WEBVTT 00:00:06.660 --> 00:00:12.150 All right now we're going to move to the next step which is creating a unique observation code which 00:00:12.150 --> 00:00:16.340 would allow us to make sure the user owns the e-mail address they have provided. 00:00:16.620 --> 00:00:17.200 OK. 00:00:17.340 --> 00:00:22.130 But before we move ahead let's just have a look at our code and if a couple of things. 00:00:22.380 --> 00:00:28.340 So because I don't assign missing from our results variable then OK. 00:00:28.710 --> 00:00:31.710 And you've got the same thing in the previous lines. 00:00:31.960 --> 00:00:32.850 All right then. 00:00:33.210 --> 00:00:34.030 OK. 00:00:34.050 --> 00:00:40.470 And also we actually don't need the quotes or the table name in the query. 00:00:40.470 --> 00:00:42.730 OK. 00:00:45.060 --> 00:00:56.070 Now let's just save our code and refresh the page and destroy it with an empty form and make sure we 00:00:56.070 --> 00:00:58.390 don't get any errors. 00:00:59.670 --> 00:01:03.130 OK we do get the right error messages in there. 00:01:03.210 --> 00:01:03.750 OK. 00:01:03.960 --> 00:01:10.190 Now legis provide a user name and see what we get. 00:01:12.160 --> 00:01:17.740 OK let's just provide an email address. 00:01:19.940 --> 00:01:20.880 OK. 00:01:21.750 --> 00:01:23.070 It looks good. 00:01:23.630 --> 00:01:23.960 OK. 00:01:23.950 --> 00:01:28.480 Now before we move to the next step just a quick comment. 00:01:28.770 --> 00:01:37.590 Sometimes you might need to do some debugging with your code especially if you have an error relating 00:01:37.590 --> 00:01:38.420 to your query. 00:01:38.460 --> 00:01:44.630 So let's change our query and just have the wrong table name. 00:01:44.850 --> 00:01:55.200 OK so if we save refresh our code try again we they then empty form. 00:01:55.290 --> 00:01:59.990 OK now we get error writing the query which is this query. 00:02:00.130 --> 00:02:03.330 OK but we don't know where the error is. 00:02:03.360 --> 00:02:08.550 So there is a function called my escape by error which is going to return the error corresponding to 00:02:08.550 --> 00:02:10.590 the last executed query. 00:02:10.920 --> 00:02:16.450 So it is odd one more line just before the xes function. 00:02:17.510 --> 00:02:17.990 OK. 00:02:18.210 --> 00:02:25.110 So we're going to use this function called my schoolboy error 00:02:25.110 --> 00:02:31.650 . 00:02:34.200 --> 00:02:35.940 So it's going to take one bomb. 00:02:36.110 --> 00:02:37.200 Well he's going to be our link. 00:02:37.200 --> 00:02:45.960 Very well where we saw the connection so let's save and refresh our code of page. 00:02:45.960 --> 00:02:49.300 So now we can see the error corresponding to the query. 00:02:49.350 --> 00:02:50.040 OK. 00:02:50.040 --> 00:02:53.830 So he's telling us that the table does not exist. 00:02:53.910 --> 00:02:54.390 OK. 00:02:54.500 --> 00:02:55.950 And that's exactly what we were expecting. 00:02:55.980 --> 00:02:57.760 As we change the table name. 00:02:57.930 --> 00:02:58.360 Right. 00:02:58.530 --> 00:03:01.990 So that's something to keep in mind to do some debugging. 00:03:02.280 --> 00:03:06.520 OK so for now I'm going to comment this line. 00:03:06.950 --> 00:03:16.610 OK and then rectify the table they then save the refresh our code and make sure these things are still 00:03:16.670 --> 00:03:17.310 working. 00:03:17.550 --> 00:03:19.460 Perfect. 00:03:19.470 --> 00:03:19.740 All right. 00:03:19.740 --> 00:03:22.680 Now let's create our unique activation code 00:03:25.800 --> 00:03:31.500 to do this we're going to need to use a function does can generate random numbers but we need something 00:03:31.500 --> 00:03:37.380 really strong using some strong algorithms to generate these random numbers. 00:03:37.410 --> 00:03:46.830 The function we're going to be using here is called Open SSL random pseudo bytes so this function will 00:03:46.830 --> 00:03:50.250 generate a pseudo random string of bytes. 