JWT Authentication in NodeJS

Поділитися
Вставка
  • Опубліковано 29 гру 2024

КОМЕНТАРІ •

  • @tfnt3839
    @tfnt3839 Рік тому +38

    I have seen the playlist of million subscriptions of the channel. but your teaching style and explanation is great.

    • @MakarnaDusmani-f3o
      @MakarnaDusmani-f3o Місяць тому

      I can't understand what he's saying, and there aren't subtitles.

    • @tfnt3839
      @tfnt3839 Місяць тому

      @@MakarnaDusmani-f3o I think video is sufficient , if you watch carefully in mute mode .

  • @Javedboqo1
    @Javedboqo1 Рік тому +9

    All of videos from this guy are very useful and amazing

  • @ctauheedpasha1527
    @ctauheedpasha1527 2 місяці тому

    the thing is the way you make us understand the concept are so good. In previous video you thought how to implement cookies but i never got time to watch the whole video but i created a logic by myself to delete the cookie id when a user clicks logout such that it redirects me to the login page again. Thank you so much and keep up the good work!!

  • @omprakashshaw796
    @omprakashshaw796 20 днів тому

    Completed half of the playlist , thank for explaing things so easily ❤❤

  • @dhruvsolanki4473
    @dhruvsolanki4473 4 місяці тому +3

    Stateless vs Stateful understood because of you, thanks!

  • @tgayush1424
    @tgayush1424 Місяць тому

    Maza a gaya your explanation is gazab , full samjh me a jata hai sab kuch.

  • @gohit8703
    @gohit8703 3 місяці тому

    thanku piyush you made my journey possible to project building

  • @weforyouweb1165
    @weforyouweb1165 Рік тому +3

    You are gem 🎉 You have very very deep knowledge of all things ❤🎉🎉

  • @joban_dhillonn
    @joban_dhillonn Рік тому

    bahot badiya exaple de kar samajiya sir apne secret key bhot confush tha thankuu

  • @knightcore4062
    @knightcore4062 4 місяці тому

    finally understand sessions cookies and jwt...thank you sirji!!!!🙏🙏🙏🙏

  • @banothutharun2743
    @banothutharun2743 3 місяці тому

    wow excellent explaination..thank you brother for this playlist 😊

  • @Shashwat-000
    @Shashwat-000 2 місяці тому +1

    10:38 you changed the token. the email was changed, the new token contains Tcf90 at last but at 10:39 (HXfCY at last) there is a cut in video where you changed it, i was getting the glitch and sure you too but you not explained that in video and directly changed something.

  • @satyampal7235
    @satyampal7235 9 місяців тому

    Awesome explanation bhai 👌

  • @Powerful-Manifestor-
    @Powerful-Manifestor- Місяць тому

    Hey! Great explanation!
    I have a couple of queries:
    1. How stateful approach is taking memory on server? In the end, we used DB instead of map, right? And anyhow, we do store createdBy anyways. So mainly is logout the issue?
    2. Also, in stateful, why does logout happen even after persisting createdBy to DB?

  • @namannema3349
    @namannema3349 8 місяців тому

    i like the way you explain by giving examples and your explanations are very user friendly

  • @AfhamAdian
    @AfhamAdian 11 місяців тому +1

    this is the best on internet

  • @PubG-dl5eh
    @PubG-dl5eh Рік тому +1

    Great video sir👍

  • @Shashwat-000
    @Shashwat-000 2 місяці тому +1

    There is no login if you changed the email using secret password also. at 10:38 to 10:39 even he can't login. there is a cut in the video from 10:38 to 10:39 where somehow he got loggedIn,the funny thing is at 10:38 the token he copied frow jwt is different from 10:39 (where there is a cutshot in the video) and he got login.

  • @mubasshirkhan1370
    @mubasshirkhan1370 11 місяців тому +1

    Thank you bhai...... ❤🧡💛💚

  • @Black-Curtains
    @Black-Curtains Рік тому +3

    Brother! as we are storing tokens with cookies. Someone can copy that token and log in, as you already demonstrated. Is it a secure way?
    कृपया मार्गदर्शन करें..

