1
00:00:01,200 --> 00:00:02,450
Hi, and welcome back.

2
00:00:02,450 --> 00:00:04,440
In this video we're going to look at how

3
00:00:04,440 --> 00:00:06,590
to perform a user log out.

4
00:00:06,590 --> 00:00:09,602
User log outs are going to use the black list

5
00:00:09,602 --> 00:00:13,420
so it's going to be similar to what we already know,

6
00:00:13,420 --> 00:00:16,750
but we're just going to add a new couple of concepts.

7
00:00:16,750 --> 00:00:18,130
The first thing I'm gonna do is open up

8
00:00:18,130 --> 00:00:20,115
the blacklist and make this an empty set.

9
00:00:20,115 --> 00:00:23,920
We don't wanna be blacklisting anybody at the start

10
00:00:23,920 --> 00:00:25,700
of our application, so we're going to make this

11
00:00:25,700 --> 00:00:30,700
an empty set just so we can add to it as we log users out.

12
00:00:31,292 --> 00:00:34,230
So that's our blacklist, it's gonna be an empty set.

13
00:00:34,230 --> 00:00:36,170
And the next thing we wanna do is go ahead into

14
00:00:36,170 --> 00:00:37,720
our user resource and we're going

15
00:00:37,720 --> 00:00:40,949
to add a user log out resource.

16
00:00:40,949 --> 00:00:43,920
Now I'm going to add this just above the token refresh,

17
00:00:43,920 --> 00:00:45,090
because I want to keep all the

18
00:00:45,090 --> 00:00:49,990
user star resources here together.

19
00:00:49,990 --> 00:00:53,705
So we're going to add a user log out resource.

20
00:00:53,705 --> 00:00:58,705
The user log out resource of course requires a jwt.

21
00:00:59,150 --> 00:01:02,877
Oop, jwt_required, there you go.

22
00:01:02,877 --> 00:01:07,650
It requires a jwt, because if you are not already

23
00:01:07,650 --> 00:01:09,980
logged in you can't possibly log out.

24
00:01:09,980 --> 00:01:14,844
So we also have to import jwt_required in there.

25
00:01:14,844 --> 00:01:17,960
Now that we've got the jwt_required,

26
00:01:17,960 --> 00:01:22,960
we can go ahead and create our post request here.

27
00:01:23,250 --> 00:01:25,000
And what this is going to do,

28
00:01:25,000 --> 00:01:27,130
is it's going to perform a log out.

29
00:01:27,130 --> 00:01:30,460
So, what is a log out?

30
00:01:30,460 --> 00:01:34,770
We don't want to blacklist the user ID,

31
00:01:34,770 --> 00:01:37,090
because if we blacklist the user ID,

32
00:01:37,090 --> 00:01:38,650
they're not going to be able to log back in.

33
00:01:38,650 --> 00:01:39,940
Or they will but they won't be able

34
00:01:39,940 --> 00:01:41,190
to access any end points.

35
00:01:42,350 --> 00:01:45,050
So what we want to blacklist is actually

36
00:01:45,050 --> 00:01:47,493
just the jwt they're using.

37
00:01:48,630 --> 00:01:51,293
If we blacklist this jwt they've sent us,

38
00:01:51,293 --> 00:01:54,867
that means that the next time they try to use that same one,

39
00:01:54,867 --> 00:01:58,230
they won't be able to do that and they will

40
00:01:58,230 --> 00:01:59,590
have to get a new one.

41
00:01:59,590 --> 00:02:01,474
And in order to get a new jwt,

42
00:02:01,474 --> 00:02:04,560
they're going to have to log in again.

43
00:02:04,560 --> 00:02:08,304
So this is how we're going to accomplish our log out.

44
00:02:08,304 --> 00:02:11,193
Just blacklist their current access token

45
00:02:11,193 --> 00:02:13,440
so that is won't work and they'll need

46
00:02:13,440 --> 00:02:15,820
to get a new one by logging in again.

47
00:02:15,820 --> 00:02:17,609
Essentially, logging out.

48
00:02:17,609 --> 00:02:21,863
All we have to do is get a unique identifier

49
00:02:21,863 --> 00:02:24,586
for the access token.

50
00:02:24,586 --> 00:02:29,586
Every access token has a unique ID that we can blacklist,

51
00:02:29,900 --> 00:02:32,810
that identifies that token only.

52
00:02:32,810 --> 00:02:34,728
It doesn't have anything to do with

53
00:02:34,728 --> 00:02:35,740
the user or anything like that,

54
00:02:35,740 --> 00:02:38,266
it's just an ID for the token so that if we blacklist

55
00:02:38,266 --> 00:02:41,481
that this specific token will become unusable

56
00:02:41,481 --> 00:02:43,550
and they'll need a new one.

57
00:02:43,550 --> 00:02:48,550
That's called jti in jwt standards and language.

58
00:02:48,812 --> 00:02:52,909
So the jti, it stands for jwt ID

59
00:02:52,909 --> 00:02:57,909
and we can get it from the get_raw_jwt function.

60
00:03:00,240 --> 00:03:03,980
And that's a dictionary that has the jti inside it.

61
00:03:03,980 --> 00:03:06,439
So again I'm just going to add a little comment

62
00:03:06,439 --> 00:03:08,600
here to say that jti is jwt ID,

63
00:03:08,600 --> 00:03:11,470
a unique identifier for a jwt.

64
00:03:11,470 --> 00:03:12,463
And there you go.

65
00:03:13,610 --> 00:03:16,997
And all we have to do then is say blacklist.add(jti).

