1
00:00:00,870 --> 00:00:05,700
Once we can verify the email now, let's tackle the next item on our agenda.

2
00:00:06,030 --> 00:00:11,850
Refresh token functionality and before we continue, let me just say that this probably will be the

3
00:00:11,850 --> 00:00:17,700
toughest part of the project just because we'll have to make modifications in multiple places at the

4
00:00:17,700 --> 00:00:18,330
same time.

5
00:00:18,840 --> 00:00:21,650
Now I will try to split it up as much as possible.

6
00:00:21,720 --> 00:00:26,510
Essentially, I'll try to set it up in a bunch of small videos, just so it's less confusing.

7
00:00:26,520 --> 00:00:31,590
But if you're still get stuck or some of this stuff is still confusing.

8
00:00:31,980 --> 00:00:35,700
Just remember, you can always go back and rewatch the video.

9
00:00:36,360 --> 00:00:42,510
Now, let's just start with general overview of what we're trying to accomplish.

10
00:00:43,110 --> 00:00:46,890
So at the moment, I have one user, I have John on.

11
00:00:46,890 --> 00:00:53,100
The good news is that we can test everything with just simple login functionality, so we don't have

12
00:00:53,100 --> 00:00:58,940
to do that whole song and dance where we create the user, then I want to delete them and all that stuff

13
00:00:58,950 --> 00:01:01,560
that was just for verify email.

14
00:01:01,680 --> 00:01:07,710
In this case, we'll be able to test everything with a Morgan and yes, on our front, and we still

15
00:01:07,710 --> 00:01:09,930
don't have the logout functionality.

16
00:01:10,470 --> 00:01:17,190
So if you ever need to get to a log in pictures, go to your URL bar or with forward slash and then

17
00:01:17,190 --> 00:01:18,810
type log in and then eventually.

18
00:01:18,810 --> 00:01:25,320
Yes, the logout functionality also will be there now for time being, I just want to showcase what

19
00:01:25,320 --> 00:01:25,830
happens.

20
00:01:26,160 --> 00:01:30,280
So when I go to my daughter's application here, I have the cookies.

21
00:01:30,300 --> 00:01:32,400
Everything is empty, blah blah blah blah.

22
00:01:32,850 --> 00:01:34,410
And let's just go here with John.

23
00:01:35,200 --> 00:01:35,760
Gmail.

24
00:01:36,120 --> 00:01:39,210
Com And then we're going to go with a secret.

25
00:01:39,510 --> 00:01:40,170
I log in.

26
00:01:41,140 --> 00:01:42,130
Life is great.

27
00:01:42,520 --> 00:01:45,480
I can see that I have John here, I have the idea all I know about.

28
00:01:45,820 --> 00:01:48,610
So what's the problem with this one token approach?

29
00:01:49,270 --> 00:01:56,620
Well, remember that when we're talking about arrest, it is stateless, meaning there is an expiration

30
00:01:56,920 --> 00:02:00,070
for this cookie and also for a token.

31
00:02:00,820 --> 00:02:04,360
Since we're sending a token with a cookie, the moment cookie expires, that's it.

32
00:02:04,360 --> 00:02:04,960
We're done.

33
00:02:05,440 --> 00:02:14,200
And what we need to understand is that just because we were successful to log in once this cookie expires,

34
00:02:14,770 --> 00:02:16,000
ran the user.

35
00:02:16,330 --> 00:02:23,260
If he or she is trying to access the orders here in the dashboard, or maybe, I don't know, product

36
00:02:23,440 --> 00:02:26,890
and stuff along those lines, they will be logged out.

37
00:02:27,310 --> 00:02:34,270
And just to demonstrate that we're going to go back to the project and where we have JWT instead of

38
00:02:34,270 --> 00:02:40,270
one day, I'm going to go with five seconds, how I can get five seconds while batters thousand multiplied

39
00:02:40,270 --> 00:02:40,780
by five.

40
00:02:40,810 --> 00:02:44,710
So at the moment, yes, our exploration is one day.

41
00:02:45,560 --> 00:02:50,300
But just simulate how it looks like once this exploration runs out.

42
00:02:50,660 --> 00:02:52,750
I'm going to go with five seconds ago.

43
00:02:52,790 --> 00:02:57,440
You don't have to do this when I'm Marcus, when I look here for those five seconds.

44
00:02:58,040 --> 00:02:59,330
So comment that.

45
00:03:00,140 --> 00:03:02,210
And then I'll set it up over here.

46
00:03:02,660 --> 00:03:03,880
And now let me navigate.

47
00:03:03,890 --> 00:03:08,540
Like I said back a long time since I cannot log out and just say, log in page.

48
00:03:09,120 --> 00:03:10,370
Let me do that one more time.

49
00:03:10,970 --> 00:03:13,690
Say John at G-mail dot com.

50
00:03:15,130 --> 00:03:21,400
And are the secret I'm I don't have any other routes, so I'm just going to wait four or five seconds

51
00:03:21,400 --> 00:03:22,390
just to showcase that.

52
00:03:22,930 --> 00:03:30,880
If, for example, a user, he is again trying to access some kind of resource and we can see that the

53
00:03:30,880 --> 00:03:33,940
cookie has expired, what do you think is going to happen?

54
00:03:34,270 --> 00:03:37,240
Well, on the front end will log out the user.

55
00:03:37,570 --> 00:03:37,960
Correct.

56
00:03:38,320 --> 00:03:41,230
I got it just to simulate that in this case, I'm just going to refresh and notice.

57
00:03:41,740 --> 00:03:48,400
That's the normal response where if the user is not logged in and more than he or she cannot access

58
00:03:48,400 --> 00:03:49,480
the resources, correct?

59
00:03:50,050 --> 00:03:52,290
But what would be a better approach?

60
00:03:52,300 --> 00:03:58,750
Well, a better approach would be following where if I go to a final application and go to inspect again

61
00:03:59,170 --> 00:04:03,700
again, I'm going to log in and again, I'm going to show you what we're getting back.

62
00:04:04,210 --> 00:04:07,210
You'll notice that we will get back to cookies.

63
00:04:07,870 --> 00:04:12,430
So one is going to be the access token and the second one will be the refresh token.

64
00:04:12,760 --> 00:04:21,640
Now again, for demonstration purposes, the access token has a very short expression just so you can

65
00:04:21,640 --> 00:04:23,650
see how everything works.

66
00:04:23,650 --> 00:04:30,190
But in general, this is where you can set it up to be 15 minutes, one hour, one day or whatever.

67
00:04:30,640 --> 00:04:36,070
So essentially so the user can get everything done that he or she wants.

68
00:04:36,460 --> 00:04:41,350
But we also have this refresh token and what's going to happen in our middleware.

69
00:04:41,590 --> 00:04:48,280
Remember, we have middleware that is checking for JWT, and all that will check for both will check

70
00:04:48,280 --> 00:04:51,520
for access token as well as refresh token and noticed.

71
00:04:51,520 --> 00:04:53,770
Now Access Token has expired.

72
00:04:54,160 --> 00:05:01,000
But if I refresh, if refreshed token is still valid, meaning it hasn't expired.

73
00:05:01,480 --> 00:05:06,010
Then again, we get back both cookies and we're not locked out.

74
00:05:06,640 --> 00:05:10,960
Hopefully, this made sense and now we're going to start setting up the functionality.

