1
00:00:00,980 --> 00:00:02,830
Hey guys, welcome back.

2
00:00:02,830 --> 00:00:04,890
In this video I just wanted to tell you a little bit

3
00:00:04,890 --> 00:00:07,870
about token freshness.

4
00:00:07,870 --> 00:00:12,050
We're going to be refreshing tokens in our REST API

5
00:00:12,050 --> 00:00:14,898
using Flask-JWT-Extended, but of course,

6
00:00:14,898 --> 00:00:18,010
we need to know what a fresh token is first.

7
00:00:18,010 --> 00:00:20,783
What does it mean to refresh a token?

8
00:00:21,930 --> 00:00:23,780
Have you ever see something

9
00:00:23,780 --> 00:00:25,330
that looks more or less like this:

10
00:00:25,330 --> 00:00:30,330
you're logged in in a website and you're just browsing along

11
00:00:30,710 --> 00:00:33,040
without a problem and suddenly,

12
00:00:33,040 --> 00:00:36,670
you get asked to confirm your password to continue,

13
00:00:36,670 --> 00:00:40,540
or to enter your credentials again just

14
00:00:40,540 --> 00:00:42,630
to make sure that you are you?

15
00:00:42,630 --> 00:00:45,070
This normally happens when you are just browsing along

16
00:00:45,070 --> 00:00:49,780
and then you wanna do something that's a bit more critical.

17
00:00:49,780 --> 00:00:52,310
For example, maybe you wanna change your password,

18
00:00:52,310 --> 00:00:54,930
or maybe you want to delete something in your account

19
00:00:54,930 --> 00:00:56,370
that's maybe important.

20
00:00:56,370 --> 00:00:58,630
In this case I was on GitHub,

21
00:00:58,630 --> 00:01:01,670
wanting to delete an existing repository

22
00:01:01,670 --> 00:01:04,933
and GitHub asked me for my password to continue.

23
00:01:05,870 --> 00:01:07,293
Why do they do that?

24
00:01:08,920 --> 00:01:13,320
The answer is they do it because they realise

25
00:01:13,320 --> 00:01:17,610
that I am logged in, but I haven't given them my username

26
00:01:17,610 --> 00:01:20,120
and password for a few days.

27
00:01:20,120 --> 00:01:23,750
So although it's unlikely somebody has stolen my computer,

28
00:01:23,750 --> 00:01:25,430
it is possible.

29
00:01:25,430 --> 00:01:28,140
So when I'm doing something quite critical,

30
00:01:28,140 --> 00:01:30,510
they want to make sure that it really is me

31
00:01:30,510 --> 00:01:33,170
and it's not the very unlikely scenario

32
00:01:33,170 --> 00:01:36,520
that somebody else has stolen my device.

33
00:01:36,520 --> 00:01:40,960
So in these cases, they want what's called a fresh token.

34
00:01:40,960 --> 00:01:44,190
They want to make sure that I am me.

35
00:01:44,190 --> 00:01:47,410
So, what happens is that you're already logged in

36
00:01:47,410 --> 00:01:49,850
but you have to enter your password again.

37
00:01:49,850 --> 00:01:51,460
So, here we go.

38
00:01:51,460 --> 00:01:53,590
What you need is a fresh token.

39
00:01:53,590 --> 00:01:57,630
And this is more or less the flow, okay.

40
00:01:57,630 --> 00:02:00,270
You start off at the left where you log in,

41
00:02:00,270 --> 00:02:02,210
and when you log in, as soon as you log in,

42
00:02:02,210 --> 00:02:03,580
you enter your username and password,

43
00:02:03,580 --> 00:02:06,323
what you have is a fresh token.

44
00:02:07,260 --> 00:02:11,650
Then you browse along, you check out a couple of pages,

45
00:02:11,650 --> 00:02:13,960
not a problem, and then maybe you leave and,

46
00:02:13,960 --> 00:02:15,920
you know, you go away.

