Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
In this lecture, we're very quickly
gonna learn how to test for secure https connections,
with a Heroku,
because we actually need that, at one point,
in our application.
So, let's go here to our authentication controller.
And right here at the top,
in this create sent token function,
here is the place where we set
the adjacent web cookie to secure,
if we are currently in production.
Remember that.
So, remember that we created this function
with adjacent response,
it also sends a cookie,
which also contains the adjacent web token.
And that cookie has a couple of options.
The first one, when it expires.
The second one,
that it can only be accessed via http basically.
And then, when we're in production,
we said that this cookie can only be sent
on a secure connection.
So, basically, on an https connection.
All right.
Now, the problem with that is that actually,
the fact that we are in production,
does not mean that connection is actually secure.
Right?
Because of course, not all deployed applications
are automatically set to https.
And so we need to change this if that we have here.
All right.
Now, in express we actually have a secure property
that is on the request.
And only when the connection is secure,
then this request dot secure is true.
Okay?
Makes sense, right?
Now the problem is, that actually in Heroku,
this doesn't work.
And that's because Heroku proxy's,
so basically redirect or modifies all incoming requests
into our application before they actually reach the app.
All right.
So, in order to make this also work on Heroku
we need to also test if the x forward proto
header is set to https.
All right.
So, that sounds a bit confusing,
but again, this is something Heroku does internally.
So, let's test here if req.secure is true,
or if req.headers.
And the header that we're looking for is x forwarded proto.
And this header is set to https
if we are on a secure connection.
All right?
So, this is something very Heroku specific.
And that's why I left this here for the last section,
after we already deployed the application.
So, if either req.secure is true,
or if this header here is set to https,
then we want the secure options here set to true.
And, so, we can actually refactor this.
So, basically we can take this,
because this will be true.
And, so, I say if this is true,
then let's say equal true here.
So, that doesn't make sense.
We can instead simply do it like this.
All right?
And, actually, we can take it even further.
And put the secure option right here.
So, why have it outside if we can just put it here?
So, secure equals this, okay?
And then we no longer need this.
And, since we're refactoring,
we actually no longer need this variable here at all.
So, let's just put it here, give it a safe,
and there's something wrong there.
Okay, and so, now the problem is that
do not have access currently to the request
in this function.
Okay, so, we need to add it here.
Request and then wherever we have create sent token,
we of course need to pass in the request in there.
So, that's here.
So, use command D to find the next one basically.
Request here.
And then finally here as well.
Okay, so, that looks much nicer
and it should also work a lot nicer than before.
However, right now, this is still not going to be working,
because there's just one more thing that we need to do,
which is basically to make our application trust proxy's.
So, again, request dot secure doesn't work
in the first place because Heroku acts as a proxy,
which kind of redirects and modifies incoming requests.
And, so, we need to go to app dot JS
and then right after this one here,
let's now trust proxy's.
And we do that by saying app dot enable trust proxy.
Okay?
So, this is something that is built into express
for this kind of situations.
All right?
And so, only if we have this setting here correctly set up,
then this header here will be correctly set,
and we will be able to read its value.
All right?
So, this is how you test if a connection is secure or not,
when you have your application deployed to Heroku.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.