# 403 - From POST HTTPS depending on size of body

**URL:** <https://discourse.nodered.org/t/403-from-post-https-depending-on-size-of-body/82716>\
**Category:** General\
**Tags:** http-in\
**Created:** [8 November 2023 14:48 UTC](https://discourse.nodered.org/t/403-from-post-https-depending-on-size-of-body/82716 "2023-11-08T14:48:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kayna](https://avatars.discourse-cdn.com/v4/letter/k/e480ec/32.png) [@kayna](https://discourse.nodered.org/u/kayna)\
**Post date:** [8 November 2023 14:48 UTC](https://discourse.nodered.org/t/403-from-post-https-depending-on-size-of-body/82716/1 "2023-11-08T14:48:48Z")

</div>

Hi, i'm getting the 403 response for my endpoint in the "http-in" node when the request is made through HTTPS. But it only occurs when in the body of the request there are 3 or more items in the array that i send. If i send 1 or 2 items in the array it responds as espected. For 3 or more i get 403, no log is show in the debug console. I looked in the "node-red-error.log" and the "node-red-out.log" but didn't found anything related to the request. If the same requisition is made from HTTP, it works regardless of the size of the array in the body.  
Does anyone has seen anything like this and/or have any idea of what i can do to identify why this happens ? As it shows no log at all i'm completely lost in what to do.  
Any help, tip or direction is really appreciated

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [8 November 2023 15:08 UTC](https://discourse.nodered.org/t/403-from-post-https-depending-on-size-of-body/82716/2 "2023-11-08T15:08:43Z")

</div>

403 is a refusal by the server to authorise the request.

You mention `the "http-in" node"` - so I assume the endpoint is created in Node-RED?

What are you using to make the requests?

Can you provide a proven working (not working) demo flow demonstrating this. Also, provide the cURLs / postman commands to test it.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [8 November 2023 17:25 UTC](https://discourse.nodered.org/t/403-from-post-https-depending-on-size-of-body/82716/3 "2023-11-08T17:25:15Z")

</div>

Are you responding with a JSON response? If so, have you checked the size of the output? ExpressJS has, I believe a default maximum JSON response size of 1MB. If needed, you can change that in the ExpressJS settings - I _think_ you can change those for the default node-red server?

---

<div class="post-metadata">

**Author:** ![kayna](https://avatars.discourse-cdn.com/v4/letter/k/e480ec/32.png) [@kayna](https://discourse.nodered.org/u/kayna)\
**Post date:** [23 November 2023 14:30 UTC](https://discourse.nodered.org/t/403-from-post-https-depending-on-size-of-body/82716/4 "2023-11-23T14:30:14Z")

</div>

I have discovered the cause of the problem. It was not in nodered. The problem was in the AWS cloud front that i use to reach nodered.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [7 December 2023 14:30 UTC](https://discourse.nodered.org/t/403-from-post-https-depending-on-size-of-body/82716/5 "2023-12-07T14:30:17Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