    • @piyushgargdev
      @piyushgargdev  Рік тому +4

      Good Point, I'll surely clear your doubt in next video ✨

  • @NKAnimations-mm2pp
    @NKAnimations-mm2pp 6 місяців тому +4

    Sir I really like your videos but there are 2 problems which I am facing:
    1. Your authentication videos are dependent on URLGeneration videos.
    2. If someone face any error in the URL at any point he wont be able to continue until that error gets resolved.
    3. Solution : if you could provide the source code then it would be easier for us to resolve our errors.
    4. Solution : If you could make such videos which are not dependent on each other then it would be easier for us to understand each concept from the Scratch

  • @webdeveloper3529
    @webdeveloper3529 Рік тому +6

    ❤ sir your lectures are blessings for me... plz cover advanced nodejs caching, threading, etc...

    • @piyushgargdev
      @piyushgargdev  Рік тому +1

      Sure, Thanks :)

    • @harshrajsinha012
      @harshrajsinha012 10 місяців тому

      i'm getting
      return done(new JsonWebTokenError('jwt malformed'));
      JsonWebTokenError: jwt malformed@@piyushgargdev
      this error

  • @pankaj8876
    @pankaj8876 Рік тому

    Great explanation! 👌

  • @AmitSingh-nq6bp
    @AmitSingh-nq6bp 4 місяці тому +1

    I really like his vs code theme , did anyone know the name of it ?

  • @100DDC
    @100DDC Рік тому

    wow, awesome bro

  • @ibntofajjal
    @ibntofajjal Рік тому

    Keep Going Bro. You Doing Well

  • @shubhamgupta-bl1tr
    @shubhamgupta-bl1tr Рік тому +3

    But if we store sessions in database tab to problem ni hogi na in statefull

    • @Ayush37262
      @Ayush37262 11 місяців тому

      He solved your doubt in the next video!!!

  • @as_if
    @as_if 8 місяців тому

    4:30 difference between this token and the UID

  • @shi-nee7966
    @shi-nee7966 Рік тому +4

    sir i am getting error "jwt malformed" i tried matching codes, also searched on stackoverflow but just couldnt solve the error...please help if you know...i will update if i get the solutain

    • @dishantsingh5790
      @dishantsingh5790 Рік тому +9

      i got the same error just now, restart ur server then dont directly go to "/" route , firstly clear cookie from Browser then go to the login page , login as user , then everythng will work fine

    • @daniyalghani4857
      @daniyalghani4857 Рік тому

      i got the same error thank you brother @@dishantsingh5790

    • @harshrajsinha012
      @harshrajsinha012 10 місяців тому

      it's not working bro @@dishantsingh5790

    • @usmanmunir5241
      @usmanmunir5241 10 місяців тому

      I am still getting error ​@@dishantsingh5790

    • @usmanmunir5241
      @usmanmunir5241 10 місяців тому

      How you resolve this error?? @shi-nee7966

  • @bm9code
    @bm9code Рік тому +1

    this is only video in which i saw that the use secret key in jwt ♥ thanks ♥

  • @shivaverma85
    @shivaverma85 9 місяців тому +2

    I dont know why everytime its giving me error as jwt malformed but i am writing the same code as you have written .. I have seen your all videos upto authentication and everything is fine but i dont know why as soon as i am using jwt its not working . i am working on it to find error from past 2 hours but its not working please help

  • @mma-dost
    @mma-dost Рік тому +2

    Great video bhaiya there is something csrf is jwt secure with that hack ?

    • @piyushgargdev
      @piyushgargdev  Рік тому +1

      Added to my list, will surely make a video on it

  • @ar.survivalcraft
    @ar.survivalcraft 5 місяців тому

    Bhaiya jab tokens ko cookies me store kiya ho to react js ke routes ko kaise protect kare based on presence of token in cookie?

  • @lovelymusic3549
    @lovelymusic3549 Рік тому +1

    Sir when you are starting a complete react JS course basic to advance any idea sir?

  • @avfitnes96
    @avfitnes96 4 місяці тому

    Thx sir❤❤

  • @deepanshuaggarwal5181
    @deepanshuaggarwal5181 Рік тому +1

    how on changing payload with wrong email and right secret key, we logged in at 10:40

    • @Ayush37262
      @Ayush37262 11 місяців тому

      Did you got the answer??
      I think maybe because we have already entered the correct email and password in the beginning...

    • @ayushacharya4778
      @ayushacharya4778 5 годин тому

      For that you need to know how jwt is verified. Header and payload part are taken and they are hashed with secret key to get a signature. First part of token is header, second is payload and third is the signature that i described how it comes.
      Verification(jwt.verify(token,secret):
      The header, payload and the secret are hashed and we get a new signature. If the new signature matches with the one we received from the third part of token(received signature) then the token is verified and user is authorized.
      Even if the email was changed, the newly generated token was valid. We extracted user id and So we logged in at 10:40

  • @Motivation-w7r
    @Motivation-w7r Рік тому

    hello big brother what is the difference between jwt token vs express-session ?

