1
00:00:01,290 --> 00:00:02,640
Hi, and welcome back.

2
00:00:02,640 --> 00:00:03,940
In this video we're going to learn

3
00:00:03,940 --> 00:00:07,410
how to configure Flask-JWT-Extended.

4
00:00:07,410 --> 00:00:09,361
Let's open up our app.py

5
00:00:09,361 --> 00:00:12,040
and we're gonna add our first piece of configure

6
00:00:12,040 --> 00:00:13,738
just to help explain,

7
00:00:13,738 --> 00:00:16,423
what exactly we're going to be configuring.

8
00:00:17,910 --> 00:00:20,420
The first piece of configuration we're gonna do

9
00:00:20,420 --> 00:00:23,380
starts with @jwt.expired_token_loader.

10
00:00:24,680 --> 00:00:27,920
Now, just for completeness this @jwt here

11
00:00:27,920 --> 00:00:31,066
is this variable that we've created, our JWTManager,

12
00:00:31,066 --> 00:00:34,800
expired_token_loader is something inside that variable.

13
00:00:34,800 --> 00:00:37,760
So, just like importing something from a module

14
00:00:37,760 --> 00:00:40,760
this accesses something from this variable here,

15
00:00:40,760 --> 00:00:42,120
and then we're gonna have

16
00:00:42,120 --> 00:00:45,080
an expired_token_callback function.

17
00:00:45,080 --> 00:00:47,080
This can be called whatever you want of course,

18
00:00:47,080 --> 00:00:49,630
it is decorated by this function here.

19
00:00:49,630 --> 00:00:50,952
This decorator here.

20
00:00:50,952 --> 00:00:53,093
Now, what does this do?

21
00:00:55,254 --> 00:00:57,150
In our JWT manager,

22
00:00:57,150 --> 00:00:59,440
we are decorating this function,

23
00:00:59,440 --> 00:01:02,220
with an expired_token_loader.

24
00:01:02,220 --> 00:01:05,640
That means that when Flask-JWT-Extended

25
00:01:05,640 --> 00:01:10,210
realises that an access token that has been sent to us

26
00:01:10,210 --> 00:01:13,453
has already expired, they expire after five minutes I think,

27
00:01:14,790 --> 00:01:16,530
it will call this function

28
00:01:16,530 --> 00:01:18,560
in order for us to tell it

29
00:01:18,560 --> 00:01:21,380
what message it should send back to the user

30
00:01:21,380 --> 00:01:23,380
telling it that their token has expired.

31
00:01:24,610 --> 00:01:27,440
Okay, so if the token expired

32
00:01:27,440 --> 00:01:30,650
we're gonna give them this message here.

33
00:01:30,650 --> 00:01:35,353
It's gonna be description, the token has expired,

34
00:01:37,020 --> 00:01:40,460
and the error, is gonna be token_expired.

35
00:01:40,460 --> 00:01:43,300
You can put whatever you want in here of course,

36
00:01:43,300 --> 00:01:46,540
but I'm just going with a nice text description,

37
00:01:46,540 --> 00:01:48,510
that maybe they can show in their mobile app,

38
00:01:48,510 --> 00:01:50,150
or on their website or something like that,

39
00:01:50,150 --> 00:01:52,970
and also an error code that won't change ever,

40
00:01:52,970 --> 00:01:56,323
so that they can see that this is what the error means.

41
00:01:57,600 --> 00:01:59,120
So just to recap,

42
00:01:59,120 --> 00:02:01,080
when the token has expired,

43
00:02:01,080 --> 00:02:03,060
for example if they log in,

44
00:02:03,060 --> 00:02:04,797
and they don't refresh their token

45
00:02:04,797 --> 00:02:08,410
and they perform another action, maybe half an hour later,

46
00:02:08,410 --> 00:02:11,620
what we're gonna say is, your token has expired,

47
00:02:11,620 --> 00:02:13,820
because they only last five minutes I think,

48
00:02:14,730 --> 00:02:16,460
so we're gonna give them this message

49
00:02:16,460 --> 00:02:19,360
and essentially ask them to authenticate themselves again.

50
00:02:20,710 --> 00:02:21,543
So that's it.

51
00:02:21,543 --> 00:02:23,600
When that happens, they'll get this message,

52
00:02:23,600 --> 00:02:26,440
as opposed to the default message

53
00:02:26,440 --> 00:02:28,050
that Flask-JWT-Extended sends

54
00:02:28,050 --> 00:02:30,953
that has some sort of MSG and ERR,

55
00:02:33,540 --> 00:02:34,690
I dunno, I just like

56
00:02:34,690 --> 00:02:37,130
being a bit more clear with what things are,

57
00:02:37,130 --> 00:02:38,580
and but that's maybe just me.

