# Access a property of the dashboard within a Express Application

**URL:** <https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186>\
**Category:** Dashboard\
**Created:** [29 June 2018 11:55 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186 "2018-06-29T11:55:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![AtenrevCode](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/atenrevcode/32/901_2.png) [@AtenrevCode](https://discourse.nodered.org/u/AtenrevCode)\
**Post date:** [29 June 2018 11:55 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186/1 "2018-06-29T11:55:49Z")

</div>

I’m trying to add a security layer to my Node-Red instance and I would like to know if I can retrieve somehow a property of the dashboard, specifically the name of the tab the user is trying to access, from a middleware function.

---

<div class="post-metadata">

**Author:** ![davidcgu](https://avatars.discourse-cdn.com/v4/letter/d/e8c25b/32.png) [@davidcgu](https://discourse.nodered.org/u/davidcgu)\
**Post date:** [29 June 2018 12:49 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186/2 "2018-06-29T12:49:54Z")

</div>

I think this is not possible however you can manage to set user@pass to be able to make it usable, for instance I have some switch to restart or shutdown the pi and this won’t work unless you first log a passaword.

Regards

---

<div class="post-metadata">

**Author:** ![shrickus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/shrickus/32/517_2.png) [@shrickus](https://discourse.nodered.org/u/shrickus)\
**Post date:** [29 June 2018 12:56 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186/3 "2018-06-29T12:56:03Z")

</div>

I don’t believe that would be possible – but perhaps there’s another approach.

Right now the **id** from each Editor flow (tab) is used in the url for that flow (e.g. `http://localhost/admin/#flow/8a6e1951.cdbcb8`). However, with a small code change I think the url encoded name of the flow could be allowed in the url as well (e.g. `http://localhost/admin/#flow/my+Secure+Flow`). @knolleary would you consider a PR to look up the flow by name if it’s not found by id?

The problem with using the internal id in the url is that the id can change. The problem with using the name is that you will have to ensure unique names across all your flows – but at least you can then add certain middleware to url patterns more easily.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [29 June 2018 12:57 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186/4 "2018-06-29T12:57:56Z")

</div>

@shrickus the question is about accessing dashboard tabs, not editor tabs.

@AtenrevCode the dashboard tabs are all built in the one page. There is not a request to the backend when a user changes tabs in the dashboard. So no, currently there is no way to do per-tab access control.

---

<div class="post-metadata">

**Author:** ![shrickus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/shrickus/32/517_2.png) [@shrickus](https://discourse.nodered.org/u/shrickus)\
**Post date:** [29 June 2018 13:06 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186/5 "2018-06-29T13:06:18Z")

</div>

So it is… can you tell I’ve been working with shuttling node-red urls through an nginx reverse proxy lately?

But I guess I’m still interested in whether you see any value in allowing an alternate form of _editor_ tab urls, containing the name instead of the id.

---

<div class="post-metadata">

**Author:** ![shrickus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/shrickus/32/517_2.png) [@shrickus](https://discourse.nodered.org/u/shrickus)\
**Post date:** [29 June 2018 13:23 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186/6 "2018-06-29T13:23:26Z")

</div>

As Nick says, the dashboard is a Single Page Application (SPA), and so it only renders the portion that corresponds to the page being shown. The only luck I’ve had with managing the page flow is by watching for output from a `ui_control` node, which sends a msg every time the page changes.

Although you can’t do actually “security” with it, you **can** redirect the user back to another page if you detect certain situations (missing context variable, for instance). You can see more examples and some cautions on [this discussion thread](https://discourse.nodered.org/t/orchestrating-dashboard-page-flow-via-ui-control/1103).

---

<div class="post-metadata">

**Author:** ![AtenrevCode](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/atenrevcode/32/901_2.png) [@AtenrevCode](https://discourse.nodered.org/u/AtenrevCode)\
**Post date:** [29 June 2018 13:54 UTC](https://discourse.nodered.org/t/access-a-property-of-the-dashboard-within-a-express-application/1186/7 "2018-06-29T13:54:13Z")

</div>

Thank you all for your responses.

@shrickus I’ll see what can I do with what you propose.
