# Access Flows based on authentication

**URL:** <https://discourse.nodered.org/t/access-flows-based-on-authentication/76669>\
**Category:** General\
**Tags:** security\
**Created:** [17 March 2023 14:19 UTC](https://discourse.nodered.org/t/access-flows-based-on-authentication/76669 "2023-03-17T14:19:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![spady7](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/spady7/32/67541_2.png) [@spady7](https://discourse.nodered.org/u/spady7)\
**Post date:** [17 March 2023 14:19 UTC](https://discourse.nodered.org/t/access-flows-based-on-authentication/76669/1 "2023-03-17T14:19:31Z")

</div>

Hi, I've tried different ways to restrict access to only some flows, based on users.  
I tried enabling the "projects" and configured as follows:

```auto
   adminAuth: {
        type: "credentials",
        users: [{
            username: "admin",
            password: "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
           permissions: ["read", "write", "projects:project1"]
        }]
    },

```

```auto
       projects: {
            /** To enable the Projects feature, set this value to true */
            enabled: true,
            workflow: {
                /** Set the default projects workflow mode.
                 * - manual - you must manually commit changes
                 * - auto - changes are automatically committed
                 * This can be overridden per-user from the 'Git config'
                 * section of 'User Settings' within the editor
                 */
                mode: "manual"
            },
			projects: {
			  "project1": {
				// Restrict access to this project to user1
				users: ["admin"],
				// Define the flows in this project
				flowFile: "flows_project1.json",
				// Additional project settings
				settings: {
				  // Enable or disable project-level logging
				  logging: false,
				  // Set the maximum number of active flows in this project
				  flow_limit: 10
				  // Other project-level settings
				}
			  }
			}
		},

```

But it's not working.  
Anyone can help on it?  
Regards

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [17 March 2023 14:24 UTC](https://discourse.nodered.org/t/access-flows-based-on-authentication/76669/2 "2023-03-17T14:24:51Z")

</div>

Hi @spady7

I'm not sure where you got that configuration from, but Node-RED doesn't support the idea of restricting access to particular flows.

A user can either access the editor or they cannot. The permissions model does not extend to individual projects or flows within a project.

---

<div class="post-metadata">

**Author:** ![spady7](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/spady7/32/67541_2.png) [@spady7](https://discourse.nodered.org/u/spady7)\
**Post date:** [17 March 2023 14:27 UTC](https://discourse.nodered.org/t/access-flows-based-on-authentication/76669/3 "2023-03-17T14:27:47Z")

</div>

Uhh ok, thank you for quick reply. Is there any plan to achieve it?  
Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [31 March 2023 14:28 UTC](https://discourse.nodered.org/t/access-flows-based-on-authentication/76669/4 "2023-03-31T14:28:30Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