58
00:02:39,760 --> 00:02:41,340
this is the expired token.

59
00:02:41,340 --> 00:02:43,020
We're gonna look at a couple more.

60
00:02:43,020 --> 00:02:46,960
We're gonna look at jwt.invalid_token_loader.

61
00:02:46,960 --> 00:02:49,756
We're gonna look at jwt.unauthorized_loader.

62
00:02:49,756 --> 00:02:53,106
We're gonna look at jwt.needs_fresh_token_loader

63
00:02:53,106 --> 00:02:57,420
and jwt.revoked_token.

64
00:02:57,420 --> 00:03:00,120
These are just four more configurations,

65
00:03:00,120 --> 00:03:01,840
and these will happen,

66
00:03:01,840 --> 00:03:04,361
when certain things happen.

67
00:03:04,361 --> 00:03:05,710
Invalid_token_loader,

68
00:03:05,710 --> 00:03:07,200
the function that this is gonna decorate,

69
00:03:07,200 --> 00:03:08,370
which is gonna be down here,

70
00:03:08,370 --> 00:03:12,370
is gonna be called when the token they send us

71
00:03:12,370 --> 00:03:14,750
in the authorization header

72
00:03:14,750 --> 00:03:17,860
is not an actual JWT.

73
00:03:17,860 --> 00:03:20,190
For example, if you type in a random string

74
00:03:20,190 --> 00:03:22,136
in the authorization header,

75
00:03:22,136 --> 00:03:24,920
it's gonna say, what are you doing, first of all,

76
00:03:24,920 --> 00:03:26,460
and then it's gonna return

77
00:03:26,460 --> 00:03:29,440
whatever this function gives back to you.

78
00:03:29,440 --> 00:03:32,255
So if you wanna return from this function,

79
00:03:32,255 --> 00:03:35,480
which we're gonna call invalid_token_callback,

80
00:03:36,950 --> 00:03:38,803
and this actually takes in an error.

81
00:03:39,780 --> 00:03:40,720
If you wanna return,

82
00:03:40,720 --> 00:03:44,083
'What are you doing?', 401

83
00:03:46,550 --> 00:03:47,460
you can do that.

84
00:03:47,460 --> 00:03:50,130
Maybe not the nicest message to give a user,

85
00:03:50,130 --> 00:03:52,340
but when they type in a random string

86
00:03:52,340 --> 00:03:53,870
in the authorization header,

87
00:03:53,870 --> 00:03:56,090
this is what will go back to them.

88
00:03:56,090 --> 00:03:57,040
So instead of doing this,

89
00:03:57,040 --> 00:04:01,083
maybe we can do a jsonify of,

90
00:04:03,930 --> 00:04:04,980
missed that one,

91
00:04:04,980 --> 00:04:07,493
there you go, there we go, that's it.

92
00:04:08,540 --> 00:04:11,370
The description is gonna be something like

93
00:04:11,370 --> 00:04:14,070
a signature verification failed.

94
00:04:14,070 --> 00:04:15,330
That's just a fancy way of saying

95
00:04:15,330 --> 00:04:19,180
we tried to check that this is a JWT, but it's actually not.

96
00:04:19,180 --> 00:04:22,920
And the error is gonna be invalid_token.

97
00:04:22,920 --> 00:04:23,910
There you have it,

98
00:04:23,910 --> 00:04:26,130
now when they submit an invalid token,

99
00:04:26,130 --> 00:04:29,070
something we think is a JWT but isn't,

100
00:04:29,070 --> 00:04:33,100
we'll try to decrypt it to access the user's identity

101
00:04:33,100 --> 00:04:36,310
and other data stored in the JWT but we won't be able to,

102
00:04:36,310 --> 00:04:37,900
because it won't be a JWT,

103
00:04:37,900 --> 00:04:39,750
and then we will return this message.

104
00:04:41,380 --> 00:04:42,970
For the unauthorized_loader

105
00:04:42,970 --> 00:04:44,070
this is going to be called

106
00:04:44,070 --> 00:04:47,700
when they don't send us a JWT at all.

107
00:04:47,700 --> 00:04:50,650
And so that just means, you know, you need to send the JWT,

108
00:04:50,650 --> 00:04:51,490
you didn't send one,

109
00:04:51,490 --> 00:04:53,940
so you're not authorised to access this endpoint.

110
00:04:54,873 --> 00:04:56,880
The needs_fresh_token_loader,

111
00:04:56,880 --> 00:04:58,570
you can probably guess what that does.

112
00:04:58,570 --> 00:05:00,990
When they send us a non-fresh token

113
00:05:00,990 --> 00:05:03,870
but we require a fresh token in our endpoint.

