1
00:00:01,739 --> 00:00:02,810
(Jose) Hi, and welcome back.

2
00:00:02,810 --> 00:00:04,740
In this video we're going to be creating

3
00:00:04,740 --> 00:00:07,335
a token refresh resource that,

4
00:00:07,335 --> 00:00:11,503
given the refresh token we created initially,

5
00:00:11,503 --> 00:00:14,563
will give us a non-fresh access token.

6
00:00:15,430 --> 00:00:17,680
Let's go ahead into our user resource

7
00:00:17,680 --> 00:00:19,690
and start creating that.

8
00:00:19,690 --> 00:00:21,540
So we're going to down to the very bottom

9
00:00:21,540 --> 00:00:24,450
of this resource and add a new one here.

10
00:00:24,450 --> 00:00:27,190
And by the way I'm adding all these small resources

11
00:00:27,190 --> 00:00:30,630
related to users inside my user.py file.

12
00:00:30,630 --> 00:00:32,060
But you can add them wherever you want.

13
00:00:32,060 --> 00:00:34,760
If you want to split them out into multiple files

14
00:00:34,760 --> 00:00:35,860
you can do that.

15
00:00:35,860 --> 00:00:37,300
But because they're quite small

16
00:00:37,300 --> 00:00:40,513
and because we can always shrink them like that,

17
00:00:40,513 --> 00:00:42,340
I'm adding them in the same file.

18
00:00:42,340 --> 00:00:45,849
And you know, 67 lines, 100 lines, is not a lot for a file.

19
00:00:45,849 --> 00:00:48,790
Alright, so now that we are here,

20
00:00:48,790 --> 00:00:53,413
let's go ahead and create our token refresh resource.

21
00:00:54,374 --> 00:00:57,650
What this is going to do, is it is going

22
00:00:57,650 --> 00:01:01,800
to receive the refresh token we created initially.

23
00:01:01,800 --> 00:01:04,900
So I'm going to expand the user log in resource

24
00:01:04,900 --> 00:01:07,280
and see here, remember how initially

25
00:01:07,280 --> 00:01:10,410
we created refresh token that we give to our users

26
00:01:10,410 --> 00:01:14,123
as well as the access token, which is the main jwt.

27
00:01:14,123 --> 00:01:17,363
This refresh token is never going to change.

28
00:01:18,300 --> 00:01:20,870
So all they have to do is send it to

29
00:01:20,870 --> 00:01:23,650
this token refresh resource and we are going

30
00:01:23,650 --> 00:01:26,347
to generate a new access token,

31
00:01:26,347 --> 00:01:28,300
but it's not going to be fresh.

32
00:01:28,300 --> 00:01:29,773
Fresh is going to be false.

33
00:01:30,610 --> 00:01:33,428
So I'm pretty sure you'll be able to do most of this,

34
00:01:33,428 --> 00:01:36,630
except for one little thing that we've not talked about yet.

35
00:01:36,630 --> 00:01:38,470
Oh sorry, I expended that by accident.

36
00:01:38,470 --> 00:01:40,320
One little thing we've not talked about yet,

37
00:01:40,320 --> 00:01:45,150
which is the jwt refresh token required.

38
00:01:45,150 --> 00:01:47,440
This is a new decorator that we're going to have to import.

39
00:01:47,440 --> 00:01:48,580
I'm just going to copy that and go up

40
00:01:48,580 --> 00:01:52,437
to the top of the file and get it from here.

41
00:01:52,437 --> 00:01:55,760
So what we need to do is,

42
00:01:55,760 --> 00:01:57,540
in this method here,

43
00:01:57,540 --> 00:02:01,066
we will be receiving a refresh token.

44
00:02:01,066 --> 00:02:03,930
Now if we call this method

45
00:02:05,752 --> 00:02:09,500
and we don't have a refresh token in the request,

46
00:02:09,500 --> 00:02:12,612
flask jwt extended is not going to to bring us in here.

47
00:02:12,612 --> 00:02:15,340
It's going to return an error.

