1
00:00:01,136 --> 00:00:02,619
Hi, and welcome back.

2
00:00:02,619 --> 00:00:07,441
In this video, I wanted to tell you about jwt_optional.

3
00:00:07,441 --> 00:00:10,441
jwt_optional is going to let you add

4
00:00:11,555 --> 00:00:16,222
into any endpoint that the jwt can or cannot be present.

5
00:00:17,933 --> 00:00:20,654
Then inside the endpoint, you can choose what to do

6
00:00:20,654 --> 00:00:22,249
if it is present or not.

7
00:00:22,249 --> 00:00:25,286
Let's go over to our item resource.

8
00:00:25,286 --> 00:00:27,701
And this time, we're gonna add some info

9
00:00:27,701 --> 00:00:29,659
here to the item list resource.

10
00:00:29,659 --> 00:00:30,867
We're gonna add a little bit more code

11
00:00:30,867 --> 00:00:35,467
That's going to be at jwt underscore optional.

12
00:00:35,467 --> 00:00:40,467
We're gonna import this at the top of the file as well.

13
00:00:40,635 --> 00:00:43,418
From flask_jwt_extended, of course.

14
00:00:43,418 --> 00:00:48,200
Now we have jwt_optional, we can do something like this.

15
00:00:48,200 --> 00:00:51,117
Usually the equal get_jwt_identity.

16
00:00:52,494 --> 00:00:54,484
Just make sure that this is imported.

17
00:00:54,484 --> 00:00:56,890
It's not, so we have to import that.

18
00:00:56,890 --> 00:01:01,406
get_jwt_identity is going to give us whatever we saved

19
00:01:01,406 --> 00:01:04,553
in the access token as the identity.

20
00:01:04,553 --> 00:01:08,865
We're saving user IDs, so this sort of makes sense.

21
00:01:08,865 --> 00:01:10,820
We're gonna get the jwt_identity,

22
00:01:10,820 --> 00:01:12,987
and that's gonna be the user ID

23
00:01:12,987 --> 00:01:16,154
of the user that is stored in the jwt.

24
00:01:18,699 --> 00:01:21,366
So that gives us the user ID, or

25
00:01:22,457 --> 00:01:26,848
because the jwt is optional, it can also give us none.

26
00:01:26,848 --> 00:01:29,693
Okay, if it gives us none, that means

27
00:01:29,693 --> 00:01:31,607
the user is not logged in,

28
00:01:31,607 --> 00:01:35,102
or they didn't send the authorization token.

29
00:01:35,102 --> 00:01:38,352 line:15% 
Okay, so we're gonna say items is this.

30
00:01:42,821 --> 00:01:45,213 line:15% 
These are our items, and then we're gonna say

31
00:01:45,213 --> 00:01:48,920 line:15% 
if user_id was provided, we're gonna return

32
00:01:48,920 --> 00:01:51,503 line:15% 
items is items and two hundred.

33
00:01:53,066 --> 00:01:57,118 line:15% 
Otherwise, if the user ID was not provided,

34
00:01:57,118 --> 00:02:00,671 line:15% 
that means we did not exit the function here,

35
00:02:00,671 --> 00:02:03,235 line:15% 
we're going to return something else.

36
00:02:03,235 --> 00:02:06,318 line:15% 
We're going to return items,

37
00:02:06,318 --> 00:02:07,874 line:15% 
but the items we're going to return

38
00:02:07,874 --> 00:02:10,191 line:15% 
are not going to be the full items.

39
00:02:10,191 --> 00:02:12,112 line:15% 
We're just going to return the item name,

40
00:02:12,112 --> 00:02:14,695 line:15% 
so item name for item in items.

41
00:02:16,334 --> 00:02:18,829 line:15% 
Okay, by the way, I'm just going to use this opportunity

42
00:02:18,829 --> 00:02:21,579 line:15% 
to rename the x there to item.

43
00:02:23,447 --> 00:02:26,030 line:15% 
And we're also going to include

44
00:02:28,536 --> 00:02:33,536 line:15% 
a small message to say "More data available if you log in."

45
00:02:34,285 --> 00:02:37,578 line:15% 
Okay, just to give the user a little bit more information.

46
00:02:37,578 --> 00:02:39,648 line:15% 
I don't know why that was there.

47
00:02:39,648 --> 00:02:41,148 line:15% 
There you have it.

