1
00:00:00,150 --> 00:00:00,630
Beautiful.

2
00:00:01,020 --> 00:00:07,130
We're pretty much done with user roots as well as user controller harm.

3
00:00:07,470 --> 00:00:11,400
There's one last thing that I want to fix.

4
00:00:11,820 --> 00:00:21,840
Not is the simple fact that when it comes to get a single user, actually, if the user has logged in

5
00:00:22,140 --> 00:00:29,340
financially, if the user has the token, the beta user can take a look at the shoes and the user profile

6
00:00:29,820 --> 00:00:32,520
if he or she has access to it.

7
00:00:33,120 --> 00:00:39,810
And that's not what we want and since will use this functionality in the later controller as well.

8
00:00:40,380 --> 00:00:44,650
Right away set up a helper function in the utos for stars.

9
00:00:44,670 --> 00:00:52,170
Let me just showcase that where if I go back and I guess in this case, I'll have to go back first to

10
00:00:52,170 --> 00:01:01,050
a mango, and I just quickly want to set up John as an admin so I can take a look at all the users here.

11
00:01:01,590 --> 00:01:04,410
Let's save that one, let's say.

12
00:01:04,410 --> 00:01:04,920
Update.

13
00:01:05,280 --> 00:01:13,080
OK, now John is a user might as well can change his name back to John, just so it's less confusing.

14
00:01:13,680 --> 00:01:14,160
All right.

15
00:01:14,520 --> 00:01:18,940
Now he is an admin, so he should be able to see all the users.

16
00:01:18,960 --> 00:01:19,260
Yup.

17
00:01:19,560 --> 00:01:24,840
So now let's leave this one, this response, and let's log in as Susan.

18
00:01:25,500 --> 00:01:29,670
So let's say here that Susan is logging in.

19
00:01:30,150 --> 00:01:36,840
OK, and where we have all the users first, let's grab her I.D., which is going to make sense.

20
00:01:37,080 --> 00:01:39,540
You can definitely take a look at her profile.

21
00:01:40,110 --> 00:01:41,490
That's not a problem.

22
00:01:41,860 --> 00:01:44,240
Yeah, that's Susan part.

23
00:01:44,280 --> 00:01:48,870
What I don't want is for Susan to view Peter's profile.

24
00:01:49,560 --> 00:01:58,560
So if I go back to all the users and if I take a look at his I.D. here and set it up in get single user,

25
00:01:59,340 --> 00:02:00,540
I'll be able to do that.

26
00:02:00,870 --> 00:02:02,220
And that's not what I want.

27
00:02:02,610 --> 00:02:03,990
Now how we can fix that?

28
00:02:04,020 --> 00:02:10,289
Well, we'll fix that in the following way where we go back to a single user.

29
00:02:10,680 --> 00:02:17,670
And like I said, we will set up a utils function where it will check for permissions.

30
00:02:18,210 --> 00:02:18,930
We're old fashioned.

31
00:02:18,930 --> 00:02:22,230
Two things will pass in the rec user.

32
00:02:22,620 --> 00:02:28,590
So the one that we're getting from our middleware, authenticate user middleware and then remember on

33
00:02:28,590 --> 00:02:31,710
the resource, we have the ID property now.

34
00:02:31,710 --> 00:02:33,510
In this case, it's going to be underscore.

35
00:02:34,380 --> 00:02:36,840
Once we start creating other resources.

36
00:02:37,230 --> 00:02:44,220
For example, reviews that might be under some other property, meaning we might call this user.

37
00:02:45,060 --> 00:02:51,390
But the idea is the same where this is going to be a I.D that matches the user.

38
00:02:51,810 --> 00:02:56,850
So let's start setting everything up and hopefully in the process, it's going to make more sense.

39
00:02:56,880 --> 00:03:03,270
So first, we want to go to utils and we want to create a new function, and I'm going to call this

40
00:03:03,630 --> 00:03:06,760
check permissions like jazz.

41
00:03:07,260 --> 00:03:10,110
Now this function is going to be looking for two values.

42
00:03:10,230 --> 00:03:18,630
It's going to be looking for the user that is requesting the resource and the second thing for the resource

43
00:03:18,630 --> 00:03:19,500
user ID.

44
00:03:19,770 --> 00:03:24,900
So let's go here and you know, let's start by getting the custom arrow because we'll have to throw

45
00:03:24,900 --> 00:03:26,970
it here, say requir.

46
00:03:27,360 --> 00:03:28,980
And we're looking for error here.

47
00:03:29,580 --> 00:03:31,170
Run back to the function.

48
00:03:31,620 --> 00:03:36,360
Like I said, we're going to go with check permissions, permissions here.

49
00:03:37,020 --> 00:03:44,160
And what I want to look for is the request user, and I'll first console.log just so I can see what

50
00:03:44,160 --> 00:03:44,760
we're getting back.

