> 00:04:45,850
So let's say here invalid.

75
00:04:46,820 --> 00:04:54,080
Credentials, credentials, and then we want to finally say about passwords, so if we pass.

76
00:04:55,080 --> 00:05:00,030
Both of these checks, then we can simply say, user that password, so we have access through the years

77
00:05:00,150 --> 00:05:02,280
and whatever is the password value.

78
00:05:02,520 --> 00:05:09,480
While we want to set it equal to a new password and then we can just save the user so that we'll save

79
00:05:09,480 --> 00:05:11,280
that user with a new password.

80
00:05:11,700 --> 00:05:18,300
Now we're still going to use await users, for instance, and we'll go with a save method.

81
00:05:18,450 --> 00:05:19,500
We save it here.

82
00:05:20,010 --> 00:05:25,410
Now, if you're wondering about the save method, essentially it's a method we can use on a document

83
00:05:25,950 --> 00:05:33,150
and it provides another option for us when we want to create new or update existing document.

84
00:05:33,810 --> 00:05:38,340
And they're going to be some instances where we'll go with this method instead.

85
00:05:39,030 --> 00:05:42,600
Now, there's nothing wrong with using methods available on the model.

86
00:05:43,200 --> 00:05:51,480
So think, create, find one and update and etc. It's just a nice alternative that we will utilize from

87
00:05:51,480 --> 00:05:52,110
time to time.

88
00:05:52,740 --> 00:05:59,250
If you want to find out more on the method, just navigate humongous docs and utilize of the search

89
00:05:59,250 --> 00:05:59,520
bar.

90
00:05:59,940 --> 00:06:05,990
And now we want to send back some kind of response or has that status will go with status codes say

91
00:06:06,000 --> 00:06:06,570
OK.

92
00:06:07,230 --> 00:06:14,370
And just like some other requests, Front is really not going to be looking for any kind of value.

93
00:06:15,090 --> 00:06:16,680
Once front end, we'll see that.

94
00:06:16,710 --> 00:06:18,910
Yep, everything is good to go.

95
00:06:19,620 --> 00:06:21,810
Am just going to display some kind of message now.

96
00:06:21,810 --> 00:06:25,740
If you want to be a bit more helpful to the front end, you can pass here the message.

97
00:06:26,190 --> 00:06:31,350
But again, if there is an error, yes, there is going to be one root at the front end is going to

98
00:06:31,350 --> 00:06:31,650
take.

99
00:06:31,720 --> 00:06:34,710
If there is success, then we'll do something else.

100
00:06:34,920 --> 00:06:40,830
But in most cases, it's not really going to depend on the message that you're sending here or say here,

101
00:06:40,830 --> 00:06:41,430
success.

102
00:06:42,330 --> 00:06:44,310
And let's just say password.

103
00:06:46,050 --> 00:06:46,680
Updated.

104
00:06:47,310 --> 00:06:48,000
All right.

105
00:06:48,610 --> 00:06:52,410
Let's take this baby for a test drive.

106
00:06:52,920 --> 00:06:58,200
So I want to navigate back to my post, man, I guess, right?

107
00:06:58,680 --> 00:07:03,930
So I'm going to navigate there, and let's just try it out with Susan, I think.

108
00:07:04,020 --> 00:07:07,020
So let me log in, log in two years there.

109
00:07:08,060 --> 00:07:11,480
And in this case, I'm going to go with Susan.

110
00:07:12,160 --> 00:07:16,220
So email is equal to Susan.

111
00:07:17,490 --> 00:07:18,990
At gmail.com.

112
00:07:20,320 --> 00:07:21,790
And then password.

113
00:07:22,270 --> 00:07:23,260
It's going to be secret.

114
00:07:24,080 --> 00:07:25,440
So let's go here with secret.

115
00:07:25,460 --> 00:07:26,870
Let's log in to Susan.

116
00:07:27,090 --> 00:07:28,610
Yeah, we're good to go.

117
00:07:29,090 --> 00:07:31,070
Now let's update the password.

118
00:07:31,670 --> 00:07:39,140
So update user password here and I'm going to go with old password secret and then new secret.

119
00:07:39,410 --> 00:07:40,890
So that's going to be my new password.

120
00:07:40,910 --> 00:07:41,930
Let's send it.

121
00:07:42,440 --> 00:07:44,180
Yep, we're good to go.

122
00:07:44,520 --> 00:07:49,550
So now if I tried to log in as Susan in secret, I should get back the error.

123
00:07:50,120 --> 00:07:51,480
Invalid credentials?

124
00:07:51,560 --> 00:07:51,950
Awesome.

125
00:07:52,490 --> 00:07:57,260
That means that I need to change this around and I'm going to go with new secret.

126
00:07:57,620 --> 00:07:58,520
And lastly.

127
00:07:59,500 --> 00:08:06,370
I want to also showcase that we're still hashing the passwords, so if I go back to my MongoDB, you'll

128
00:08:06,370 --> 00:08:09,940
notice that I'm not storing a string of new secret.

129
00:08:10,570 --> 00:08:12,980
So even though we updated the password?

130
00:08:13,000 --> 00:08:13,870
Check it out.

131
00:08:13,870 --> 00:08:15,040
It is still hashed.

132
00:08:15,520 --> 00:08:15,910
Why?

133
00:08:15,910 --> 00:08:16,690
It's still hashed.

134
00:08:16,870 --> 00:08:18,940
Well, because we go with that save.

135
00:08:19,510 --> 00:08:19,990
Correct.

136
00:08:20,170 --> 00:08:23,620
So we're going user that saving method.

137
00:08:24,160 --> 00:08:28,120
And what that does, it invokes what invokes this guy.

138
00:08:28,700 --> 00:08:35,289
We preach save hook, where again we use decrypt and we hash the password go.

139
00:08:35,380 --> 00:08:36,220
Does that password?

140
00:08:36,580 --> 00:08:39,190
And we hashed hopefully it that is clear.

141
00:08:39,669 --> 00:08:42,220
And now we can move on to the next step.