47
00:02:15,920 --> 00:02:18,053
You come back the next day, one day later,

48
00:02:19,190 --> 00:02:21,240
and you continue browsing.

49
00:02:21,240 --> 00:02:22,160
And that's fine.

50
00:02:22,160 --> 00:02:24,192
You're token has expired, the initial token that you got

51
00:02:24,192 --> 00:02:28,290
when you logged in, that has expired,

52
00:02:28,290 --> 00:02:32,610
but, the website or the mobile app automatically realises

53
00:02:32,610 --> 00:02:34,090
that you're still logged in,

54
00:02:34,090 --> 00:02:37,400
you're gonna refresh your token,

55
00:02:37,400 --> 00:02:39,790
you're going to use the information

56
00:02:39,790 --> 00:02:44,650
that you already have on file to realise

57
00:02:44,650 --> 00:02:46,440
that you're still logged in.

58
00:02:46,440 --> 00:02:49,140
It's unlikely that somebody has stolen your device,

59
00:02:49,140 --> 00:02:52,760
so they can still let you browse around the website.

60
00:02:52,760 --> 00:02:54,720
What would happen here is that you

61
00:02:54,720 --> 00:02:58,180
would have refreshed your token, okay.

62
00:02:58,180 --> 00:03:00,210
We're gonna look at exactly how to refresh a token

63
00:03:00,210 --> 00:03:01,600
in the next couple of videos.

64
00:03:01,600 --> 00:03:03,840
But what the website would do in this case is,

65
00:03:03,840 --> 00:03:06,120
the initial token has expired,

66
00:03:06,120 --> 00:03:08,910
you are about to continue browsing,

67
00:03:08,910 --> 00:03:10,440
they don't wanna ask you for your username

68
00:03:10,440 --> 00:03:12,860
and password again, because, you know, asking for

69
00:03:12,860 --> 00:03:14,850
that every day is quite cumbersome.

70
00:03:14,850 --> 00:03:17,850
So what they do is they refresh your token.

71
00:03:17,850 --> 00:03:21,010
They use the information they already have on file

72
00:03:21,010 --> 00:03:25,470
to issue you a new access token completely free of charge

73
00:03:25,470 --> 00:03:28,270
or without having to enter your username and password again.

74
00:03:28,270 --> 00:03:31,440
But then let's say that after browsing you wanna go

75
00:03:31,440 --> 00:03:33,340
and change your password.

76
00:03:33,340 --> 00:03:34,993
That's a critical operation.

77
00:03:36,410 --> 00:03:40,810
So, because it's been a while since you gave your details,

78
00:03:40,810 --> 00:03:45,810
this website may now wonder whether is it really you

79
00:03:45,850 --> 00:03:47,420
or is it someone else.

80
00:03:47,420 --> 00:03:48,970
You know, because it's not everyday

81
00:03:48,970 --> 00:03:50,820
that you change your password, right.

82
00:03:51,660 --> 00:03:53,470
So in that case, instead of going straight

83
00:03:53,470 --> 00:03:56,770
to the password change, a site, they'll ask you

84
00:03:56,770 --> 00:03:58,220
to enter your password again.

85
00:03:59,100 --> 00:04:02,890
This, entering the password again, allows them to know

86
00:04:02,890 --> 00:04:06,820
that it is you and then you can go ahead

87
00:04:06,820 --> 00:04:08,750
and change your password.

88
00:04:08,750 --> 00:04:12,520
The way we're gonna replicate this using Flask-JWT-Extended,

89
00:04:12,520 --> 00:04:15,010
is precisely with token refreshing.

90
00:04:15,010 --> 00:04:18,920
So, for as long as we can, we are going

91
00:04:18,920 --> 00:04:21,150
to be refreshing tokens, essentially.

92
00:04:21,150 --> 00:04:23,560
As soon as the initial token expires,

93
00:04:23,560 --> 00:04:25,593
we will refresh it and issue a new one.