  • @amrExplore
    @amrExplore Рік тому

    Very nicely explained Piyush. ! question though, in case of refresh token does the secret on the server changes since the payload information would remain the same ? Wonderful JWT explnation

  • @seemakhan-jx8lp
    @seemakhan-jx8lp 2 місяці тому

    Assalamo Alikum Sir
    Sir kiya asa office hai jo urdu mai interview ly our office waly urdu bholy muje typescript react javascript and node.js and exprees ati sirf language ka issues hai english ki samj ati par mai bol nhi sakti

  • @pallabdandapat1866
    @pallabdandapat1866 7 місяців тому +1

    sir getting the below error :
    C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\jsonwebtoken\verify.js:70
    return done(new JsonWebTokenError('jwt malformed'));
    ^
    JsonWebTokenError: jwt malformed
    at module.exports [as verify] (C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\jsonwebtoken\verify.js:70:17)
    at getUser (C:\Users\palla\Downloads\short-url-node\short-url-node\service\auth.js:13:16)
    at checkAuth (C:\Users\palla\Downloads\short-url-node\short-url-node\middlewares\auth.js:15:18)
    at Layer.handle [as handle_request] (C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\express\lib
    outer\layer.js:95:5)
    at trim_prefix (C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\express\lib
    outer\index.js:328:13)
    at C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\express\lib
    outer\index.js:286:9
    at Function.process_params (C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\express\lib
    outer\index.js:346:12)
    at next (C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\express\lib
    outer\index.js:280:10)
    at cookieParser (C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\cookie-parser\index.js:71:5)
    at Layer.handle [as handle_request] (C:\Users\palla\Downloads\short-url-node\short-url-node
    ode_modules\express\lib
    outer\layer.js:95:5)
    Node.js v20.6.1
    [nodemon] app crashed - waiting for file changes before starting...

    • @pratyushpragyey7002
      @pratyushpragyey7002 7 місяців тому +2

      function getUser(token){
      if(!token) return null;
      try {
      return jwt.verify(token ,secret);

      } catch (error) {
      return null;
      }
      }
      use this function instead of what you've written

    • @pallabdandapat1866
      @pallabdandapat1866 7 місяців тому

      @@pratyushpragyey7002 yes sir , i have done the same thing , thank you.

    • @mayanksinha1883
      @mayanksinha1883 7 місяців тому

      @@pratyushpragyey7002 thanks mannn

  • @vijenderkumar3034
    @vijenderkumar3034 Рік тому +3

    Nice video

  • @ShashankGrade-xk9dc
    @ShashankGrade-xk9dc 4 місяці тому

    when i replace my token with wrong one the app remain run

  • @ctet5470
    @ctet5470 Рік тому

    Where we are calling getUser function?

  • @mayanksinha1883
    @mayanksinha1883 7 місяців тому

    nodejs\urlshortener\service\auth.js:8
    _id: user._id,
    ^
    TypeError: Cannot read properties of undefined (reading '_id')

  • @SulavGhimireeee
    @SulavGhimireeee 11 місяців тому

    Thanks bro

  • @codingwave56
    @codingwave56 Рік тому +1

    Hmne Information (Object) ko JWT ki madad se bina Secret key bhi generate kar diya to ye secret key kiss kam ki? Plz Reply Sir...

    • @utube6044
      @utube6044 Рік тому +1

      kaha pe?

    • @varunchakraborty6020
      @varunchakraborty6020 11 місяців тому +2

      I don't know if you got the soln or no, but Secret key token me changes krne ke liye h n ki use read krne ke liye

    • @codingwave56
      @codingwave56 11 місяців тому +1

      @@varunchakraborty6020 Yes, Got it 👍🏻
      Thanks

    • @utube6044
      @utube6044 11 місяців тому

      @@varunchakraborty6020 matlab ki dekhne k liye ki ye token meri secret key se bana hai ki nai?

    • @varunchakraborty6020
      @varunchakraborty6020 11 місяців тому

      @@utube6044 hn mtlb agr kisi aur ne changes krdiya token me, to mai verify krskta hu, ki final token mere secret key se bni h ya nhi

  • @fatimaiqra2169
    @fatimaiqra2169 3 місяці тому

    Thanks

  • @iamakashkumarram
    @iamakashkumarram Рік тому +3

    JWT Authentication basic to Advance full cover karado sir.

