# Accessing Global Context Data Inside ui\_base.js for uiShared.httpMiddleware in Node-RED for Custom Authentication

**URL:** <https://discourse.nodered.org/t/accessing-global-context-data-inside-ui-base-js-for-uishared-httpmiddleware-in-node-red-for-custom-authentication/90999>\
**Category:** Dashboard\
**Tags:** dashboard-2\
**Created:** [15 September 2024 12:48 UTC](https://discourse.nodered.org/t/accessing-global-context-data-inside-ui-base-js-for-uishared-httpmiddleware-in-node-red-for-custom-authentication/90999 "2024-09-15T12:48:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DhamodharanGopal](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dhamodharangopal/32/95512_2.png) [@DhamodharanGopal](https://discourse.nodered.org/u/DhamodharanGopal)\
**Post date:** [15 September 2024 12:48 UTC](https://discourse.nodered.org/t/accessing-global-context-data-inside-ui-base-js-for-uishared-httpmiddleware-in-node-red-for-custom-authentication/90999/1 "2024-09-15T12:48:04Z")

</div>

Hello Everyone,

I’m trying to implement custom authentication in Node-RED by accessing global context data inside the `ui_base.js` file, specifically in the `uiShared.httpMiddleware` function, to prevent unauthorized access to the dashboard. I want to retrieve session data stored in the global context and validate it based on a session ID stored in cookies.

Here’s the relevant code snippet from ui\_base.js:

**File Path Reference:** /home/dhamo/.node-red/node\_modules/@flowfuse/node-red-dashboard/nodes/config/ui\_base.js

```auto
uiShared.httpMiddleware = function (req, res, next) {
    // Extract session_id using cookie-parser
    const sessionId = req.cookies.session_id;
    console.log('Extracted session_id:', sessionId);

    // Access global context
    const globalContext = RED.settings.contextStorage; // Not sure if this is correct

    // Check if session_id exists in the global context
    if (sessionId) {
        const sessionData = global.get(sessionId); // Not sure how to access the global context properly
        console.log("sessionData")
        if (sessionData && sessionData.loggedIn) {
            console.log(`Session valid for user: ${sessionData.username}`);
            next(); // Proceed to next middleware
        } else {
            console.log('Session invalid or expired, redirecting to login.');
            res.status(404).send('Session not found. Please log in.');
        }
    } else {
        console.log('No session_id found in the request, redirecting to login.');
        res.status(404).send('No session found. Please log in.');
    }
};

```

**Issue**  
I’m unsure how to properly access the global context data (specifically session information) in this file and function. I attempted to use `RED.settings.contextStorage` and `global.get(sessionId)`, but it seems like I’m not accessing the global context correctly.

**Questions** :

- How can I access the global context data inside `ui_base.js` (or `uiShared.httpMiddleware`) in order to validate session information?
- Is there a better approach for handling custom authentication within Node-RED’s dashboard middleware, or any recommendations on managing session state effectively in this scenario?
- **Session Generation:** Currently, I’m using a simple `Math.random()` approach to generate sessions in /login endpoint inside a function node. Is there a more secure or structured way to generate and manage sessions, which can be used consistently across all nodes and the local source code (including middleware) for authentication?

Any suggestions or code examples would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [18 September 2024 15:13 UTC](https://discourse.nodered.org/t/accessing-global-context-data-inside-ui-base-js-for-uishared-httpmiddleware-in-node-red-for-custom-authentication/90999/2 "2024-09-18T15:13:18Z")

</div>

Hmmm, I'm not sure there is. @Steve-Mcl can you access the `flow`/`global` context stores from within the runtime code?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [18 September 2024 16:25 UTC](https://discourse.nodered.org/t/accessing-global-context-data-inside-ui-base-js-for-uishared-httpmiddleware-in-node-red-for-custom-authentication/90999/3 "2024-09-18T16:25:46Z")

</div>

Yes but it is not advisable as far as I am concerned. For example, I would not want a node reading or writing to context without my knowledge.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [18 October 2024 16:26 UTC](https://discourse.nodered.org/t/accessing-global-context-data-inside-ui-base-js-for-uishared-httpmiddleware-in-node-red-for-custom-authentication/90999/4 "2024-10-18T16:26:10Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