00:03:50.340 --> 00:03:53.060 OK so what's the bytes. 00:03:53.400 --> 00:03:56.150 So a bytes which we spell like this. 00:03:56.270 --> 00:03:56.900 OK. 00:03:56.940 --> 00:04:03.060 Is a unit of data which is eight binary digits long. 00:04:03.330 --> 00:04:03.870 OK. 00:04:04.200 --> 00:04:12.690 So let's just write this units of data which is 8 binary days long which is 8 bits. 00:04:12.870 --> 00:04:14.260 So was 8 bits. 00:04:14.400 --> 00:04:17.530 So a bit is the smallest units of data. 00:04:17.580 --> 00:04:18.730 Ok for the computer. 00:04:18.840 --> 00:04:23.010 So that's where the computer is going to store either 0 or 1. 00:04:23.010 --> 00:04:25.440 So that's what one bit is. 00:04:25.500 --> 00:04:26.060 OK. 00:04:26.220 --> 00:04:28.930 So one base is 0 or 1. 00:04:29.100 --> 00:04:31.610 So our function is going to take a couple of tries. 00:04:31.620 --> 00:04:35.710 So the first one is going to be how many bytes. 00:04:35.800 --> 00:04:43.030 OK we would like to generate So let's go for 16 bytes and then the second promiser OK is optional. 00:04:43.530 --> 00:04:49.830 And if you put a variable in there is going to be OK the function is going to store in that variable 00:04:49.890 --> 00:04:52.550 a boolean either false or true. 00:04:52.610 --> 00:04:58.730 So it's going to be true if the algorithm OK used for the function is ss to be strong. 00:04:58.900 --> 00:05:04.090 Ok so very often that variable is going to be true. 00:05:04.110 --> 00:05:04.530 OK. 00:05:04.680 --> 00:05:09.620 It's very rare that we get a false value for that variable. 00:05:09.990 --> 00:05:13.860 Ok so we get to use only the first promise for now. 00:05:14.640 --> 00:05:24.000 OK so we're going to store the output of our function inside a variable as we're going to call activation 00:05:24.000 --> 00:05:25.870 key. 00:05:27.380 --> 00:05:28.470 OK. 00:05:31.200 --> 00:05:36.750 Now we need to know how many characters we're going to allocate for this variable. 00:05:36.810 --> 00:05:37.180 OK. 00:05:37.180 --> 00:05:39.460 Inside our users table. 00:05:39.600 --> 00:05:40.220 OK. 00:05:40.380 --> 00:05:43.530 So we say we're going to be using 16 bytes. 00:05:43.530 --> 00:05:44.070 OK. 00:05:44.250 --> 00:05:49.200 So each byte is 8 bits so 16 bytes 00:05:52.560 --> 00:05:55.940 is going to give us 60 and multiplied by 8. 00:05:56.180 --> 00:05:56.640 OK. 00:05:56.720 --> 00:05:59.960 And that's going to be 128 bits. 00:06:01.040 --> 00:06:01.940 OK. 00:06:02.610 --> 00:06:04.020 To understand this clearly. 00:06:04.210 --> 00:06:06.730 OK you can imagine that for each bit. 00:06:06.750 --> 00:06:07.200 OK. 00:06:07.260 --> 00:06:08.520 We've got two values. 00:06:08.520 --> 00:06:12.140 Ok so the first bit is going to be two values either 0 or 1. 00:06:12.150 --> 00:06:16.370 The second one is going to be to either 0 or 1 and so on. 00:06:16.440 --> 00:06:16.960 OK. 00:06:17.340 --> 00:06:24.660 So if you represent a number in this format OK this is what we call base 2. 00:06:24.680 --> 00:06:35.130 OK so what do we store the value of our activation key in the table uses we're going to store this in 00:06:35.460 --> 00:06:36.090 a decimal. 00:06:36.300 --> 00:06:40.670 So we're going to need to convert this base to to base 16. 00:06:40.800 --> 00:06:42.130 So based Eckstine. 00:06:42.160 --> 00:06:48.190 OK corresponds to two multiplied by two four times. 00:06:48.570 --> 00:06:50.940 And that's what going to give us 16. 00:06:51.120 --> 00:06:58.800 OK so four hundred twenty eight bits in this formula you'll find and it's twenty eight twos. 00:06:58.950 --> 00:07:12.540 OK but if we go for 16 multiplied by 16 extra OK for this same formula that's going to give us how many 00:07:12.540 --> 00:07:18.870 times 16 that's going to be hundred twenty eight divided by four. 00:07:19.020 --> 00:07:19.640 OK. 00:07:19.920 --> 00:07:21.500 So that's going to be 32. 00:07:21.690 --> 00:07:28.400 So actually we're going to need 32 characters for our activation key in the Users table. 