  • @AtharvJoshi-jc7ow
    @AtharvJoshi-jc7ow 6 місяців тому +2

    then why the heck IRCTC uses session😂
    it loggs you out at the last second of your attempt to book tatkal ticket💩

    • @anandshete9170
      @anandshete9170 6 місяців тому

      bhai ham agar hot to ham khud hi acche khase website bana lete yarr inko kon bataye abb saste saste developers use kiye hai inhone

  • @sourabhgarg2890
    @sourabhgarg2890 3 місяці тому

    bro u teaching backend or hacking?

  • @CodeForgePro
    @CodeForgePro 3 місяці тому

    but somewone steal the cookie and try to login in their system can we stop this

    • @Atul_Thakre30
      @Atul_Thakre30 2 місяці тому

      That's why it is not a good way

  • @mromkar5366
    @mromkar5366 Місяць тому

    jwt malformed how to solve

  • @Royal1825
    @Royal1825 2 дні тому

    Great

  • @abhayyraz
    @abhayyraz 5 місяців тому

    Too Good

  • @najmulhasan5997
    @najmulhasan5997 Рік тому

    thanks

  • @20_omkar_kadu57
    @20_omkar_kadu57 Рік тому

    jwt itma hi hota he ya aur bhi kuch he

  • @dhruvbandi6633
    @dhruvbandi6633 Рік тому

    bro where is the code

  • @MrBlazzerBoy
    @MrBlazzerBoy 11 місяців тому

    Please mention it's Hindi in title.

  • @sudhanshugautam425
    @sudhanshugautam425 Рік тому

    let say you want to make this project open source, but in the backend itself you shared the secret key and using that anyone can get make fake token????

    • @Ayush37262
      @Ayush37262 11 місяців тому +2

      I think we will store the secret key in the .env file

  • @mdebrahim2164
    @mdebrahim2164 Рік тому

    helpfull

  • @ChandransuSekharSatapathy
    @ChandransuSekharSatapathy 8 місяців тому

    someone has its source code

  • @rishabhraj8233
    @rishabhraj8233 Рік тому

    hey I am here on 1st jan anybody else?

  • @nithenbains
    @nithenbains 5 місяців тому

    explaination is top-notch
    but appke voice tone like a little child is speaks

  • @hetpatel9503
    @hetpatel9503 Рік тому

    👌

  • @chrisjordan5849
    @chrisjordan5849 5 місяців тому

    Sir ji ek hi video me pura samjha diya karo na bar bar ja ke dusri video pehle dekho

  • @hemobhai1
    @hemobhai1 10 місяців тому +38

    Ek hi video me bana diya Karo na warna bataya hi mat karo pahle ye dekho tab wo dekho aadmi yaha sikhne aata hai ki tumlog ka views badhane

    • @mujibulhaquetanim
      @mujibulhaquetanim 10 місяців тому +8

      Bhai, have some patience. it is not a paid course.

    • @Flux-e4y
      @Flux-e4y 10 місяців тому +1

      same bro
      mujhe bhi bhout gussa aata hai

    • @proudtobeindian27
      @proudtobeindian27 9 місяців тому +15

      Bhai mat aaya kar ehsaan na kar us par, ek to free main pada ra upar se tu attitude dikha ra, scroll kar aur dusare ko dekh na

    • @shivajikapale2336
      @shivajikapale2336 8 місяців тому +3

      Bhai bahut badiya padha raha hai banda free mai... Pura videos dekho nahi to kuch mat dekho

    • @quick-bytes
      @quick-bytes 8 місяців тому +5

      Separate video better hai warna bohot long ho jata woh video na itna tum ya koi bhi samaj kr digest kr pata atleast iska part 1 video khtm hua hoga tb logo ne practice krne ka try kra hoga
      Netflix pr binge watch krne nahi aaye ho sikhne aaye ho tum yaha pr 🙂

  • @ShivendraPratap524
    @ShivendraPratap524 Рік тому

    What next?????

    • @piyushgargdev
      @piyushgargdev  Рік тому

      We will cover advance concepts while building projects, No video for today!

    • @ShivendraPratap524
      @ShivendraPratap524 Рік тому

      @@piyushgargdev matlab ab projects hi projects ayenge

    • @ShivendraPratap524
      @ShivendraPratap524 Рік тому

      One more request react ke sath integrate karle bhi ek project, fir chain se jinda rahenge

    • @ShivendraPratap524
      @ShivendraPratap524 Рік тому

      @@piyushgargdev aur haa videos ki continuity yahi rakhiyega sir