114
00:05:03,870 --> 00:05:08,220
For example, in our item post, we've got fresh_jwt_required,

115
00:05:08,220 --> 00:05:10,150
so if they don't send a fresh token,

116
00:05:10,150 --> 00:05:13,020
we will call this function.

117
00:05:13,020 --> 00:05:16,540
Finally, the revoke_token_loader is an interesting one here.

118
00:05:16,540 --> 00:05:19,210
We're gonna look more at token revoking

119
00:05:19,210 --> 00:05:20,930
in the next couple of videos,

120
00:05:20,930 --> 00:05:23,400
but essentially in Flask-JWT-Extended

121
00:05:23,400 --> 00:05:25,210
you can revoke a token.

122
00:05:25,210 --> 00:05:28,410
You can say, this token is no longer valid.

123
00:05:28,410 --> 00:05:29,680
Here's a use case.

124
00:05:29,680 --> 00:05:34,283
Say your user logs in, and they get an access token,

125
00:05:35,340 --> 00:05:38,575
and then they maybe do a couple of requests

126
00:05:38,575 --> 00:05:41,060
and then they wanna log out.

127
00:05:41,060 --> 00:05:44,920
Well how do you log out a user who has a valid access token?

128
00:05:44,920 --> 00:05:47,000
You can't take it away from them,

129
00:05:47,000 --> 00:05:49,500
they've already maybe got it saved on their mobile phone,

130
00:05:49,500 --> 00:05:51,400
or maybe on postman, or something.

131
00:05:51,400 --> 00:05:52,610
So what do you do?

132
00:05:52,610 --> 00:05:55,200
You add it to the revoked token list.

133
00:05:55,200 --> 00:05:57,833
That way, when that access token comes back,

134
00:05:58,810 --> 00:06:00,540
you call this function here and you say,

135
00:06:00,540 --> 00:06:02,150
this token has been revoked,

136
00:06:02,150 --> 00:06:05,230
or maybe you can say, you have been logged out,

137
00:06:05,230 --> 00:06:06,380
or something like that.

138
00:06:07,350 --> 00:06:08,720
Now, these are all gonna be

139
00:06:08,720 --> 00:06:10,438
fairly similar to these ones here.

140
00:06:10,438 --> 00:06:12,230
They're just gonna return some JSON,

141
00:06:12,230 --> 00:06:13,063
so what we're gonna do is

142
00:06:13,063 --> 00:06:14,950
I'm just gonna copy them from my notes

143
00:06:16,140 --> 00:06:18,694
and then briefly talk over what they are.

144
00:06:18,694 --> 00:06:22,070
I just copied in here, we've got the unauthorized_loader,

145
00:06:22,070 --> 00:06:23,710
and I've added a function down there

146
00:06:23,710 --> 00:06:25,660
called missing_token_callback,

147
00:06:25,660 --> 00:06:28,280
and that just returns another JSON string,

148
00:06:28,280 --> 00:06:31,610
that says, request does not contain an access token.

149
00:06:31,610 --> 00:06:34,540
For the needs_fresh_token_loader, I've added a new function,

150
00:06:34,540 --> 00:06:37,150
that I've called, token_not_fresh_callback,

151
00:06:37,150 --> 00:06:39,080
and that also returns some JSON, that says,

152
00:06:39,080 --> 00:06:40,800
this token is not fresh,

153
00:06:40,800 --> 00:06:42,370
and for the revoked_token_loader,

154
00:06:42,370 --> 00:06:44,400
I've added another one that says,

155
00:06:44,400 --> 00:06:45,793
the token has been revoked.

156
00:06:47,200 --> 00:06:49,100
So that's how you can configure

157
00:06:49,100 --> 00:06:51,810
these things here in Flask-JWT-Extended.

158
00:06:51,810 --> 00:06:53,890
There are a couple more things you can configure,

159
00:06:53,890 --> 00:06:57,390
but we can't just go over every piece of everything

160
00:06:57,390 --> 00:06:59,950
in Flask-JWT-Extended, that would be quite boring,

161
00:06:59,950 --> 00:07:03,650
so if you do need to configure something more specific

162
00:07:03,650 --> 00:07:05,432
please check the official documentation,

163
00:07:05,432 --> 00:07:08,170
and for Flask-JWT-Extended it's actually quite good,

164
00:07:08,170 --> 00:07:10,260
and it guides you over every little setting

165
00:07:10,260 --> 00:07:12,710
that you can change in it, which are quite a lot.

166
00:07:13,600 --> 00:07:14,928
So that's it for this video.

167
00:07:14,928 --> 00:07:16,607
Just wanted to tell you a little bit about this,

168
00:07:16,607 --> 00:07:18,257
and I'll see you on the next one.