00:07:29.100 --> 00:07:34.110 Ok so since we're going to be storing this variable in X a decimal we're going to need to convert it 00:07:34.350 --> 00:07:40.760 from binary to a symbol and there is a very useful function for this is called binary to ex-head is 00:07:40.770 --> 00:07:41.340 simple. 00:07:41.660 --> 00:07:42.430 OK. 00:07:43.230 --> 00:07:47.640 Just like this. 00:07:47.640 --> 00:07:56.040 All right so now let's have a look at our table and make sure that you've got 32 characters allocated 00:07:56.190 --> 00:08:02.100 for the observation key in the Users table that you can see that the observation field has caused 32 00:08:02.100 --> 00:08:03.480 characters allocated already. 00:08:03.480 --> 00:08:04.770 So we don't have to change anything. 00:08:04.920 --> 00:08:12.060 OK now let's insert the user details with the activation code in the Users table. 00:08:12.060 --> 00:08:16.080 So to do this we're going to create a query first. 00:08:16.260 --> 00:08:19.720 OK I'm going to store it in a variable as we're going to call it. 00:08:19.820 --> 00:08:29.710 Q Well so the query is going to insert a whole line or a record in the table. 00:08:30.240 --> 00:08:37.590 So the syntax is inserted into the table name which is used is and then we're going to have parentheses 00:08:38.520 --> 00:08:43.360 where are going to place the names of our columns. 00:08:43.370 --> 00:08:53.080 OK all the affected columns and then we're going to have values forward again by parentheses. 00:08:53.540 --> 00:08:58.800 Are we going to place all the corresponding values for each of those columns so the columns are going 00:08:58.800 --> 00:09:02.340 to be as following are going to have the user name. 00:09:03.060 --> 00:09:07.410 OK then the email 00:09:11.190 --> 00:09:15.110 and the password. 00:09:15.480 --> 00:09:19.650 And finally we need the activation key as well. 00:09:19.650 --> 00:09:21.880 And that's actuation. 00:09:22.070 --> 00:09:29.590 Right now the corresponding values are going to be the user name better. 00:09:29.910 --> 00:09:37.230 They are going to need to place these in the same order as the order of the columns email 00:09:41.310 --> 00:09:45.030 password. 00:09:45.570 --> 00:09:49.700 And then the oxidation key. 00:09:50.250 --> 00:09:50.820 OK. 00:09:50.880 --> 00:09:56.160 And just make sure that you place each of these inside single quotes like that's 00:09:59.200 --> 00:10:01.340 the 00:10:10.510 --> 00:10:16.060 now to run the query we're going to use the function of my query. 00:10:16.430 --> 00:10:16.940 OK. 00:10:17.110 --> 00:10:18.480 Which will take a couple of weeks. 00:10:18.480 --> 00:10:25.520 So the first one is the link variable pay and the second one is the query cell. 00:10:25.990 --> 00:10:31.040 So we're going to store the hours of this function inside a variable. 00:10:31.340 --> 00:10:31.840 OK. 00:10:32.040 --> 00:10:33.870 So we're going to call results. 00:10:33.880 --> 00:10:35.730 So that's going to be an object. 00:10:35.730 --> 00:10:37.960 All right. 00:10:40.000 --> 00:10:43.140 So if the query is successful that's going to be an object. 00:10:43.330 --> 00:10:45.650 Otherwise it's going to return false. 00:10:45.800 --> 00:10:50.710 OK now we're going to check if the query is not successful. 00:10:50.750 --> 00:10:51.920 OK. 00:10:52.540 --> 00:10:55.740 So if it's not successful that's going to return false. 00:10:55.780 --> 00:10:58.960 So the opposite is going to be true. 00:10:58.960 --> 00:10:59.630 OK. 00:10:59.770 --> 00:11:02.620 So we're going to check the opposite of results. 00:11:03.010 --> 00:11:08.010 If that's the case we're going to echo an error message. 00:11:08.330 --> 00:11:10.690 Okay so I just copy that one. 00:11:10.710 --> 00:11:13.680 Say Tony. 00:11:15.940 --> 00:11:16.500 OK. 00:11:16.510 --> 00:11:22.690 And I'd say something like there was an error in setting 00:11:30.060 --> 00:11:34.590 the details in the database. 