1
00:00:00,530 --> 00:00:02,203
- [Instructor] Hi and
welcome back to the course.

2
00:00:02,203 --> 00:00:04,717
The last video we left it
on a bit of a cliffhanger

3
00:00:04,717 --> 00:00:06,923
before implementing authentication,

4
00:00:06,923 --> 00:00:09,081
but in this video we're
going to finalise that

5
00:00:09,081 --> 00:00:12,868
and explain the entire
flow on how it works.

6
00:00:12,868 --> 00:00:14,208
The first thing we have to do

7
00:00:14,208 --> 00:00:17,605
is setup JWT to work with our app.

8
00:00:17,605 --> 00:00:21,437
So let's import from flask_JWT.

9
00:00:21,437 --> 00:00:23,604
We're going to import JWT.

10
00:00:25,677 --> 00:00:29,673
Now remember to set the apps
secret key, that's important,

11
00:00:29,673 --> 00:00:32,379
and then we're going to
create something called JWT

12
00:00:32,379 --> 00:00:36,418
equals JWT app

13
00:00:36,418 --> 00:00:39,473
authenticate and identity.

14
00:00:39,473 --> 00:00:41,853
Now these two names may sound familiar,

15
00:00:41,853 --> 00:00:46,020
because they are indeed
what we implemented earlier.

16
00:00:48,113 --> 00:00:51,289
So in the last video we implemented

17
00:00:51,289 --> 00:00:53,298
inside security.py

18
00:00:53,298 --> 00:00:57,381
to important functions
authenticate and identity.

19
00:00:58,523 --> 00:01:03,045
When we initialise the JWT object

20
00:01:03,045 --> 00:01:06,658
and that is going to use our app,

21
00:01:06,658 --> 00:01:10,001
the authenticate and the
identity functions together

22
00:01:10,001 --> 00:01:12,884
to allow for authentication of the users.

23
00:01:12,884 --> 00:01:15,329
So here's how it's going to work

24
00:01:15,329 --> 00:01:20,109
JWT creates a new endpoint

25
00:01:20,109 --> 00:01:24,276
that endpoint is /auth, /auth.

26
00:01:25,983 --> 00:01:28,801
When we call /auth

27
00:01:28,801 --> 00:01:31,740
we send it a username and a password

28
00:01:31,740 --> 00:01:35,539
and the JWT extension gets
that username and password

29
00:01:35,539 --> 00:01:38,892
and sends it over to the
authenticate function

30
00:01:38,892 --> 00:01:41,619
that takes in a username and a password.

31
00:01:41,619 --> 00:01:44,621
We are then going to find
the correct user object

32
00:01:44,621 --> 00:01:46,374
using that username

33
00:01:46,374 --> 00:01:48,336
and we're going to compare its password

34
00:01:48,336 --> 00:01:53,074
to the one that we receive
through the auth endpoint.

35
00:01:53,074 --> 00:01:55,874
If they match we're
going to return the user

36
00:01:55,874 --> 00:01:57,712
and that becomes sort of the identity.

37
00:01:57,712 --> 00:02:00,123
So what happens next is the auth endpoint

38
00:02:00,123 --> 00:02:03,706
returns a JWT token, a JW token.

39
00:02:06,110 --> 00:02:09,801
Now that JW token in
itself doesn't do anything,

40
00:02:09,801 --> 00:02:13,619
but we can send it

41
00:02:13,619 --> 00:02:15,952
to the next request we make.

42
00:02:17,234 --> 00:02:19,734
So when we send a JW token

43
00:02:21,031 --> 00:02:24,948
what JWT does is it calls
the identity function

44
00:02:26,058 --> 00:02:30,054
and then it uses the JWT
token to get the user ID

45
00:02:30,054 --> 00:02:32,758
and with that it gets the correct user

46
00:02:32,758 --> 00:02:36,675
for that user ID that
the JWT token represents.

