# Custom authentication tokens, In the case of source compilation, following the official example does not work

**URL:** <https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025>\
**Category:** General\
**Tags:** security\
**Created:** [16 May 2024 16:25 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025 "2024-05-16T16:25:35Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![xieshuang](https://avatars.discourse-cdn.com/v4/letter/x/7ea924/32.png) [@xieshuang](https://discourse.nodered.org/u/xieshuang)\
**Post date:** [16 May 2024 16:25 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/1 "2024-05-16T16:25:35Z")

</div>

I want to secure Node-RED using a token. I am embedding Node-RED within my website, and I want access to Node-RED to be restricted only through the website. An example of this is provided below:

```auto
 adminAuth: {
        tokens: function(token) {
            return new Promise(function(resolve, reject) {
                // Check if the token is valid
                if (token === 'rdp2vex0nq4mzl8tf8hba1tpr5umtmzn') {
                    // Resolve with the user object
                    var user = { username: 'admin', permissions: '*' };
                    resolve(user);
                } else {
                    // Resolve with null if the token is not valid
                    resolve(null);
                }
            });
        },
    
    },

```

I've managed to secure access to Node-RED. However, I feel like it's not the right way, but it works.  
the problem is there is no protection on Nodes itself, for example, the Node-RED dashboard.  
I've seen this concept implemented in home assistant, but I don't understand how

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 May 2024 16:43 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/2 "2024-05-16T16:43:10Z")

</div>

Leaving aside that the example is certainly NOT, in any way secure.

The example shows authentication for the admin web service - e.g. the Editor and related API's. The user-facing web service used by things like dashboard, http-in/-out, the websocket nodes, UIBUILDER (by default though it can have its own separate server if desired), etc - is secured separately.

---

<div class="post-metadata">

**Author:** ![xieshuang](https://avatars.discourse-cdn.com/v4/letter/x/7ea924/32.png) [@xieshuang](https://discourse.nodered.org/u/xieshuang)\
**Post date:** [17 May 2024 01:37 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/3 "2024-05-17T01:37:57Z")

</div>

This is my adminAuth configuration.

```auto
adminAuth: {
       type: "credentials",
       users: [{
           username: "admin",
           password: "$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN.",
           permissions: "*"
       }],
       tokens: function(token) {
            return new Promise(function(resolve, reject) {
                if (token == 'test') {
                    var user = { username: 'admin', permissions: '*' };
                    resolve(user);
                } else {
                    resolve(null);
                }
            });
        },
        tokenHeader: "token"
    },

```

The final page rendering appears like this, how can I remove the login box?

 ![e5aaf38b0abf82a1d222bd3bd2fbbda](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/1/31e675e62ef8ddc465f32b9a7f8873d32661399d.png)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [17 May 2024 08:22 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/4 "2024-05-17T08:22:45Z")

</div>

How are providing the access token when you load the editor in the browser? With that configuration, it will look for an authentication token in the `token` http header.

---

<div class="post-metadata">

**Author:** ![xieshuang](https://avatars.discourse-cdn.com/v4/letter/x/7ea924/32.png) [@xieshuang](https://discourse.nodered.org/u/xieshuang)\
**Post date:** [17 May 2024 10:18 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/5 "2024-05-17T10:18:31Z")

</div>

I have included the token in the header, and attempting to access via [http://127.0.0.1:1880?access\_token=test](http://127.0.0.1:1880/?access_token=test) also fails.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/1/51ebc9e6f76e966f1089df85a7814cddf917b654.png)

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [17 May 2024 12:06 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/6 "2024-05-17T12:06:56Z")

</div>

Are headers case insensitive ? because in your screenshot it shows `Token` with capital `T`  
Did you try `tokenHeader: "Token"` ?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [17 May 2024 20:09 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/7 "2024-05-17T20:09:25Z")

</div>

http headers should be case insensitive according to the standards.

---

<div class="post-metadata">

**Author:** ![xieshuang](https://avatars.discourse-cdn.com/v4/letter/x/7ea924/32.png) [@xieshuang](https://discourse.nodered.org/u/xieshuang)\
**Post date:** [20 May 2024 01:35 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/8 "2024-05-20T01:35:40Z")

</div>

May I ask, dear experts, how should we proceed to troubleshoot the issue at hand?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [20 May 2024 08:16 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/9 "2024-05-20T08:16:47Z")

</div>

> [@xieshuang](#):
>
> I've managed to secure access to Node-RED. However, I feel like it's not the right way, but it works.  
> the problem is there is no protection on Nodes itself, for example, the Node-RED dashboard.

I believe you are saying that your `adminAuth` configuration is working - you have secured access to the editor.

Your question is how to secure Node-RED dashboard and other HTTP routes created by your flows.

Ben has replied to your question on GitHub here with pointers to how to secure the node routes: [AdminAuth using token fails · Issue #2642 · node-red/node-red · GitHub](https://github.com/node-red/node-red/issues/2642#issuecomment-2119800092)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [18 August 2024 08:17 UTC](https://discourse.nodered.org/t/custom-authentication-tokens-in-the-case-of-source-compilation-following-the-official-example-does-not-work/88025/10 "2024-08-18T08:17:33Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
