# Add middleware for static contents

**URL:** <https://discourse.nodered.org/t/add-middleware-for-static-contents/23667>\
**Category:** General\
**Created:** [26 March 2020 10:45 UTC](https://discourse.nodered.org/t/add-middleware-for-static-contents/23667 "2020-03-26T10:45:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jacyuan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jacyuan/32/7256_2.png) [@jacyuan](https://discourse.nodered.org/u/jacyuan)\
**Post date:** [26 March 2020 10:45 UTC](https://discourse.nodered.org/t/add-middleware-for-static-contents/23667/1 "2020-03-26T10:45:59Z")

</div>

Hello everyone,

**Here is my context:**

We would like to use node-red server as an intermediate layer, for accessing private files.

For POC purpose, we added a simple http GET file route under nodered, in order to check and validate the input token from url params. And we read and send back a local file, such as suggested in  
[https://cookbook.nodered.org/http/serve-a-local-file](https://cookbook.nodered.org/http/serve-a-local-file)

The whole mechanism works fine, but to read and send back a file buffer object seems to be slow.  
If we need to show contents (video) in a real time conversation, this solution seems inadaptable.

**Questions:**

- Is there any alternative solutions or mechanisms for facilitating this kind of file download process ?
- I was thinking about using the static folder, since it’s much more faster. But can we add a token validation middleware before access to static folder ? (I've tested the httpNodeMiddleware, but if I understand well, it's only for normal routes)

Thank you very much

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 March 2020 16:24 UTC](https://discourse.nodered.org/t/add-middleware-for-static-contents/23667/2 "2020-03-26T16:24:56Z")

</div>

You can easily check whether `httpNodeMiddleware` by adding a custom header, restarting Node-RED and doing a full reload of a static resource (to clear any caching).

Assuming that doesn't work, you could probably abuse uibuilder to do what you want as that certainly does have a middleware feature that should apply to all resources (I think, I tend to loose track of some of the more esoteric features 🕶). I can probably tweak it anyway if something specific is needed.

---

<div class="post-metadata">

**Author:** ![jacyuan](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jacyuan/32/7256_2.png) [@jacyuan](https://discourse.nodered.org/u/jacyuan)\
**Post date:** [27 March 2020 15:50 UTC](https://discourse.nodered.org/t/add-middleware-for-static-contents/23667/3 "2020-03-27T15:50:57Z")

</div>

(Haha, thanks for advice, i'm gonna test it for my personal projects later 😁)

I checked the code from NodeRed, seems no more than basic auth middleware can be used. I'm wondering whether I should create a node red component for this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [26 May 2020 15:51 UTC](https://discourse.nodered.org/t/add-middleware-for-static-contents/23667/4 "2020-05-26T15:51:00Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
