# (adminAuth) unable to login node-red

**URL:** <https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074>\
**Category:** General\
**Created:** [21 January 2019 03:49 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074 "2019-01-21T03:49:32Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [20 January 2020 13:32 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/22 "2020-01-20T13:32:27Z")

</div>

There seems to be a lot of asterisks in the screenshot above of your login...

When you are trying to login, what are you putting in the password field, the hash which you have in your settings file, or the password that you used to generate the hash?

---

<div class="post-metadata">

**Author:** ![abhishekjaiswalraw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/abhishekjaiswalraw/32/16377_2.png) [@abhishekjaiswalraw](https://discourse.nodered.org/u/abhishekjaiswalraw)\
**Post date:** [21 January 2020 04:53 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/23 "2020-01-21T04:53:13Z")

</div>

I putting the password which there in the setting.js file

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [21 January 2020 10:03 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/24 "2020-01-21T10:03:51Z")

</div>

Can you try copying the username & password shown below into your `settings.js` file;

```auto
     adminAuth: {
        type: "credentials",
        users: [{
            username: "admin",
            password: "$2a$08$1NzTz7reHuZ2LC7PI5raEe6iSWhvs/iPyvqEt7cMulEedF9orq3Xq",
            permissions: "*"
        }]
    },

```

Then restart node-RED, and try and login using these details;  
Username: **admin**  
Password: **mypassword**

...and let us know if you can then log in.

---

<div class="post-metadata">

**Author:** ![abhishekjaiswalraw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/abhishekjaiswalraw/32/16377_2.png) [@abhishekjaiswalraw](https://discourse.nodered.org/u/abhishekjaiswalraw)\
**Post date:** [21 January 2020 17:34 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/25 "2020-01-21T17:34:40Z")

</div>

Thanks Done

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [21 January 2020 18:11 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/26 "2020-01-21T18:11:09Z")

</div>

Are you able to login using those details?

If so, then maybe you made an error generating the password hash, see [https://nodered.org/docs/user-guide/runtime/securing-node-red](https://nodered.org/docs/user-guide/runtime/securing-node-red)

Don't forget to set your own username/password 👍

---

<div class="post-metadata">

**Author:** ![birla8319](https://avatars.discourse-cdn.com/v4/letter/b/ce73a5/32.png) [@birla8319](https://discourse.nodered.org/u/birla8319)\
**Post date:** [3 February 2020 06:50 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/27 "2020-02-03T06:50:19Z")

</div>

Thanks a lot. It would help me a lot in windows.

---

<div class="post-metadata">

**Author:** ![idkpmiller](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/idkpmiller/32/22064_2.png) [@idkpmiller](https://discourse.nodered.org/u/idkpmiller)\
**Post date:** [16 May 2020 21:38 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/28 "2020-05-16T21:38:05Z")

</div>

I hit the same issue that I could not login when setting adminAuth to use a hash.  
I followed through and found the example provided by @Paul-Reed and tested that credential set and that works fine. meaning the issue is more about the hash generation.  
The example working shows

1. I have set everything correct
2. That node-red is functioning correctly
3. the hash is somehow not matching the password string when I generate it using the hash-pw command and node-red decrypts it.

I looked at point #3 a little more and tried to check the hash I provided against the password string using an online tool and they do match. I tried with the example provided and of course it too matched, and I did try a purposely failing case to make sure the online site was correctly functioning and it failed as it should.

I have also tried to generate the hash using an online tool ([https://bcrypt-generator.com](https://bcrypt-generator.com)) and that hash too does not work.  
So my attention returns bck to the only thing that is working on my system that is the example given by Paul-Read. How was that hash generated?

Quite intrigued with whats wrong.

Regards

Paul

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [16 May 2020 21:55 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/29 "2020-05-16T21:55:55Z")

</div>

> [@idkpmiller](#):
>
> How was that hash generated?

By following the [node-RED documentation](https://nodered.org/docs/user-guide/runtime/securing-node-red)...

The command `node -e "console.log(require('bcryptjs').hashSync(process.argv[1], 8));" your-password-here` seems a pretty reliable way to generate it.

---

<div class="post-metadata">

**Author:** ![idkpmiller](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/idkpmiller/32/22064_2.png) [@idkpmiller](https://discourse.nodered.org/u/idkpmiller)\
**Post date:** [16 May 2020 22:20 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/30 "2020-05-16T22:20:16Z")

</div>

I did see that alternative way mentioned and did try to see it it would produce the same result, unfortunately it is not clear to me what directory is the 'node-red' directory as there are a few levels in my users home directory I did try using it to see if I could generate something and it failed with errors so I gathered it was because I am not in the correct directory when executing the command, but perhaps the errors needs further investigation. Can you give the hash-pw method a try that is also staed in the instructions and see if it also works for you? I suspect it will. I just would like the confirmation.

Thanks  
Paul

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [16 May 2020 22:40 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/31 "2020-05-16T22:40:26Z")

</div>

> [@idkpmiller](#):
>
> unfortunately it is not clear to me what directory is the 'node-red' directory

Yes, the wording in the docs is a little misleading -

> Alternative, you can run the following command from within the Node-RED **install** directory:

I run the command from within the node-RED **user** directory, which on a Raspberry Pi is `/home/pi/.node-red` and seems to work fine.  
The **user** directory is where your `settings.js` & `flows.json` files are stored.