51
00:03:44,760 --> 00:03:48,720
So request user and that resource.

52
00:03:50,130 --> 00:03:52,850
Resource user I.D..

53
00:03:53,070 --> 00:03:57,600
So those are the two things that this function is going to be looking for, and for the time being,

54
00:03:57,600 --> 00:04:01,650
I want to console.log three things I want to log.

55
00:04:02,750 --> 00:04:08,990
The request, user request user, I want to log the resource.

56
00:04:09,560 --> 00:04:15,010
And I also want to log the type off just because it's very important for us.

57
00:04:15,020 --> 00:04:16,430
So say time off.

58
00:04:17,060 --> 00:04:24,920
And in this case, I'm not looking for a quest user for resource use already and the same or we're here.

59
00:04:25,580 --> 00:04:26,720
So the same deal.

60
00:04:27,320 --> 00:04:30,020
I'll take this guy and I'll copy and paste.

61
00:04:30,050 --> 00:04:31,580
Now we want to explore this.

62
00:04:31,580 --> 00:04:34,430
So say module that exports is equal to you.

63
00:04:34,910 --> 00:04:36,110
Check permissions.

64
00:04:36,560 --> 00:04:37,600
And the same.

65
00:04:37,610 --> 00:04:40,150
That's where we go to index jazz.

66
00:04:40,880 --> 00:04:45,500
Copy and paste it in for check permissions.

67
00:04:46,450 --> 00:04:47,200
Permissions.

68
00:04:48,190 --> 00:04:50,710
And then we just add here that.

69
00:04:51,690 --> 00:04:58,230
So say we're looking for check permissions and we want to export, so check permissions when we want

70
00:04:58,230 --> 00:05:00,960
to jump back to our user controller.

71
00:05:01,790 --> 00:05:03,770
I've already attached cookies response.

72
00:05:03,780 --> 00:05:04,530
Beautiful.

73
00:05:04,980 --> 00:05:11,130
Let's go for check permissions and where we're getting the single user right after.

74
00:05:11,610 --> 00:05:15,630
If the user doesn't exist, let's invoke check permissions.

75
00:05:16,200 --> 00:05:22,560
And like I said, I want to pass in two things I want to pass in the user object that is on the request.

76
00:05:22,920 --> 00:05:27,900
So we go here with Rick and user, so that user.

77
00:05:28,260 --> 00:05:33,210
And the second thing is the I.D. property on a resource.

78
00:05:33,210 --> 00:05:36,750
Again, in this case, it is a user resource.

79
00:05:37,380 --> 00:05:38,340
So where is the I.D?

80
00:05:38,370 --> 00:05:39,570
It is on the score ID.

81
00:05:40,200 --> 00:05:47,430
Once we start creating other resources, a.k.a. reviews, the property might be different, but it will

82
00:05:47,430 --> 00:05:49,440
still point to a user.

83
00:05:49,560 --> 00:05:51,000
Hopefully, that makes sense.

84
00:05:51,360 --> 00:05:59,580
So in this case, let's go with user dot and then underscore I.D. We share it, and let's make the request

85
00:05:59,580 --> 00:06:00,180
one more time.

86
00:06:00,480 --> 00:06:02,970
So let's jump to a postman.

87
00:06:03,960 --> 00:06:07,020
That Mr. Branch of them otherwise.

88
00:06:08,170 --> 00:06:13,120
Might turn into a mess one day, so let's go here, I can still see the user.

89
00:06:13,480 --> 00:06:14,270
OK, that's great.

90
00:06:14,290 --> 00:06:15,520
We'll fix that in a second.

91
00:06:15,640 --> 00:06:20,860
What I want to do right now is go back to my server and here I can clearly see three things.

92
00:06:21,040 --> 00:06:29,260
First, I can see that Susan is doing the request with name user I.D. as well as wrong.

93
00:06:29,800 --> 00:06:31,300
OK, so that's an awesome start.

94
00:06:31,870 --> 00:06:37,440
And the second thing is the user I.D. So in this case, that is Peter's ID.

95
00:06:38,110 --> 00:06:38,560
Correct.

96
00:06:38,680 --> 00:06:45,850
Because notice that as Susan's I.D. this is Peter said, I think this is an object and this is going

97
00:06:45,850 --> 00:06:48,340
to become very important in a second.

98
00:06:48,370 --> 00:06:54,130
So once I have all of these console.log again, I'll leave it for your reference, just in case you

99
00:06:54,130 --> 00:06:55,510
want to take a look at it later.

100
00:06:56,110 --> 00:07:04,690
And now let's set up some functionality where unless the user role is admin, I actually want to throw

101
00:07:04,690 --> 00:07:05,110
the error.

