# Custom Admin API with authentication

**URL:** https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051
**Category:** General
**Created:** [21 May 2020 20:57 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051 "2020-05-21T20:57:43Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ashish-y](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@ashish-y](https://discourse.nodered.org/u/ashish-y)
#### Post date: [21 May 2020 20:57 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051/1 "2020-05-21T20:57:44Z")

</div>

Hi,

I have a custom API that fetches data from a datasource on click of a button from the node-red dropdown menu.

Location of the API:  
packages/node\_modules/@node-red/editor-api/lib/admin/index.js

`adminApp.get("/test",test,apiUtil.errorHandler);`

This works as expected but I wan to encapsulate this under runtime authentication. Something similar to

`adminApp.get("/flows",needsPermission("flows.read"),flows.get,apiUtil.errorHandler);`

**Expected Behavior** : If the user is logged in only then he has access to /test api  
**Current Behavior** : The /test API is open and has no authentication in place.

Any pointers on how to achieve this?

Thanks!

---

<div class="post-metadata">

### Author: ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)
#### Post date: [21 May 2020 21:07 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051/2 "2020-05-21T21:07:53Z")

</div>

Hi @ashish-y

If you look at the `adminApp.get` call you've shared, you'll see the `needsPermission("flows.read")` middleware - that is what enables authentication on the endpoint. You'll need to pick the right permission to require - the string passed to the function.

The permission takes the form of `XYZ.read` or `XYZ.write` - depending on whether it requires read-only or full read/write access.

---

<div class="post-metadata">

### Author: ![ashish-y](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@ashish-y](https://discourse.nodered.org/u/ashish-y)
#### Post date: [21 May 2020 21:16 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051/3 "2020-05-21T21:16:47Z")

</div>

Thanks @knolleary.

Yes, I figured that part out.

So when I do  
`adminApp.get("/test",needsPermission("test.read"),test.get,apiUtil.errorHandler);`  
It's unauthorized.

I guess my question is where do I define scope of this new permission?  
I can't figure out how `needsPermission("flows.read")` is enabling authentication.

---

<div class="post-metadata">

### Author: ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)
#### Post date: [21 May 2020 21:23 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051/4 "2020-05-21T21:23:30Z")

</div>

The `needsPermission` function returns a middleware that handles the request before it reaches your `test.get` function. That middleware checks if the user making the request has the required permission.

> [@ashish-y](#):
>
> I guess my question is where do I define scope of this new permission?

You don't have to predefined the permission anywhere. As long as the permission string takes the form `XYZ.read` or `XYZ.write` then it will work as expected.

As per [the docs](https://nodered.org/docs/user-guide/runtime/securing-node-red#user-permissions) users either have the permission `read` or `*`. If it is `read` then they are allowed to access anything with a `XYZ.read` permission. If it's `*` then they can access everything.

The reason for the `XYZ` part of the permission is to identify the type of resource being accessed - which allows for some finer-grained permissions. For example, a user couple have a permission of `["read", "inject.write"]` - this would allow them read-only access to the editor, but would be able to trigger any inject nodes.

---

<div class="post-metadata">

### Author: ![ashish-y](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@ashish-y](https://discourse.nodered.org/u/ashish-y)
#### Post date: [21 May 2020 23:51 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051/6 "2020-05-21T23:51:45Z")

</div>

Thanks very much for clearing this up, @knolleary

needsPermission was returning unauthorized for one of my custom API.  
I finally figured it out.

Incorrect path in HTTP get request 😛

Finally got it working.

Cheers!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [4 June 2020 23:51 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051/7 "2020-06-04T23:51:49Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