94
00:04:26,440 --> 00:04:28,300
And when that one expires we will refresh it

95
00:04:28,300 --> 00:04:29,133
and issue a new one.

96
00:04:29,133 --> 00:04:32,410
And so on until they do something critical.

97
00:04:32,410 --> 00:04:33,840
By the time they do something critical

98
00:04:33,840 --> 00:04:37,850
we will know whether the token they are currently using

99
00:04:37,850 --> 00:04:42,779
to do that is a token that was generated from logging in,

100
00:04:42,779 --> 00:04:47,483
or is it a token that was generated from refreshing.

101
00:04:48,690 --> 00:04:50,230
Okay.

102
00:04:50,230 --> 00:04:55,230
So, if the token itself doesn't expire after a few hours,

103
00:04:58,130 --> 00:05:00,540
the token that you get when you log in doesn't expire

104
00:05:00,540 --> 00:05:04,130
after a few hours, you'll see something like this.

105
00:05:04,130 --> 00:05:06,740
It says here, you're entering pseudo mode.

106
00:05:06,740 --> 00:05:10,240
We won't ask for your password again for a few hours.

107
00:05:10,240 --> 00:05:14,400
That we can replicate by not allowing our tokens

108
00:05:14,400 --> 00:05:16,810
to expire for a few hours.

109
00:05:16,810 --> 00:05:17,980
Okay?

110
00:05:17,980 --> 00:05:22,980
Up until this point, we had what's called a non-fresh token.

111
00:05:23,290 --> 00:05:26,340
That is a token that was generated from refreshing,

112
00:05:26,340 --> 00:05:29,490
as opposed to from giving our username and password.

113
00:05:29,490 --> 00:05:32,100
As soon as we type our password in,

114
00:05:32,100 --> 00:05:34,053
now we have a fresh token.

115
00:05:35,100 --> 00:05:37,680
With a fresh token, we can know

116
00:05:37,680 --> 00:05:39,633
that this is the person we think it is.

117
00:05:40,610 --> 00:05:43,730
Without a fresh token, maybe their device got stolen,

118
00:05:43,730 --> 00:05:45,043
or something like that.

119
00:05:46,600 --> 00:05:49,190
In this case, you can see GitHub won't ask you

120
00:05:49,190 --> 00:05:51,330
for your password again for a few hours,

121
00:05:51,330 --> 00:05:53,370
that's because, well, we can replicate

122
00:05:53,370 --> 00:05:57,490
that using Flask-JWT-Extended by allowing our tokens

123
00:05:57,490 --> 00:06:00,620
to live for a few hours and not letting them expire.

124
00:06:00,620 --> 00:06:04,060
That way, we would keep a fresh token for a few hours,

125
00:06:04,060 --> 00:06:05,720
then we would refresh and we

126
00:06:05,720 --> 00:06:07,680
would no longer have a fresh token.

127
00:06:07,680 --> 00:06:09,690
The next time we wanna do something like this,

128
00:06:09,690 --> 00:06:12,126
we would have to ask the user for their password again

129
00:06:12,126 --> 00:06:17,126
so we get another fresh token and we revalidate the user is

130
00:06:17,183 --> 00:06:18,423
who they say they are.

131
00:06:20,040 --> 00:06:23,780
All right, so a fresh token, just to recap,

132
00:06:23,780 --> 00:06:25,840
is a token you've received

133
00:06:25,840 --> 00:06:28,083
after entering your username and password.

134
00:06:29,330 --> 00:06:31,220
And then the site can be confident it's you

135
00:06:31,220 --> 00:06:32,910
and not someone else.

136
00:06:32,910 --> 00:06:36,170
A non-fresh token is a token you've received

137
00:06:36,170 --> 00:06:38,810
by refreshing a previous token.

138
00:06:38,810 --> 00:06:41,150
We're going to look at how to do refreshing

139
00:06:41,150 --> 00:06:42,370
in the next couple if videos,

140
00:06:42,370 --> 00:06:44,323
so stay tuned and I'll see you there.

