# Credentials for "function" node

**URL:** <https://discourse.nodered.org/t/credentials-for-function-node/88524>\
**Category:** Feature Requests\
**Tags:** function-node\
**Created:** [5 June 2024 16:03 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524 "2024-06-05T16:03:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dpslavov](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dpslavov/32/91750_2.png) [@dpslavov](https://discourse.nodered.org/u/dpslavov)\
**Post date:** [5 June 2024 16:03 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/1 "2024-06-05T16:03:59Z")

</div>

Hello,

I've implemented a new functionality for "function" node for configuring a single pair of credentials and make them available for use in function's code. It's based on already available credentials framework for node development, really a simple patch.  
What's your opinion, will this be a valuable addition and should I open a PR for it?

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [5 June 2024 16:40 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/2 "2024-06-05T16:40:42Z")

</div>

> [@dpslavov](#):
>
> make them available for use in function's code

Hi,  
What do you mean by that ?  
Password type credentials are not readable by the editor. If you bypass this, you leave the editor vulnerable.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [5 June 2024 17:06 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/3 "2024-06-05T17:06:42Z")

</div>

@dpslavov a screenshot might help demonstrate what you are proposing.

In general, we have various other ways to make credentials available to a node. For example, you can add an env var at the Group, Subflow or Flow level that is stored as a credential:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/c/6c608e15bd33613f1529ae57d38460ee635c8119.png)

The node can then just use `env.get('my secret')` to retrieve the value.

---

<div class="post-metadata">

**Author:** ![dpslavov](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dpslavov/32/91750_2.png) [@dpslavov](https://discourse.nodered.org/u/dpslavov)\
**Post date:** [6 June 2024 19:00 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/4 "2024-06-06T19:00:56Z")

</div>

Hi,

You are confusing code with editor. What I mean is that `node` object has new property `credentials` which you can use in your code like this:

```auto
const username = node.credentials.username;
const password = node.credentials.password;

```

In this way you don't have to have plaintext passwords in your flow.

---

<div class="post-metadata">

**Author:** ![dpslavov](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dpslavov/32/91750_2.png) [@dpslavov](https://discourse.nodered.org/u/dpslavov)\
**Post date:** [6 June 2024 19:09 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/5 "2024-06-06T19:09:21Z")

</div>

@knolleary Here are some screenshots:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/b/6b71b99bac4be3a4d78df00c37e4a84d28de25cd.png)  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/9/e931e993677b8afc3997c2f453f42baf54cb9fe1.png)

To be honest I didn't knew that environment variables can be stored as secrets, if I knew that probably I wouldn't implement this patch...

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [7 June 2024 04:23 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/6 "2024-06-07T04:23:17Z")

</div>

Although I don't think this is a bad idea, what if you need more than 1 credential ?  
Note that there is a dedicated node available for influx.

---

<div class="post-metadata">

**Author:** ![dpslavov](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dpslavov/32/91750_2.png) [@dpslavov](https://discourse.nodered.org/u/dpslavov)\
**Post date:** [7 June 2024 07:57 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/7 "2024-06-07T07:57:54Z")

</div>

Node's credentials implementation isn't well suited for multiple records. Of course it isn't impossible to to implement such thing but I preferred clean implementation and easy of use over functionality.  
Yes, I'm aware that several InfluxDB contrib nodes do exists.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [6 August 2024 07:58 UTC](https://discourse.nodered.org/t/credentials-for-function-node/88524/8 "2024-08-06T07:58:50Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
