1
00:00:01,310 --> 00:00:02,660
Hi, and welcome back.

2
00:00:02,660 --> 00:00:06,290
In this video we're going to start looking at blacklisting.

3
00:00:06,290 --> 00:00:10,680
A blacklist allows us to have a list of things that we don't

4
00:00:10,680 --> 00:00:12,393
want to allow access to.

5
00:00:13,920 --> 00:00:16,360
So, what we are going to do in this video is we're going

6
00:00:16,360 --> 00:00:20,940
to create a short blacklist of user IDs that we want

7
00:00:20,940 --> 00:00:22,323
to deny access to.

8
00:00:23,320 --> 00:00:25,960
So, let's go ahead and create a new file that I'm gonna

9
00:00:25,960 --> 00:00:30,460
call Blacklist dot py and here I'm going to create a simple

10
00:00:30,460 --> 00:00:33,550
constant set with the values two and three.

11
00:00:33,550 --> 00:00:36,240
So this is a set of values in python, two and three are

12
00:00:36,240 --> 00:00:41,170
the values inside it and these are the user IDs that

13
00:00:41,170 --> 00:00:42,974
will be denied access.

14
00:00:42,974 --> 00:00:47,974
So, user ID one will have access, but user ID two

15
00:00:48,510 --> 00:00:51,691
and user ID three won't have access, will automatically say

16
00:00:51,691 --> 00:00:53,513
you cannot access this.

17
00:00:54,370 --> 00:00:55,460
How are we going to do that?

18
00:00:55,460 --> 00:00:58,460
It won't work magically just by creating that file.

19
00:00:58,460 --> 00:01:02,381
We do have to add a little bit of configuration in here.

20
00:01:02,381 --> 00:01:05,029
The first thing is we have to enable the blacklist

21
00:01:05,029 --> 00:01:06,880
in flask jwt extended.

22
00:01:06,880 --> 00:01:10,523
By default it is disabled, so we have to do app dot config

23
00:01:10,523 --> 00:01:15,523
jwt underscore blacklist underscore enabled is

24
00:01:15,890 --> 00:01:18,870
gonna be true, and the second thing is

25
00:01:18,870 --> 00:01:23,870
app dot config jwt blacklist token

26
00:01:23,990 --> 00:01:28,890
checks are going to be a list of access and refresh.

27
00:01:28,890 --> 00:01:31,790
This just means we're gonna enable the blacklist for both

28
00:01:31,790 --> 00:01:34,310
access and refresh tokens.

29
00:01:34,310 --> 00:01:36,360
No matter what they send, we're going to say no

30
00:01:36,360 --> 00:01:37,553
you cannot access this.

31
00:01:39,040 --> 00:01:41,550
Now that we've done this, a blacklist is enabled,

32
00:01:41,550 --> 00:01:45,500
but it still doesn't know what is a blacklisted thing

33
00:01:45,500 --> 00:01:48,460
versus not a blacklisted thing.

34
00:01:48,460 --> 00:01:51,723
So, we have to make sure to do that.

35
00:01:54,540 --> 00:01:59,540
All to do is go ahead and down here add another loader.

36
00:01:59,920 --> 00:02:04,920
What we're going to do is say at jwt dot token

37
00:02:05,160 --> 00:02:10,160
in blacklist loader and this is going to be a function

38
00:02:10,560 --> 00:02:15,550
that returns true if the token that we're being sent is

39
00:02:15,550 --> 00:02:16,513
in the blacklist.

40
00:02:17,440 --> 00:02:19,610
And is has a return false if it is not in the blacklist.

41
00:02:19,610 --> 00:02:23,088
I am going to call this check if token in blacklist

42
00:02:23,088 --> 00:02:28,088
and it receives the parameter which is the decrypted token.

43
00:02:29,540 --> 00:02:33,830
In the decrypted token, we can access any data stored in the

44
00:02:33,830 --> 00:02:36,547
token, so this can be the identity.

45
00:02:36,547 --> 00:02:39,273
It can also be other things like when the token was created,

46
00:02:39,273 --> 00:02:42,052
a specific token ID, and so forth.

47
00:02:42,052 --> 00:02:45,630
We're gonna access the users identity, so we're gonna say

48
00:02:45,630 --> 00:02:50,120
return decrypted token identity.

49
00:02:50,120 --> 00:02:54,610
This identity field is in the jwt and it comes

50
00:02:54,610 --> 00:02:59,040
from the flask jwt extended internals,

51
00:02:59,040 --> 00:03:01,240
so we don't get to define this token,

52
00:03:01,240 --> 00:03:03,610
it just is there and it contains the value

53
00:03:03,610 --> 00:03:06,780
that we set when we created the access token.