47
00:02:38,869 --> 00:02:41,382
And if it can do that that means

48
00:02:41,382 --> 00:02:43,112
that the user was authenticated,

49
00:02:43,112 --> 00:02:46,445
the JWT token is valid, and all is good.

50
00:02:47,972 --> 00:02:51,853
So from flask JWT we're
going to import JWT and

51
00:02:51,853 --> 00:02:54,353
JWT required

52
00:02:55,457 --> 00:02:59,461
and that is a decorator
that we are going to call

53
00:02:59,461 --> 00:03:01,711
in front of our get method.

54
00:03:03,712 --> 00:03:05,528
So what's going to happen now is that

55
00:03:05,528 --> 00:03:07,629
we are going to have to authenticate

56
00:03:07,629 --> 00:03:10,462
before we can call the get method.

57
00:03:11,326 --> 00:03:13,576
So let's go over to Postman

58
00:03:14,714 --> 00:03:18,214
and in here just go to

59
00:03:20,167 --> 00:03:23,750
5,000/auth.

60
00:03:26,640 --> 00:03:29,954
So we've got here a new
endpoint that we've not created

61
00:03:29,954 --> 00:03:32,383
the JWT token creates that for us,

62
00:03:32,383 --> 00:03:33,637
sorry not the JWT token,

63
00:03:33,637 --> 00:03:36,453
the JWT extension creates that for us

64
00:03:36,453 --> 00:03:37,755
and all we have to do

65
00:03:37,755 --> 00:03:39,832
is pass in a username and a password.

66
00:03:39,832 --> 00:03:43,628
So the headers authorization have to be

67
00:03:43,628 --> 00:03:45,647
JSON,

68
00:03:45,647 --> 00:03:47,994
has to be a post, and in the body

69
00:03:47,994 --> 00:03:49,911
we're going to pass in,

70
00:03:52,485 --> 00:03:54,187
I'm sorry not authorization, content type,

71
00:03:54,187 --> 00:03:56,187
what am I talking about.

72
00:03:57,093 --> 00:03:59,445
Here we're going to pass in a username

73
00:03:59,445 --> 00:04:01,195
which has to be Bob

74
00:04:01,195 --> 00:04:04,814
and a password, which has to be ASDF.

75
00:04:04,814 --> 00:04:07,247
These have to match exactly

76
00:04:07,247 --> 00:04:10,247
that ones in our in memory database.

77
00:04:11,113 --> 00:04:13,289
Okay, I'm going to save this now

78
00:04:13,289 --> 00:04:15,606
and there we've got our auth endpoint.

79
00:04:15,606 --> 00:04:19,773
So what do you think is going
to happen when we press send?

80
00:04:21,047 --> 00:04:22,880
Well let's try it out.

81
00:04:24,984 --> 00:04:26,901
That's some sort of

82
00:04:28,743 --> 00:04:29,867
funny thing that happened there.

83
00:04:29,867 --> 00:04:33,046
We have to be running our app of course.

84
00:04:33,046 --> 00:04:35,088
Let's do it again.

85
00:04:35,088 --> 00:04:36,302
There we go.

86
00:04:36,302 --> 00:04:40,425
Now we have the JWT back.

87
00:04:40,425 --> 00:04:43,004
This is the JWT, it's pretty long,

88
00:04:43,004 --> 00:04:45,435
and what we're going to do is copy that.

89
00:04:45,435 --> 00:04:47,311
So just select the entire thing

90
00:04:47,311 --> 00:04:49,944
without the quotation marks and copy it

91
00:04:49,944 --> 00:04:52,430
and then we're going to create a new item.

92
00:04:52,430 --> 00:04:55,104
So I'm going to create
a piano for example,

93
00:04:55,104 --> 00:04:58,544
and as you know this does
not require a JW token.

94
00:04:58,544 --> 00:05:00,500
So we should be able to do it just fine,

95
00:05:00,500 --> 00:05:04,301
because we've not really changed anything.