66
00:03:19,760 --> 00:03:21,240
And then we can return a wee message

67
00:03:21,240 --> 00:03:25,203
that says successfully logged out.

68
00:03:28,040 --> 00:03:31,990
Now we have to import get_raw_jwt and also blacklist,

69
00:03:31,990 --> 00:03:34,483
so let's go ahead to the top and do that.

70
00:03:35,850 --> 00:03:40,850
Get_raw_jwt and from Blacklist import BLACKLIST.

71
00:03:41,379 --> 00:03:45,610
Now remember blacklist is a set so we can add things

72
00:03:45,610 --> 00:03:48,063
to a set, and that's totally fine in Python.

73
00:03:49,046 --> 00:03:50,320
That's it.

74
00:03:50,320 --> 00:03:54,000
Now that this is done, we have to go to our app.py

75
00:03:54,000 --> 00:03:58,540
and make sure in the token in BLACKLIST loader

76
00:03:58,540 --> 00:04:01,400
that we stop checking the identity of the token.

77
00:04:01,400 --> 00:04:04,510
Now we have to check the jti of the token.

78
00:04:04,510 --> 00:04:06,320
Okay, that's just so that we make sure

79
00:04:06,320 --> 00:04:08,370
that we're checking the right thing that we've saved.

80
00:04:08,370 --> 00:04:11,060
The identity in the token will still be same as before,

81
00:04:11,060 --> 00:04:15,020
the user ID, the jti is another thing that we can access

82
00:04:15,020 --> 00:04:19,446
in the decrypted token that contained the jwt's ID.

83
00:04:19,446 --> 00:04:21,030
Okay?

84
00:04:21,030 --> 00:04:22,880
Now, we also have to, of course,

85
00:04:22,880 --> 00:04:27,880
add the user log out resources into our api.

86
00:04:28,760 --> 00:04:30,322
So let's do that.

87
00:04:30,322 --> 00:04:33,322
(keyboard clicking)

88
00:04:36,953 --> 00:04:38,184
That's it.

89
00:04:38,184 --> 00:04:39,787
Now we've added them here.

90
00:04:39,787 --> 00:04:41,710
We can go ahead into postman and try it out.

91
00:04:41,710 --> 00:04:44,423
So, I've still got some things open from before.

92
00:04:44,423 --> 00:04:46,378
We're just going to close them.

93
00:04:46,378 --> 00:04:51,378
And we may have to run our app, that helps.

94
00:04:52,121 --> 00:04:54,540
So I'm just gonna run it there

95
00:04:54,540 --> 00:04:57,364
and go back to postman, sorry about that,

96
00:04:57,364 --> 00:05:00,203
I keep forgetting to run the app.

97
00:05:00,203 --> 00:05:03,434
Now that app's running, we can register a new user,

98
00:05:03,434 --> 00:05:06,229
user created successfully, we can log in.

99
00:05:06,229 --> 00:05:09,300
We've got the access token, remember that gets saved

100
00:05:09,300 --> 00:05:13,530
into our environment variables and then we can get an item.

101
00:05:13,530 --> 00:05:15,360
It won't be found, but that's okay.

102
00:05:15,360 --> 00:05:18,046
But then, we can go over and create a new end point

103
00:05:18,046 --> 00:05:22,270
here that is going to be a url/logout

104
00:05:23,338 --> 00:05:27,670
and we can include our header if we need to.

105
00:05:27,670 --> 00:05:30,710
Bearer, access token, like that.

106
00:05:30,710 --> 00:05:34,862
We can send this over, and I think it's a post, isn't it?

107
00:05:34,862 --> 00:05:37,110
Successfully logged out.

108
00:05:37,110 --> 00:05:38,433
We can go back to my item,

109
00:05:39,440 --> 00:05:41,764
and now you can see that the token has been revoked.

110
00:05:41,764 --> 00:05:44,580
So that is how you do a log out,

111
00:05:44,580 --> 00:05:47,233
making sure that the user can actually then log

112
00:05:48,253 --> 00:05:49,660
and out back in and use the item again.

113
00:05:49,660 --> 00:05:52,340
As you can see, logging back in and getting a new item,

114
00:05:52,340 --> 00:05:53,990
that works, we can then go ahead

115
00:05:56,219 --> 00:05:57,052
and log out if we want again

116
00:05:57,052 --> 00:05:57,885
and this won't work again and so forth.

117
00:05:57,885 --> 00:05:59,547
So as you can see, we are blacklisting specific

118
00:05:59,547 --> 00:06:03,550
jti's, not specific users.

119
00:06:03,550 --> 00:06:05,400
This gives us a lot more flexibility,

120
00:06:05,400 --> 00:06:07,650
because the user can log back in and continue

121
00:06:07,650 --> 00:06:10,560
using the service, which is normally what you'd want.

122
00:06:10,560 --> 00:06:12,880
You can keep an entirely separate blacklist

123
00:06:12,880 --> 00:06:15,570
for specific user identities if you wanted.

124
00:06:15,570 --> 00:06:18,910
For example, if somebody was abusing your system

125
00:06:18,910 --> 00:06:22,470
you could do that or blacklist IP addresses and so forth.

126
00:06:22,470 --> 00:06:24,780
You can do all sorts of stuff with a blacklist.

127
00:06:24,780 --> 00:06:27,573
It's generally quite a handy thing to have.

128
00:06:27,573 --> 00:06:30,500
So that's it for this video, hope you've enjoyed it.

129
00:06:30,500 --> 00:06:32,150
And I'll see you on the next one.

