# adminAuth stategy role based permission

**URL:** https://discourse.nodered.org/t/adminauth-stategy-role-based-permission/80695
**Category:** General
**Tags:** security
**Created:** [21 August 2023 19:28 UTC](https://discourse.nodered.org/t/adminauth-stategy-role-based-permission/80695 "2023-08-21T19:28:41Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![AMWN](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amwn/32/41809_2.png) [@AMWN](https://discourse.nodered.org/u/AMWN)
#### Post date: [21 August 2023 19:28 UTC](https://discourse.nodered.org/t/adminauth-stategy-role-based-permission/80695/1 "2023-08-21T19:28:41Z")

</div>

This [question](https://discourse.nodered.org/t/role-based-access/28666/5) is asked before, but no good solution was given. I want the give the user permission base on the group he is in azure ad.

I authenticate the users with auth type strategie passport-azure-ad. Just like the [example](https://nodered.org/docs/user-guide/runtime/securing-node-red#oauthopenid-based-authentication) in the docs, it has a verify function. This function calls done(null, profile). The profile has a property username.

The next step is de users function. This function only excepts a user value. This is the username from the profile object passed by de verify function.

```auto
users: function (user) {
            if(user) {
                return Promise.resolve({ username: user, permissions: "*" }) 
            } else {
                return Promise.resolve(null)
            }
        },

```

How can I pass trough the permission from the verify function to the user function?  
Globale variable isn't the solution, because when user logs in by cached token no authentication (validation) happens.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [20 October 2023 19:28 UTC](https://discourse.nodered.org/t/adminauth-stategy-role-based-permission/80695/2 "2023-10-20T19:28:59Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