54
00:03:06,780 --> 00:03:11,390
We're gonna say in blacklist we have to

55
00:03:11,390 --> 00:03:12,800
import blacklist as well.

56
00:03:12,800 --> 00:03:14,183
Let me do that real quick.

57
00:03:18,500 --> 00:03:21,460
Make sure to not misspell things, there you go.

58
00:03:21,460 --> 00:03:25,918
So again, this is just saying the encrypted token identity

59
00:03:25,918 --> 00:03:30,220
in blacklist will be true if it is in there and it will

60
00:03:30,220 --> 00:03:32,343
be false if it's not in there.

61
00:03:32,343 --> 00:03:33,870
And that's it.

62
00:03:33,870 --> 00:03:37,500
If it's there, what it's gonna do is going to determine that

63
00:03:38,468 --> 00:03:39,570
this is blacklisted and it's going to go down here

64
00:03:39,570 --> 00:03:42,180
to the revoked token loader and it's going to say

65
00:03:42,180 --> 00:03:44,776
this token has been revoked, you don't have access.

66
00:03:44,776 --> 00:03:47,420
If it's not in the blacklist,

67
00:03:47,420 --> 00:03:48,790
it's just not going to do anything.

68
00:03:48,790 --> 00:03:51,733
It's gonna continue and allow access no problem.

69
00:03:52,840 --> 00:03:57,360
Let's go into Postman and open this up.

70
00:03:57,360 --> 00:03:59,183
So we're going to create a new user.

71
00:04:00,930 --> 00:04:03,990
Gotta make sure your app is running, though, so I always

72
00:04:03,990 --> 00:04:05,503
do forget to do that.

73
00:04:06,900 --> 00:04:11,150
We are going to open up the terminal and run our app

74
00:04:11,150 --> 00:04:11,983
like that.

75
00:04:12,900 --> 00:04:15,020
Now we're going to create our user.

76
00:04:15,020 --> 00:04:17,800
We have our user created successfully and this user

77
00:04:19,750 --> 00:04:22,403
is user ID number one.

78
00:04:23,480 --> 00:04:26,280
So we can use this user as normal.

79
00:04:26,280 --> 00:04:28,730
We're gonna try to get an item, and remember that item

80
00:04:28,730 --> 00:04:33,310
get requires a jwt so this works because this is the first

81
00:04:33,310 --> 00:04:35,390
user in our database.

82
00:04:35,390 --> 00:04:37,900
If we go ahead and create a different user, I am going

83
00:04:37,900 --> 00:04:42,267
to call this user 15, and we create it.

84
00:04:42,267 --> 00:04:45,003
Then we can log in as that user.

85
00:04:47,040 --> 00:04:50,020
But, now this access token is saved into an environment

86
00:04:50,020 --> 00:04:53,650
variables and when we try to access the item is going

87
00:04:53,650 --> 00:04:56,300
to check the blacklist for that access token and it's

88
00:04:56,300 --> 00:04:59,790
going to determine that you cannot access it.

89
00:04:59,790 --> 00:05:00,623
There you have it.

90
00:05:00,623 --> 00:05:03,773
You can see that it says the token has been revoked.

91
00:05:04,830 --> 00:05:08,200
That is exactly what we'd expect because that's what the

92
00:05:08,200 --> 00:05:10,243
token revoked loader does.

93
00:05:11,640 --> 00:05:14,810
So in this video we've looked at blacklisting.

94
00:05:14,810 --> 00:05:18,410
We have blacklisted a static set of user IDs and that's

95
00:05:18,410 --> 00:05:20,870
not really normally what you want to do.

96
00:05:20,870 --> 00:05:23,160
Normally you want to use this blacklisting

97
00:05:23,160 --> 00:05:24,070
for specific things.

98
00:05:24,070 --> 00:05:26,060
For example, if somebody is abusing your system and you

99
00:05:26,060 --> 00:05:31,060
want to revoke their access or if you have somebody that's

100
00:05:31,840 --> 00:05:35,920
logged out and you want to revoke their token specifically,

101
00:05:35,920 --> 00:05:38,230
not their user ID, but just the token that they

102
00:05:38,230 --> 00:05:41,650
are currently using so that they have to log in again.

103
00:05:41,650 --> 00:05:44,530
And, I'm sure you can come up with a few more scenarios

104
00:05:44,530 --> 00:05:46,600
where you might want to use token revoking.

105
00:05:46,600 --> 00:05:49,010
But, I'm sure you'll agree it's a pretty useful

106
00:05:49,010 --> 00:05:52,680
feature of flask jwt extended, so it's worth looking

107
00:05:52,680 --> 00:05:54,670
at it in the very next video.

108
00:05:54,670 --> 00:05:55,620
I'll see you there.