102
00:07:05,830 --> 00:07:09,850
I want to say that, hey, listen, you're not authorized to access this Iraq.

103
00:07:10,630 --> 00:07:11,800
So how is that going to look like?

104
00:07:11,830 --> 00:07:17,920
Well, I can go with if I request user, so this object over here.

105
00:07:18,130 --> 00:07:20,440
So request user.

106
00:07:21,410 --> 00:07:23,990
And I'm looking for dot and roll.

107
00:07:24,560 --> 00:07:32,390
And I'll say, if the role is equal to admin, then we're good one return from the function and you'll

108
00:07:32,390 --> 00:07:33,980
see why we're there, not in a second.

109
00:07:34,220 --> 00:07:38,090
So say here, if there are always equal to admin, then we're good.

110
00:07:38,480 --> 00:07:44,720
Then basically proceed with next steps that you have here in a function which is going to be sending

111
00:07:44,720 --> 00:07:45,440
back the user.

112
00:07:46,010 --> 00:07:55,370
Then I want to check whether the user I.D. on the request matches that of the resource user I.D. But

113
00:07:55,370 --> 00:07:57,740
keep in mind, this is an object.

114
00:07:58,310 --> 00:08:02,570
So if you'll just check we're equals, it's not going to make sense.

115
00:08:02,570 --> 00:08:04,820
So we need to turn that object into districts.

116
00:08:04,820 --> 00:08:14,180
So in the next line, I'll say following or I'll say if request user user I.D. is equal to a resource

117
00:08:14,390 --> 00:08:17,060
user I.D., but we turn us into a strength.

118
00:08:17,300 --> 00:08:19,310
Otherwise, again, it's going to be big fat mass.

119
00:08:20,210 --> 00:08:22,160
If that's the case, again, we return again.

120
00:08:22,160 --> 00:08:23,270
We're good now.

121
00:08:23,810 --> 00:08:29,540
If none of those conditions are met, what I want to do, I want to throw the error right away.

122
00:08:29,900 --> 00:08:31,820
I want to say throw new.

123
00:08:33,000 --> 00:08:36,870
Custom error, I will go with unauthorized in this case.

124
00:08:37,470 --> 00:08:43,320
So, yeah, technically the authentication work, but you're not authorized to access this route, so

125
00:08:43,320 --> 00:08:43,950
say not.

126
00:08:44,840 --> 00:08:54,290
Authorized to access this route, and now it's finally to start out, so running, navigate back to

127
00:08:54,290 --> 00:08:55,220
my postman.

128
00:08:55,640 --> 00:08:57,050
And here let's send.

129
00:08:57,440 --> 00:09:00,470
We should get back not authorized to access the truck.

130
00:09:00,980 --> 00:09:06,860
And only if I logging as John, I'll be able to see it, or I can view it as a beer.

131
00:09:07,310 --> 00:09:14,330
So if I go back to all the users and if I take Susan's I.D., I'm going to be successful.

132
00:09:14,600 --> 00:09:17,620
I mean, at least I should be unless there's a bug or send it.

133
00:09:17,630 --> 00:09:19,820
Yep, I can view the profile.

134
00:09:20,360 --> 00:09:25,940
But when it comes to other users profile, only the admin or the user can do that.

135
00:09:26,270 --> 00:09:33,440
So if we were logged in and by the way, party here, I would go here with John and log in.

136
00:09:33,440 --> 00:09:36,800
OK, awesome or good, we get back the response.

137
00:09:37,460 --> 00:09:38,510
That should work.

138
00:09:39,260 --> 00:09:47,510
Now let's go here in the get single user and let's try to access Susan, and we're successful because

139
00:09:47,510 --> 00:09:49,190
we are admin again.

140
00:09:49,220 --> 00:09:50,420
Just to recap.

141
00:09:50,720 --> 00:09:52,730
I take a look at the request user.

142
00:09:53,210 --> 00:09:59,120
So the object that I'm getting, as well as resource user ID in this case, a resource is user.

143
00:09:59,600 --> 00:10:06,530
But in other cases, the resource might be something else, might be review, might be product or whatever.

144
00:10:07,160 --> 00:10:11,210
And I check whether the role is on, if that's the case.

145
00:10:11,300 --> 00:10:11,700
Yep.

146
00:10:11,720 --> 00:10:18,070
Admins have all the privileges, so we're good to go if the user I.D. matches to the research study,

147
00:10:18,080 --> 00:10:20,360
but we need to turn to a string again.

148
00:10:20,720 --> 00:10:21,770
We're good to go.

149
00:10:22,100 --> 00:10:25,520
We just proceed to whatever is in the next line.

150
00:10:26,180 --> 00:10:34,910
But if none of them are met, why don't we throw a unauthorized and we say, not authorized to access

151
00:10:34,910 --> 00:10:35,630
this route?