00:11:37.720 --> 00:11:38.850 Okay. 00:11:39.730 --> 00:11:45.520 And then are going to access the whole ph be good. 00:11:45.610 --> 00:11:50.120 All right if you want to use the L statements you can do that. 00:11:50.290 --> 00:11:53.010 I'm going to go for the exits function. 00:11:54.010 --> 00:11:59.540 Now let's send an e-mail to the user to make sure that they own the e-mail address they have provided 00:11:59.550 --> 00:12:00.080 . 00:12:00.480 --> 00:12:03.640 OK. 00:12:05.890 --> 00:12:08.390 So we're going to use the mail BHP function. 00:12:08.620 --> 00:12:09.270 OK. 00:12:09.650 --> 00:12:16.300 So it's going to take a few promises so the first one is going to be the email where we sending the 00:12:16.360 --> 00:12:22.080 email and is it going to be our e-mail variable that we are going to have the subject of the e-mail 00:12:22.100 --> 00:12:22.510 . 00:12:22.940 --> 00:12:33.940 So they say confirm your registration then we are going to have the body of our e-mail. 00:12:34.390 --> 00:12:38.880 And let's call that message. 00:12:39.170 --> 00:12:47.110 Now we're going to start inside this variable the body of the e-mail and then we going to have another 00:12:49.090 --> 00:12:55.350 Paromita that's going to be from which e-mail message is coming from. 00:12:55.600 --> 00:12:56.710 OK. 00:12:56.710 --> 00:12:57.250 So 00:13:00.700 --> 00:13:03.790 you can choose any e-mail address where this is going to go for 00:13:07.390 --> 00:13:08.230 development. 00:13:08.270 --> 00:13:10.610 And then G-mail article. 00:13:11.260 --> 00:13:14.740 Ok so now in it's build our message variable. 00:13:14.860 --> 00:13:18.890 Before email function. 00:13:19.600 --> 00:13:21.400 So it's not like this. 00:13:21.790 --> 00:13:28.850 Please click on this link and activate your account. 00:13:29.470 --> 00:13:36.610 Basically we're going to have a link as we're going to be sending to our user and the link is going 00:13:36.610 --> 00:13:39.860 to direct them to the activates those PSP file. 00:13:40.120 --> 00:13:53.010 Ok so this place is have a line here and again and let's add the link to the variable. 00:13:54.680 --> 00:13:57.720 OK. 00:14:02.450 --> 00:14:03.830 So just a reminder. 00:14:04.140 --> 00:14:04.510 OK. 00:14:04.510 --> 00:14:12.400 So if if you're building a real projects where users are going to be signing up and logging in you will 00:14:12.400 --> 00:14:15.220 need to purchase an SSL certificates. 00:14:15.250 --> 00:14:19.150 OK so that you can have a secure connection. 00:14:19.340 --> 00:14:25.390 Make sure that's anything that's exchanged between your users and your server is done in a secure way 00:14:25.410 --> 00:14:25.590 . 00:14:25.750 --> 00:14:26.860 OK. 00:14:26.860 --> 00:14:29.380 So for now I'm using a subdomain. 00:14:29.380 --> 00:14:37.030 So that's why it's not possible to have a whole connection but if you're doing a real one you will need 00:14:37.050 --> 00:14:38.340 that's OK. 00:14:38.410 --> 00:14:38.710 So 00:14:41.780 --> 00:14:46.560 that's going to be activated bought BHP. 00:14:47.290 --> 00:14:55.190 And if you if you remember the x rays those PSP file is going to receive a couple of pharmacies. 00:14:55.740 --> 00:14:56.430 OK. 00:14:56.440 --> 00:15:00.370 So it's going to receive an e-mail and an activation key. 00:15:00.460 --> 00:15:02.470 And there was going to be get promises. 00:15:02.470 --> 00:15:02.990 OK. 00:15:03.310 --> 00:15:06.080 So let's add these to the link. 00:15:06.310 --> 00:15:08.510 OK. 00:15:08.550 --> 00:15:08.970 So 00:15:17.350 --> 00:15:21.720 you have a question mark and then the first performance is going to be e-mail. 00:15:21.920 --> 00:15:22.880 OK. 00:15:23.050 --> 00:15:24.870 And they're going to need the equal sign. 00:15:25.450 --> 00:15:33.100 And then the value of the e-mail so for e-mails if you place them inside a u r l you would need to encode 00:15:33.340 --> 00:15:40.360 the email for the real formats and for this rather than placing the email like this. 00:15:40.440 --> 00:15:41.400 OK. 00:15:41.930 --> 00:15:47.970 We're going to need to use a function that will encode the email for you all. 00:15:48.400 --> 00:15:50.800 OK so that's key and that function is called. 