# Authentication and Authorization Examples for Node-RED

**URL:** <https://discourse.nodered.org/t/authentication-and-authorization-examples-for-node-red/51750>\
**Category:** Share Your Projects\
**Tags:** security\
**Created:** [1 October 2021 12:38 UTC](https://discourse.nodered.org/t/authentication-and-authorization-examples-for-node-red/51750 "2021-10-01T12:38:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rozek](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rozek/32/48594_2.png) [@rozek](https://discourse.nodered.org/u/rozek)\
**Post date:** [1 October 2021 12:38 UTC](https://discourse.nodered.org/t/authentication-and-authorization-examples-for-node-red/51750/1 "2021-10-01T12:38:04Z")

</div>

I'm currently preparing a set of Node-RED flows and use cases for my students in order to motivate and encourage them to invent and build web sites and REST services without having to know, learn and program much.

Often, such services require some kind of user authentication, sometimes paired with authorization. For that reason, I've implemented three different approaches to authentication and authorization with Node-RED and published them on [GitHub](https://github.com/rozek/node-red-authorization-examples).

Since they may also be of interest to others, feel free to use them in whatever way you like (in fact, the package has already received its first "star" before I was able to "officially" publish it...)

As usual, any feedback is welcome!

With greetings from Germany,

Andreas Rozek

---

<div class="post-metadata">

**Author:** ![rozek](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rozek/32/48594_2.png) [@rozek](https://discourse.nodered.org/u/rozek)\
**Post date:** [2 October 2021 03:40 UTC](https://discourse.nodered.org/t/authentication-and-authorization-examples-for-node-red/51750/2 "2021-10-02T03:40:55Z")

</div>

I've just updated my examples a bit (primarily to enhance the interoperability of all parts in my little "kit" of Node-RED examples and contributions...)

---

<div class="post-metadata">

**Author:** ![rozek](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rozek/32/48594_2.png) [@rozek](https://discourse.nodered.org/u/rozek)\
**Post date:** [22 October 2021 04:26 UTC](https://discourse.nodered.org/t/authentication-and-authorization-examples-for-node-red/51750/3 "2021-10-22T04:26:02Z")

</div>

There is a new version of cookie- and header-based authentication available - the credentials validation functions now remove both `UserId` and `Password` from `msg.payload` in order to avoid sending this sensitive information back.

---

<div class="post-metadata">

**Author:** ![rozek](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rozek/32/48594_2.png) [@rozek](https://discourse.nodered.org/u/rozek)\
**Post date:** [25 October 2021 15:46 UTC](https://discourse.nodered.org/t/authentication-and-authorization-examples-for-node-red/51750/4 "2021-10-25T15:46:37Z")

</div>

Just a small update: the "validate credentials" function nodes now explicitly validate the content type of the incoming POST request body and accept `application/x-www-form-urlencoded` and `application/json` only.

All automated test have been updated accordingly
