# Constantly having to authorize when using static links

**URL:** <https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468>\
**Category:** Dashboard\
**Tags:** dashboard-2\
**Created:** [12 February 2024 21:41 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468 "2024-02-12T21:41:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [12 February 2024 21:41 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/1 "2024-02-12T21:41:32Z")

</div>

I'm using example buttons - [Dashboard 2 Beta development - #162 by hotNipi](https://discourse.nodered.org/t/dashboard-2-beta-development/83550/162) but finding whenever I load the DB page I have to re-authorized it 🥵  
I'm using `httpStaticAuth` to protect endpoints, and thinking that it's due to the CSS using a static served image which is hosted in my NR instance.

```auto
.dusk_city_icon{
    --icon_src: url("/static/noderedbutton/cityscape-at-dusk.svg");
    --button_background:#f4900c;
}

```

Any way to stop this PITA, apart from hosting the image elsewhere or using inbuilt icons?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [13 February 2024 02:32 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/2 "2024-02-13T02:32:51Z")

</div>

As always, if you used a proxy to handle all the TLS and auth, everything would be covered I think.

---

<div class="post-metadata">

**Author:** ![kevinGodell](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kevingodell/32/27040_2.png) [@kevinGodell](https://discourse.nodered.org/u/kevinGodell)\
**Post date:** [13 February 2024 14:21 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/3 "2024-02-13T14:21:27Z")

</div>

> [@Paul-Reed](#):
>
> Any way to stop this PITA, apart from hosting the image elsewhere or using inbuilt icons?

If your are also using httpNodeAuth and depending on how you set httpStaticRoot and httpNodeRoot, the static paths may be behind 2 basic-auth middlewares.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [13 February 2024 20:52 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/4 "2024-02-13T20:52:50Z")

</div>

Just tried hosting the image files in Github, and accessing them via Github Pages instead of serving them via node-RED static.  
Seems to solve the problem 😃

Any problems with using this solution?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [13 February 2024 23:52 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/5 "2024-02-13T23:52:35Z")

</div>

> [@Paul-Reed](#):
>
> Any problems with using this solution?

I can think of a number of potential security and operational related issues. But much depends on the detailed configuration.

It would certainly be better to work out why this is happening and fix it. I don't know enough about your config to suggest something I'm afraid.

You _could_ turn the SVG into a data: embedded image but that is likely to be quite large. May be worth trying though. Then the image can be part of your CSS directly without having to load it.

---

<div class="post-metadata">

**Author:** ![hotNipi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hotnipi/32/383_2.png) [@hotNipi](https://discourse.nodered.org/u/hotNipi)\
**Post date:** [14 February 2024 09:32 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/6 "2024-02-14T09:32:27Z")

</div>

> [@TotallyInformation](#):
>
> You _could_ turn the SVG into a data: embedded image

If you now wonder how to do it - just find an online converter and convert the svg to the base64 string and then replace the content of the `--icon_src` url

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/3/4343c56a907908ed136d8822cb27d021f7190a0b.png)

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [14 February 2024 19:25 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/7 "2024-02-14T19:25:59Z")

</div>

> [@hotNipi](#):
>
> If you now wonder how to do it

You know me too well!!

Thanks @TotallyInformation & @hotNipi - Yes, that works well, and on simple icons, the file size isn't too bad.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [15 March 2024 19:26 UTC](https://discourse.nodered.org/t/constantly-having-to-authorize-when-using-static-links/85468/8 "2024-03-15T19:26:31Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
