# $.ajax is not including Bearer if called from HTML

**URL:** <https://discourse.nodered.org/t/ajax-is-not-including-bearer-if-called-from-html/51773>\
**Category:** General\
**Created:** [2 October 2021 09:36 UTC](https://discourse.nodered.org/t/ajax-is-not-including-bearer-if-called-from-html/51773 "2021-10-02T09:36:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [2 October 2021 09:36 UTC](https://discourse.nodered.org/t/ajax-is-not-including-bearer-if-called-from-html/51773/1 "2021-10-02T09:36:54Z")

</div>

Hi

I am working on some security updates, that involves locking down some `RED.httpAdmin` endpoints.

```auto
RED.httpAdmin.get(
			'/zwave-js/cfg-version',
			RED.auth.needsPermission('flows.read'),
			function (req, res) {
				delete require.cache[require.resolve('zwave-js/package.json')];
				const ZWaveJSPackage = require('zwave-js/package.json');
				res.json({
					zwjsversion: ZWaveJSPackage.version,
					zwjscfgversion: ZWaveJSPackage.dependencies['@zwave-js/config'],
					moduleversion: ModulePackage.version
				});
			}
		);

```

This is called upon from `oneditprepare`

```auto
$.ajax({
			url: '/zwave-js/cfg-version',
			cache: false,
			dataType: 'json',
			method: 'GET',
			success: function (data) {
				$('#MOD_Version').val(data.moduleversion);
				$('#ZWJS_Version').val(data.zwjsversion);
				$('#ZWJS_CFGVersion').val(data.zwjscfgversion);
			}
		});

```

however, it seems this does not include the Bearer token, In the header - and of course we get **401 Unauthorized**.

I read you setup the ajax framework to include the Bearer?  
Am I missing something?

Other $.ajax calls do include the header - i.e. in my js file that drives a custom UI tab,  
this seems to be limited to the HTML file -\> `oneditprepare`

Thank you please!

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [2 October 2021 09:51 UTC](https://discourse.nodered.org/t/ajax-is-not-including-bearer-if-called-from-html/51773/2 "2021-10-02T09:51:54Z")

</div>

> [@marcus-j-davies](#):
>
> `url: '/zwave-js/cfg-version',`

Do not start the URL with a `/`.

If a user has set `httpAdminRoot` to move the editor to a different path, you need to make your request relative to the current page and not assume it is served from `/`

That _might_ also solve the bearer token issue.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [2 October 2021 09:54 UTC](https://discourse.nodered.org/t/ajax-is-not-including-bearer-if-called-from-html/51773/3 "2021-10-02T09:54:38Z")

</div>

Well well well, that worked!

Thanks Nick - Much appreciated

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [16 October 2021 09:55 UTC](https://discourse.nodered.org/t/ajax-is-not-including-bearer-if-called-from-html/51773/4 "2021-10-16T09:55:05Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
