# Access to header variables in node red editor for authentication

**URL:** <https://discourse.nodered.org/t/access-to-header-variables-in-node-red-editor-for-authentication/21806>\
**Category:** General\
**Created:** [16 February 2020 17:09 UTC](https://discourse.nodered.org/t/access-to-header-variables-in-node-red-editor-for-authentication/21806 "2020-02-16T17:09:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![crackytsi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/crackytsi/32/28369_2.png) [@crackytsi](https://discourse.nodered.org/u/crackytsi)\
**Post date:** [16 February 2020 17:09 UTC](https://discourse.nodered.org/t/access-to-header-variables-in-node-red-editor-for-authentication/21806/1 "2020-02-16T17:09:35Z")

</div>

Hi,  
I want to implement a customer authentication for node red that uses a http header set by a reverse proxy. After several time searching in the internet, I was still unable to find any hint that pointed me in the right direction.

Can you help me?  
How can I access the http header variables (e.g. user-agent) from within the plugin module?

Thanks a lot 🙂

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 February 2020 17:54 UTC](https://discourse.nodered.org/t/access-to-header-variables-in-node-red-editor-for-authentication/21806/2 "2020-02-16T17:54:59Z")

</div>

Short answer: The Auth plugin api doesn't provide a way for it to access the headers. So it isn't possible to do it today.

This has come up a few times recently. There is some work going on to extend what is possible to do with Auth plugins. It doesn't currently address this particular scenario, but perhaps it should.

See my comments here [Use Admin API with adminAuth type strategy](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719/2)

---

<div class="post-metadata">

**Author:** ![crackytsi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/crackytsi/32/28369_2.png) [@crackytsi](https://discourse.nodered.org/u/crackytsi)\
**Post date:** [16 February 2020 18:12 UTC](https://discourse.nodered.org/t/access-to-header-variables-in-node-red-editor-for-authentication/21806/3 "2020-02-16T18:12:30Z")

</div>

Thank you very much @knolleary 🙂 )  
What do you mean with "there is some work going on"?

I think another authentication scenario is to use client-certificate authentication, this would also require to access the authenticated certificate e.g. using [https://www.npmjs.com/package/client-certificate-auth](https://www.npmjs.com/package/client-certificate-auth)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 February 2020 18:56 UTC](https://discourse.nodered.org/t/access-to-header-variables-in-node-red-editor-for-authentication/21806/4 "2020-02-16T18:56:01Z")

</div>

> [@crackytsi](#):
>
> What do you mean with "there is some work going on"?

I mean there is literally someone working on a design for this at the moment, as I describe in the post I linked to.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [16 April 2020 18:56 UTC](https://discourse.nodered.org/t/access-to-header-variables-in-node-red-editor-for-authentication/21806/5 "2020-04-16T18:56:03Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