96
00:05:04,301 --> 00:05:06,749
And as you can see the piano comes back

97
00:05:06,749 --> 00:05:08,308
and all is good.

98
00:05:08,308 --> 00:05:10,581
We can call our items endpoint,

99
00:05:10,581 --> 00:05:13,149
which returns a list of items

100
00:05:13,149 --> 00:05:15,453
and that returns just a list of items

101
00:05:15,453 --> 00:05:17,728
as it did in the last video,

102
00:05:17,728 --> 00:05:21,311
but finally let's call
for a specific item.

103
00:05:25,403 --> 00:05:28,414
And WA-LA we get some
sort of error message.

104
00:05:28,414 --> 00:05:30,718
The request does not
contain an access token

105
00:05:30,718 --> 00:05:32,680
and the status code is 401,

106
00:05:32,680 --> 00:05:34,473
which means unauthorised,

107
00:05:34,473 --> 00:05:37,121
and the error is that
authorization is required.

108
00:05:37,121 --> 00:05:39,310
So we're missing something here

109
00:05:39,310 --> 00:05:42,234
and so we are, because we have to send in

110
00:05:42,234 --> 00:05:44,424
the JW token so that

111
00:05:44,424 --> 00:05:47,500
flask JWT can understand that we are

112
00:05:47,500 --> 00:05:50,611
a user that has logged in in the past

113
00:05:50,611 --> 00:05:52,071
and the way we do that

114
00:05:52,071 --> 00:05:55,133
is we put in a new header,
which is authorization

115
00:05:55,133 --> 00:05:58,325
and the value is really
important, has to be

116
00:05:58,325 --> 00:06:02,569
JWT space

117
00:06:02,569 --> 00:06:05,011
and then paste in the entire token

118
00:06:05,011 --> 00:06:07,597
which is a pretty long thing

119
00:06:07,597 --> 00:06:09,320
and that is it.

120
00:06:09,320 --> 00:06:12,820
Then press send and we get our piano back.

121
00:06:15,773 --> 00:06:18,488
So that's what logged
in means to a server.

122
00:06:18,488 --> 00:06:22,096
It means can you prove
that you are somebody

123
00:06:22,096 --> 00:06:25,050
and we can prove it if we send in this

124
00:06:25,050 --> 00:06:27,005
authorization header.

125
00:06:27,005 --> 00:06:29,979
Flask JWT is going to look
at the authorization header.

126
00:06:29,979 --> 00:06:34,379
It's going to understand
that we are a user

127
00:06:34,379 --> 00:06:38,793
and with this it's going to decode it,

128
00:06:38,793 --> 00:06:41,986
it's going to retrieve a user ID from it,

129
00:06:41,986 --> 00:06:44,398
and in our security file

130
00:06:44,398 --> 00:06:46,364
it's going to call the identity payload,

131
00:06:46,364 --> 00:06:47,963
it's going to get the user ID,

132
00:06:47,963 --> 00:06:49,306
and then it's going to
get the correct user

133
00:06:49,306 --> 00:06:51,397
for that ID.

134
00:06:51,397 --> 00:06:53,273
And because that user does exist,

135
00:06:53,273 --> 00:06:55,301
Bob and ASDF,

136
00:06:55,301 --> 00:06:57,809
then it knows that we are logged in

137
00:06:57,809 --> 00:07:00,142
and then we run this method.

138
00:07:01,578 --> 00:07:03,994
So hopefully all of that made sense

139
00:07:03,994 --> 00:07:06,205
and authentication generally is quite a

140
00:07:06,205 --> 00:07:08,052
confusing and complex thing,

141
00:07:08,052 --> 00:07:10,776
but flask JWT really does
make it a lot simpler

142
00:07:10,776 --> 00:07:12,992
then it has been in the past.

143
00:07:12,992 --> 00:07:15,077
So hopefully all that's okay.

144
00:07:15,077 --> 00:07:17,890
Thanks for watching and I'll
see you in the very next video.