48
00:02:43,153 --> 00:02:46,701
So, this item list resource now has

49
00:02:46,701 --> 00:02:48,868
a jwt_optional on its get.

50
00:02:49,894 --> 00:02:51,173
The first thing we do is we get

51
00:02:51,173 --> 00:02:54,395
the identity stored in the jwt.

52
00:02:54,395 --> 00:02:57,312
If there is no jwt, we return none.

53
00:02:58,957 --> 00:03:02,059
Then we create our list of items.

54
00:03:02,059 --> 00:03:05,726
This is just the item JSON in all our items.

55
00:03:06,636 --> 00:03:10,000
If the user ID is present, that means the user is logged in.

56
00:03:10,000 --> 00:03:12,260
We're just gonna return all of the item data

57
00:03:12,260 --> 00:03:14,888
we have in our database.

58
00:03:14,888 --> 00:03:19,729
But if we don't do that, that means the user did not log in

59
00:03:19,729 --> 00:03:23,344
or did not provide an authorization header,

60
00:03:23,344 --> 00:03:25,975
so we're just going to return another dictionary

61
00:03:25,975 --> 00:03:29,642
that says the items are just the item names.

62
00:03:30,616 --> 00:03:33,847
So we're not going to return all the item JSON

63
00:03:33,847 --> 00:03:36,197
including store ID and the price and so forth.

64
00:03:36,197 --> 00:03:37,519
We're just gonna return the item name

65
00:03:37,519 --> 00:03:39,337
so they can see what's there.

66
00:03:39,337 --> 00:03:44,004
And we're gonna say "More data available if you log in."

67
00:03:45,820 --> 00:03:47,167
So that's it.

68
00:03:47,167 --> 00:03:49,506
So couple of things we've learned in this video.

69
00:03:49,506 --> 00:03:51,839
jwt_optional can be useful

70
00:03:51,839 --> 00:03:53,941
if you want to allow your endpoints

71
00:03:53,941 --> 00:03:56,439
to return some data if the user is logged in

72
00:03:56,439 --> 00:03:58,796
and a different data if they are logged out.

73
00:03:58,796 --> 00:04:02,066
And also of course, get_jwt_identity can be really useful

74
00:04:02,066 --> 00:04:06,182
to actually see who the user is that is logged in.

75
00:04:06,182 --> 00:04:11,139
This is going to give us the data that we saved in the jwt.

76
00:04:11,139 --> 00:04:15,490
Of course, you could do user model dot find by ID user ID

77
00:04:15,490 --> 00:04:19,445
to get a user model using that identity

78
00:04:19,445 --> 00:04:22,317
that we've stored in the jwt.

79
00:04:22,317 --> 00:04:25,468
Okay, with that said, we are going to clear this

80
00:04:25,468 --> 00:04:29,867
and run the app, and then we're gonna go over to Postman

81
00:04:29,867 --> 00:04:32,617
and we are going to try this out.

82
00:04:34,329 --> 00:04:37,912
So, we have an item stored in our database.

83
00:04:41,433 --> 00:04:43,878
This is the one my item there.

84
00:04:43,878 --> 00:04:48,295
And we can get all of the items, as you can see here.

85
00:04:50,600 --> 00:04:53,281
Okay, so we have a list of items

86
00:04:53,281 --> 00:04:56,354
that just has the item name, and it says,

87
00:04:56,354 --> 00:04:58,886
"More data available if you log in."

88
00:04:58,886 --> 00:05:01,508
Of course, Postman, or rather, our app

89
00:05:01,508 --> 00:05:04,524
doesn't know we're logged in because we don't have a header.

90
00:05:04,524 --> 00:05:06,937
So if we include it, if we include the authorization header

91
00:05:06,937 --> 00:05:09,520
with bearer access token there,

92
00:05:12,228 --> 00:05:16,620
as soon as we do that, we now get the full dictionary

93
00:05:16,620 --> 00:05:20,368
of items here, the full list of dictionaries there.

94
00:05:20,368 --> 00:05:23,283
So this is how you can return different amounts

95
00:05:23,283 --> 00:05:25,808
of information, depending on whether the user

96
00:05:25,808 --> 00:05:28,068
is logged in or not.

97
00:05:28,068 --> 00:05:31,223
That's it for this video, I'll see you on the next one.