---

<div class="post-metadata">

**Author:** ![meeki007](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/meeki007/32/12499_2.png) [@meeki007](https://discourse.nodered.org/u/meeki007)\
**Post date:** [17 May 2020 03:40 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/32 "2020-05-17T03:40:17Z")

</div>

I just tested [node-red-contrib-bcrypt](https://flows.nodered.org/node/node-red-contrib-bcrypt)  
It works for generating a good hash that works with adminAuth

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [17 May 2020 06:02 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/33 "2020-05-17T06:02:16Z")

</div>

Yes. I did once propose we create a node-red-hashpw shortcut but for some reason Nick wasn't keen.

---

<div class="post-metadata">

**Author:** ![idkpmiller](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/idkpmiller/32/22064_2.png) [@idkpmiller](https://discourse.nodered.org/u/idkpmiller)\
**Post date:** [18 May 2020 06:22 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/34 "2020-05-18T06:22:43Z")

</div>

I think the issue is my install, for some reason is has some issue that I cannot explain as it works with the hash of mypassword provided.  
I have tried doing the command below as root and as the openhabian user, I am not on a pi but I built my openhab install using the openhabian scripts.

```auto
root@openhab /home...openhabian/.node-red $ su openhabian -
bash: cannot set terminal process group (-1): Inappropriate ioctl for device
bash: no job control in this shell
openhabian@openhab:~/.node-red$ pwd
/home/openhabian/.node-red
openhabian@openhab:~/.node-red$ node -e "console.log(require('bcryptjs').hashSync(process.argv[1], 8));" mypassword
internal/modules/cjs/loader.js:550
    throw err;
    ^

Error: Cannot find module 'bcryptjs'
    at Function.Module._resolveFilename (internal/modules/cjs/loader.js:548:15)
    at Function.Module._load (internal/modules/cjs/loader.js:475:25)
    at Module.require (internal/modules/cjs/loader.js:598:17)
    at require (internal/modules/cjs/helpers.js:11:18)
    at [eval]:1:13
    at Script.runInThisContext (vm.js:65:33)
    at Object.runInThisContext (vm.js:197:38)
    at Object.<anonymous> ([eval]-wrapper:6:22)
    at Module._compile (internal/modules/cjs/loader.js:654:30)
    at evalScript (internal/bootstrap/node.js:483:27)
openhabian@openhab:~/.node-red$

```

If somebody could help me step through getting this resolved please.

Regards  
Paul

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [18 May 2020 07:47 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/35 "2020-05-18T07:47:46Z")

</div>

Is bcrypt installed in your operating system?  
It's not installed by default in all OS, you may need to manually install it.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [18 May 2020 08:00 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/36 "2020-05-18T08:00:37Z")

</div>

No - that is not the advice that is needed here.

That one-liner alternative has to be run in the directory where Node-RED is _installed_. It's hard to be more specific because each OS puts globally installed modules in a slightly different place.

If you run: `npm list -g node-red` it should tell you where it is installed - go to that directory and rerun the command.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [18 May 2020 08:36 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/37 "2020-05-18T08:36:45Z")

</div>

Have I been doing it wrong all these years... perhaps it's something unique to Raspbian.

![pswd](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/b/0b3217fa1475c3c3e73c7236eae9eb0ba62fcbe2.jpeg)

![pswd](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/e/6e29f767af2142275652c0248fbc51f5291f541a.jpeg)

---

<div class="post-metadata">

**Author:** ![afelix](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/afelix/32/9743_2.png) [@afelix](https://discourse.nodered.org/u/afelix)\
**Post date:** [18 May 2020 08:42 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/38 "2020-05-18T08:42:08Z")

</div>

Have you installed bcrypt globally or is it present in the node\_modules in your nr user dir? For either, that command would work.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [18 May 2020 08:51 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/39 "2020-05-18T08:51:08Z")

</div>

> [@afelix](#):
>
> or is it present in the node\_modules in your nr user dir?

I can't recall how/if bcrypt was originally installed, but yes it's present in `node_modules`, so I'm assuming that's why it's working from `.node-red`.

---

<div class="post-metadata">

**Author:** ![dborsnich](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dborsnich/32/21072_2.png) [@dborsnich](https://discourse.nodered.org/u/dborsnich)\
**Post date:** [28 May 2020 20:49 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/40 "2020-05-28T20:49:48Z")

</div>

Thanks, it works for me. With only user and password in text, does'nt work  
With password hash, works ok  
Node red in a Azure ubuntu virtualization 18.04

---

<div class="post-metadata">

**Author:** ![panban-ux](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/panban-ux/32/21609_2.png) [@panban-ux](https://discourse.nodered.org/u/panban-ux)\
**Post date:** [9 June 2020 19:37 UTC](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074/41 "2020-06-09T19:37:06Z")

</div>

i succesfully generated a password with  
node-red-admin hash-pw  
and paste it inside the settings.js but only is unlocked with mypassword. How odd is that. its straight forward creating a has what the error you mentioning on a later post?  
What about **mypassword** can anyone log with it and not the stored hash?  
what i found strange though is when i hit node-red-admin hash-pw doesnt allow me enter a pass just the enter key works and then generates a hash

[Previous page](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074.md?page=1)

[Next page](https://discourse.nodered.org/t/adminauth-unable-to-login-node-red/7074.md?page=3)