48
00:02:15,340 --> 00:02:16,793
It's going to say, you know, 401,

49
00:02:18,033 --> 00:02:18,866
you didn't authenticate properly,

50
00:02:18,866 --> 00:02:19,699
you need to send more data.

51
00:02:20,570 --> 00:02:24,350
So, by the time we are running this line 70 here,

52
00:02:24,350 --> 00:02:26,123
we have a refresh token.

53
00:02:27,050 --> 00:02:28,883
And because we have a refresh token,

54
00:02:32,568 --> 00:02:34,810
that means we can use it to get the jwt identity.

55
00:02:34,810 --> 00:02:36,473 line:15% 
So we can see current_user is get_jwt_identity.

56
00:02:40,580 --> 00:02:43,830 line:15% 
Now, we imported this on the item resource earlier

57
00:02:43,830 --> 00:02:46,080 line:15% 
but we didn't import it in the user resource.

58
00:02:47,182 --> 00:02:49,199
So let's go ahead and and do that.

59
00:02:49,199 --> 00:02:50,200
And because this is getting quite long,

60
00:02:50,200 --> 00:02:52,340
we are going to use the bracket notification in Python

61
00:02:52,340 --> 00:02:56,310
to import multiple packages from the same module.

62
00:02:56,310 --> 00:02:57,143
Like that.

63
00:02:57,143 --> 00:02:58,090
It's totally fine.

64
00:02:58,090 --> 00:03:00,210
You cannot ignore the brackets in here,

65
00:03:00,210 --> 00:03:02,390
you need the brackets to be able

66
00:03:02,390 --> 00:03:03,680
to import in multiple lines.

67
00:03:03,680 --> 00:03:05,460
But this looks a little bit tidier there.

68
00:03:05,460 --> 00:03:07,883
And we've imported get_jwt_identity,

69
00:03:07,883 --> 00:03:10,471
and you can see that get_jwt_identity works

70
00:03:10,471 --> 00:03:14,439
with a refresh token as well as with an access token,

71
00:03:14,439 --> 00:03:16,880
so we have a refresh token here,

72
00:03:16,880 --> 00:03:18,837
but we can use it to get the jwt identity,

73
00:03:18,837 --> 00:03:21,951
which as you know is the user ID.

74
00:03:21,951 --> 00:03:24,084
Then, we're going to create a new token,

75
00:03:24,084 --> 00:03:26,240
it's going to be create_access_token.

76
00:03:26,240 --> 00:03:30,479
The identity is going to be the current user.

77
00:03:30,479 --> 00:03:33,910
And fresh is going to be false.

78
00:03:33,910 --> 00:03:36,105
The access token we are going to give back

79
00:03:36,105 --> 00:03:38,840
is not going to be fresh.

80
00:03:38,840 --> 00:03:41,199
Now, that means that they're probably going to save it,

81
00:03:41,199 --> 00:03:44,015
they're going to send it back in with the next request,

82
00:03:44,015 --> 00:03:47,900
and we will be able to check whether it is fresh or not.

83
00:03:47,900 --> 00:03:50,360
If it's fresh, just as a reminder,

84
00:03:50,360 --> 00:03:52,570
it means that they have just given us

85
00:03:53,656 --> 00:03:54,489
their user name and password.

86
00:03:54,489 --> 00:03:56,060
We can be really confident that they

87
00:03:56,060 --> 00:03:57,880
are who they say they are.

88
00:03:57,880 --> 00:04:00,840
If it's not fresh, it means that maybe they typed

89
00:04:00,840 --> 00:04:03,590
their user name and password a couple of days ago.

90
00:04:03,590 --> 00:04:05,810
So maybe they've lost their device,

91
00:04:05,810 --> 00:04:07,403
their mobile phone or their laptop,

92
00:04:07,403 --> 00:04:10,280
and they are not who they say they are.

93
00:04:10,280 --> 00:04:13,040
So, for example, if they wanted to change their password

94
00:04:13,040 --> 00:04:16,000
and they have a non-fresh token, we may ask them

95
00:04:16,000 --> 00:04:17,410
for a fresh token instead.

