Protecting user routes

We will add requireSignin and hasAuthorization to the user route declarations that need to be protected with authentication and also authorization.

Update the read, update, and delete routes in user.routes.js as follows.

mern-skeleton/server/routes/user.routes.js:

import authCtrl from '../controllers/auth.controller'...router.route('/api/users/:userId')    .get(authCtrl.requireSignin, userCtrl.read)    .put(authCtrl.requireSignin, authCtrl.hasAuthorization,      userCtrl.update)    .delete(authCtrl.requireSignin, authCtrl.hasAuthorization,      userCtrl.remove)...

The route to read a user's information only needs authentication verification, whereas the update and delete routes should check for both authentication and authorization ...

Get Full-Stack React Projects now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.