00:15:50.830 --> 00:15:53.060 You are really in code. 00:15:53.800 --> 00:15:57.970 OK. 00:16:01.810 --> 00:16:03.700 All right. 00:16:03.700 --> 00:16:07.570 And then we're going to the prom. 00:16:09.810 --> 00:16:17.290 And as ampersand key equal activation. 00:16:18.820 --> 00:16:20.590 Now let's have a look at the male function. 00:16:20.590 --> 00:16:25.520 So if the e-mail is sent successfully the function is going to return to. 00:16:25.620 --> 00:16:28.980 OK he's going to return a boolean true. 00:16:28.990 --> 00:16:31.960 If the email is sends successfully false if not. 00:16:32.090 --> 00:16:35.620 So what are we going to do we going actually to check the output of this function. 00:16:35.860 --> 00:16:38.740 So if mail. 00:16:38.940 --> 00:16:39.310 OK 00:16:42.230 --> 00:16:44.350 going to echo a success message. 00:16:44.560 --> 00:16:44.820 OK 00:16:44.840 --> 00:16:51.840 . 00:16:59.340 --> 00:17:00.220 OK. 00:17:00.250 --> 00:17:02.170 And say 00:17:07.390 --> 00:17:10.090 thank you for offering 00:17:14.440 --> 00:17:16.140 me an email. 00:17:16.760 --> 00:17:21.110 I was being sent to the email address provided. 00:17:21.580 --> 00:17:21.870 OK 00:17:25.060 --> 00:17:28.120 . 00:17:31.510 --> 00:17:33.670 Please click on the acceleration link 00:17:37.110 --> 00:17:37.710 accelerator 00:17:37.760 --> 00:17:43.280 . 00:17:43.640 --> 00:17:44.410 All right. 00:17:44.410 --> 00:17:46.830 In order to include the variable email like. 00:17:47.160 --> 00:17:55.330 When the double quotes instead of single words also will need to change the inside double quotes to 00:17:55.390 --> 00:17:58.170 single code like this. 00:17:58.180 --> 00:17:59.950 OK. 00:18:00.350 --> 00:18:01.380 All right. 00:18:01.720 --> 00:18:03.050 Now let's have a look. 00:18:03.260 --> 00:18:05.460 It's the last word. 00:18:05.560 --> 00:18:13.110 So when you saw the password in the user table we shouldn't be storing the password in plain text. 00:18:13.270 --> 00:18:15.430 Well need to hush our password. 00:18:15.550 --> 00:18:16.140 OK. 00:18:16.300 --> 00:18:20.760 So when we were preparing the variables for the queries. 00:18:21.100 --> 00:18:21.780 OK. 00:18:21.940 --> 00:18:27.760 So it was an extra step that we needed for the password and that's hashing the password. 00:18:27.760 --> 00:18:32.860 So get to replace the password variable with the husht version of the password so we're going to use 00:18:33.670 --> 00:18:35.200 a hashing function. 00:18:35.200 --> 00:18:37.270 So there are many functions you can use. 00:18:37.330 --> 00:18:39.060 There is M.D five. 00:18:39.310 --> 00:18:45.160 OK it's not the strongest harshing function. 00:18:45.280 --> 00:18:48.570 We can sense with this function for now. 00:18:48.760 --> 00:18:54.520 So the empty five function is going to use a hashing algorithm to hash out a password. 00:18:54.520 --> 00:19:01.230 So the output of this function is going to be 128 bits long. 00:19:01.330 --> 00:19:07.270 OK but it's going to be stored in ex-head decimal automatically. 00:19:07.480 --> 00:19:10.520 So that's going to give us 32 characters. 00:19:10.750 --> 00:19:19.360 OK so let's have a quick look at our table and make sure that we of course 32 characters allocated for 00:19:19.360 --> 00:19:20.900 the password. 00:19:20.980 --> 00:19:32.120 So we're going to need to change the structure of the password field so that needs 32 characters. 00:19:32.380 --> 00:19:38.470 So we're going to come back later to this field where we use another hashing function. 00:19:38.500 --> 00:19:40.290 Now let's start with the undefine. 00:19:40.540 --> 00:19:47.450 I'm going to come back to that in a little bit and explain why we're not going to rely on the under-five 00:19:47.560 --> 00:19:47.700 . 00:19:47.820 --> 00:19:52.430 OK.