96
00:04:17,410 --> 00:04:19,625
We may ask them to enter the username and password.

97
00:04:19,625 --> 00:04:21,611
That way we just ensure a bit more security,

98
00:04:21,611 --> 00:04:24,650
but we don't have to keep asking them passwords

99
00:04:24,650 --> 00:04:28,070
if all they wanna do is, I don't know, see their contacts

100
00:04:28,070 --> 00:04:33,070
or maybe look at their feeds in Instagram or Facebook

101
00:04:33,790 --> 00:04:35,670
or something like that.

102
00:04:35,670 --> 00:04:38,209
So, now that we've got our new token created,

103
00:04:38,209 --> 00:04:40,660
we can just go ahead and return it.

104
00:04:40,660 --> 00:04:45,660
So we're going to return access_token is the new token

105
00:04:45,781 --> 00:04:47,398
that we've created.

106
00:04:47,398 --> 00:04:49,750
And you can put the 200 in there.

107
00:04:49,750 --> 00:04:51,670
Don't need to put it in, that's a default value

108
00:04:51,670 --> 00:04:53,070
that's going to be returne, but nevertheless

109
00:04:53,070 --> 00:04:55,803
it's always good to be explicit with these things.

110
00:04:56,940 --> 00:04:57,773
That's it.

111
00:04:57,773 --> 00:04:59,300
Now we've got this saved.

112
00:04:59,300 --> 00:05:01,580
We can go ahead and add it to our app.py.

113
00:05:01,580 --> 00:05:04,880
So I'm going to double click that and open app.py.

114
00:05:04,880 --> 00:05:07,250
And from resources.user we're gonna import

115
00:05:07,250 --> 00:05:09,120
user register, user, user log in,

116
00:05:09,120 --> 00:05:12,039
and now token refresh as well.

117
00:05:12,039 --> 00:05:14,040
Here if we want you can also put this

118
00:05:14,040 --> 00:05:15,730
in multiple lines if that make you feel better.

119
00:05:15,730 --> 00:05:17,120
But I think it's quite short

120
00:05:17,120 --> 00:05:19,840
so I'm going to leave it in one line just yet.

121
00:05:19,840 --> 00:05:22,713
And we can more it into more lines later on if we have to.

122
00:05:23,730 --> 00:05:25,830
Now that we've imported it, we can go ahead

123
00:05:27,231 --> 00:05:28,064 line:15% 
and add it as a resource down here.

124
00:05:29,378 --> 00:05:30,211 line:15% 
So we're going to do api.add_resource.

125
00:05:32,728 --> 00:05:34,093 line:15% 
And it's going to read a token refresh,

126
00:05:35,073 --> 00:05:38,423 line:15% 
and this endpoint is going to be the slash refresh endpoint.

127
00:05:39,420 --> 00:05:42,103
That's it.

128
00:05:43,129 --> 00:05:44,390
Now we can go over to Postman

129
00:05:44,390 --> 00:05:46,680
and try this out and see if this works.

130
00:05:46,680 --> 00:05:47,880
So the first thing that I'm going to do

131
00:05:47,880 --> 00:05:52,180
is I'm going to go ahead and launch the app.py.

132
00:05:52,180 --> 00:05:56,470
So for that I'm going to have to, of course,

133
00:05:56,470 --> 00:06:01,121
open up my virtual environment and then do python app.py.

134
00:06:01,121 --> 00:06:03,310
That's my app now running.

135
00:06:03,310 --> 00:06:06,380
We can go over to Postman, and of course

136
00:06:06,380 --> 00:06:09,780
we'll have to register, that's the first thing to do.

137
00:06:09,780 --> 00:06:11,050
Gonna create a new user.

138
00:06:11,050 --> 00:06:14,083
The user here is user2 abcxyz,

139
00:06:14,930 --> 00:06:16,788
it doesn't really matter what it is.

