# Custom autheitication. sharing data with variable in settings.json

**URL:** <https://discourse.nodered.org/t/custom-autheitication-sharing-data-with-variable-in-settings-json/101700>\
**Category:** General\
**Created:** [30 August 2026 06:52 UTC](https://discourse.nodered.org/t/custom-autheitication-sharing-data-with-variable-in-settings-json/101700 "2026-08-30T06:52:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![svefro](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/svefro/32/4306_2.png) [@svefro](https://discourse.nodered.org/u/svefro)\
**Post date:** [30 August 2026 06:52 UTC](https://discourse.nodered.org/t/custom-autheitication-sharing-data-with-variable-in-settings-json/101700/1 "2026-08-30T06:52:50Z")

</div>

I have made a custom authentication middleware in settings.js that handles session and users for all my http nodes.

Currently i store data in a global in settings.js `global['my_auth_data']` this is loaded on each request and updated when a user is logged in. They then get a httponly cookie with a session id that is matched on all subsequent request.

I also want to bind the session\_id to a websocket \_session.id for the user to limit some users from some websocket commands.

to do this i have made a http endpoint `/user_session` that serves the session\_id back to the spa.  
That same endpoint contains the variable with the last update to `global['my_auth_data']` this is saved in node-red global context as `sessions` object, this is going to be used later in node red to match websocket \_session.id to the user

I know that sending session id to the user and back is not the best way to do it, better suggestions are accepted 🙂 )

in node-red i need to match the session\_id to a user and session in global context `sessions` object, and then add that websocket \_session.id to that users session.

after this i accept or deny certian commands for that user / userlevel

My problem is that i have not found a good way of updating the original `global['my_auth_data']`with the websocket sessions.

so i constantly need to merge the two everytime i get an updated version trough /user\_session.

How can this be acomplished?

i see that there is a `webSocketNodeVerifyClient`that i could use to limit entire sessions. but i just want to limit some commands.

I wish there was a websocket middleware that i could hook in to in settings.js.  
i could then attach my session info in the message that goes to node red. same way i do with the httpMiddleware.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [30 August 2026 19:30 UTC](https://discourse.nodered.org/t/custom-autheitication-sharing-data-with-variable-in-settings-json/101700/2 "2026-08-30T19:30:27Z")

</div>

I've not checked your request too closely, but have you checked out UIBUILDER?

UIBUILDER will take up some of the heavy lifting for you as it automatically creates a [socket.io](http://socket.io) realtime connection between Node-RED and client browsers. There are various features available that will help with passing user data and validating user access.

---

<div class="post-metadata">

**Author:** ![svefro](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/svefro/32/4306_2.png) [@svefro](https://discourse.nodered.org/u/svefro)\
**Post date:** [30 August 2026 21:02 UTC](https://discourse.nodered.org/t/custom-autheitication-sharing-data-with-variable-in-settings-json/101700/3 "2026-08-30T21:02:35Z")

</div>

I think i'm to far down the rabbit hole on this to use that. 😛

---

<div class="post-metadata">

**Author:** ![svefro](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/svefro/32/4306_2.png) [@svefro](https://discourse.nodered.org/u/svefro)\
**Post date:** [1 September 2026 07:56 UTC](https://discourse.nodered.org/t/custom-autheitication-sharing-data-with-variable-in-settings-json/101700/4 "2026-09-01T07:56:10Z")

</div>

Ended up using a function in functionGlobalContext