140
00:06:16,788 --> 00:06:19,080
Then we're going to have to go and log in.

141
00:06:19,080 --> 00:06:21,965
Just make sure that the user and the password match there.

142
00:06:21,965 --> 00:06:25,914
Now, we've got our access token saved into our collection,

143
00:06:25,914 --> 00:06:29,666
but our tests are not saving the refresh token.

144
00:06:29,666 --> 00:06:33,200
So, you know how to add a test to save the refresh token.

145
00:06:33,200 --> 00:06:34,760
It's the same as the access token.

146
00:06:34,760 --> 00:06:36,310
But for now we're just going to copy it

147
00:06:36,310 --> 00:06:38,289
and do this manually.

148
00:06:38,289 --> 00:06:41,171
Now that we've got this refresh token,

149
00:06:41,171 --> 00:06:44,100
we can go ahead and create a new endpoint

150
00:06:44,100 --> 00:06:49,100
that is going to do url/refresh.

151
00:06:50,850 --> 00:06:51,860
It's gonna be a post

152
00:06:53,193 --> 00:06:56,558
or did I actually call it a get?

153
00:06:56,558 --> 00:06:58,510
Did I call it a get?

154
00:06:58,510 --> 00:07:00,070
No, I called it a post, that's okay.

155
00:07:00,070 --> 00:07:00,903
My bad.

156
00:07:00,903 --> 00:07:03,070
Just couldn't remember if I misspelt that.

157
00:07:03,070 --> 00:07:04,900
This is going to be a post, because it has to receive

158
00:07:04,900 --> 00:07:06,230
data in the body.

159
00:07:06,230 --> 00:07:07,780
So we're going to go ahead in the body,

160
00:07:07,780 --> 00:07:10,358
sorry, in the headers, not in the body,

161
00:07:10,358 --> 00:07:14,759
and do authorization, and this is going to be Bearer

162
00:07:14,759 --> 00:07:18,440
and then our refresh token.

163
00:07:18,440 --> 00:07:19,603
Remember, this is not the access token,

164
00:07:19,603 --> 00:07:22,090
this is the refresh token that we've just copied

165
00:07:22,090 --> 00:07:24,768
from the result of the log in endpoint.

166
00:07:24,768 --> 00:07:26,443
And then we can send this over,

167
00:07:26,443 --> 00:07:29,378
and we get a new access token.

168
00:07:29,378 --> 00:07:32,220
We can just pick a few characters,

169
00:07:32,220 --> 00:07:34,410
ij9 for example,

170
00:07:34,410 --> 00:07:37,060
and maybe it's the same one,

171
00:07:37,060 --> 00:07:37,893
yeah there we go.

172
00:07:37,893 --> 00:07:40,414
Let's pick the last ones, this is always the same.

173
00:07:40,414 --> 00:07:44,170
And so, raxptni, and at the end you can see they're

174
00:07:44,170 --> 00:07:46,080
a little bit different down there.

175
00:07:46,080 --> 00:07:48,650
So, this is a completely different access token.

176
00:07:48,650 --> 00:07:51,843
It contains the same data, and a lot of it is

177
00:07:51,843 --> 00:07:55,980
quite similar, but some of these things are a bit different.

178
00:07:55,980 --> 00:07:59,223
And you can tell it is a different access token by that.

179
00:08:00,344 --> 00:08:02,100
You can use this access token

180
00:08:02,100 --> 00:08:04,700
as you would any other access token,

181
00:08:04,700 --> 00:08:09,500
but in the endpoint that require a fresh access token,

182
00:08:09,500 --> 00:08:11,777
you won't be able to use this one.

183
00:08:11,777 --> 00:08:13,550
You'll have to use a fresh token, i.e. you must have

184
00:08:13,550 --> 00:08:18,180
just logged in and used that token and not any other.

185
00:08:18,180 --> 00:08:19,920
We're going to look at how you can require

186
00:08:19,920 --> 00:08:22,610
a fresh access token in the very next video.

187
00:08:22,610 --> 00:08:23,710
So I'll see you there.

