# Custom user authentication and check request host

**URL:** <https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430>\
**Category:** General\
**Created:** [14 July 2021 22:50 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430 "2021-07-14T22:50:14Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [14 July 2021 22:50 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/1 "2021-07-14T22:50:14Z")

</div>

can some one help, how check host in adminAuth

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [15 July 2021 06:17 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/2 "2021-07-15T06:17:00Z")

</div>

Can you explain what you mean by that please.

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [15 July 2021 06:55 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/3 "2021-07-15T06:55:53Z")

</div>

this is about a http request, how check header x-forwarded-host or host ?

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [15 July 2021 19:33 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/4 "2021-07-15T19:33:12Z")

</div>

Do I understand correctly that there is no such possibility?

---

<div class="post-metadata">

**Author:** ![Gunner](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gunner/32/43582_2.png) [@Gunner](https://discourse.nodered.org/u/Gunner)\
**Post date:** [15 July 2021 20:45 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/5 "2021-07-15T20:45:52Z")

</div>

Probably not with the limited details you have provided.

Do you have a flow that shows what you have been trying to do?

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [15 July 2021 21:03 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/6 "2021-07-15T21:03:47Z")

</div>

I do not have any flow, I want to check the http.header host in adminAuth property

---

<div class="post-metadata">

**Author:** ![Gunner](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gunner/32/43582_2.png) [@Gunner](https://discourse.nodered.org/u/Gunner)\
**Post date:** [15 July 2021 21:09 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/7 "2021-07-15T21:09:43Z")

</div>

Sooo... To clarify...You want someone else to do your research and find your solution for something you haven't tried yourself, nor provided any clear details on precisely what, where and why?

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [15 July 2021 21:16 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/8 "2021-07-15T21:16:11Z")

</div>

there is documentation [Securing Node-RED : Node-RED](https://nodered.org/docs/user-guide/runtime/securing-node-red#custom-user-authentication), it does not indicate how to use the http request in adminAuth, I ask if it is possible to use http request in adminAuth

but as I understand, there is no such possibility

> <https://github.com/node-red/node-red/blob/4b3f5d74a0e9939639eec19e079dde86e2a86a02/packages/node_modules/@node-red/editor-api/lib/index.js#L67>

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [15 July 2021 21:23 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/9 "2021-07-15T21:23:55Z")

</div>

as the lines just before that show - you can set your own httpAdminMiddleware which is a function where you can probably do whatever you like.

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [15 July 2021 21:38 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/10 "2021-07-15T21:38:39Z")

</div>

thx

I read about httpAdminMiddleware, but there the rule on all for admin / editor routes.  
I only need authenticate page

the task is simple, if the http.header host is "test.example" then show the page authenticate

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [15 July 2021 22:20 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/11 "2021-07-15T22:20:19Z")

</div>

> [@twocolors](#):
>
> I read about httpAdminMiddleware, but there the rule on all for admin / editor routes.

But you can check what route the request is for and decide whether to apply your logic or not.

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [16 July 2021 02:19 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/12 "2021-07-16T02:19:54Z")

</div>

Thank you  
Did I understand you correctly that I would then have to rewrite all the authorization logic?

it seems to me it would be good to have access to req adminAuth , to find user ip/hostname/agent/.. and already build on this logic 'custom code to authenticate'

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [16 July 2021 06:34 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/13 "2021-07-16T06:34:33Z")

</div>

The way express middleware works is to pass to the next handler so if you don't want to handle it you just pass it on.

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [16 July 2021 06:54 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/14 "2021-07-16T06:54:44Z")

</div>

apparently I cannot explain correctly, I want to show /auth/ login only to users with req.hostname='[test.com](http://test.com)', other users must log in without authorization.

in the middleware it turns out, I need to check the hostname and if it is not [test.com](http://test.com) then somehow authorize the user without going to the /auth/login page

all this is not very convenient and it would be easier to write in adminAuth

or I just don't understand how you suggest using httpAdminMiddleware

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 July 2021 07:14 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/15 "2021-07-16T07:14:30Z")

</div>

Hi @twocolors

unfortunately the existing `adminAuth` system doesn't make it very easy to do what you are trying to do. But I think there is a way to do it.

`adminAuth` lets you provide a `tokens` function - that can be used to validate a user token if `adminAuth` doesn't recognise it as one of its own.

In your `httpAdminMiddleware` function, you could check the host and if it fails whatever test you want and it doesn't provide its own auth token via the Authorization header, you could add your own token to the request to show its is allowed in. Then in your `tokens` function of `adminAuth`, check for that token and preauthenticate the user with it.

The only piece of that I'm not 100% sure about is whether the middleware will be allowed to modify the request headers.

---

<div class="post-metadata">

**Author:** ![twocolors](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/twocolors/32/36787_2.png) [@twocolors](https://discourse.nodered.org/u/twocolors)\
**Post date:** [16 July 2021 08:32 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/16 "2021-07-16T08:32:27Z")

</div>

thx, you solved is help me

full code

```auto
    adminAuth: {
        type: "credentials",
        users: [{
            username: "admin",
            password: "$2a$08$ECvfFBqMjCVqGIHrOzfioOfx44Q9.M7ZfeOaq/Hm4C2UOgkuF/fAe", //admin
            permissions: "*"
        }],
        tokenHeader: "x-my-custom-token",
        tokens: function (token) {
            return new Promise(function (resolve, reject) {
                // Do whatever work is needed to check token is valid
                if (token == 'sameorigin') {
                    // Resolve with the user object. It must contain
                    // properties 'username' and 'permissions'
                    var user = { username: 'admin', permissions: '*' };
                    resolve(user);
                } else {
                    // Resolve with null as this user does not exist
                    resolve(null);
                }
            });
        },
    },
    httpAdminMiddleware: function (req, res, next) {
        if (req.hostname == 'localhost') {
            req.headers['x-my-custom-token'] = 'sameorigin';
            if (req.url == '/auth/login') {
                res.redirect('/');
            } else {
                next();
            }
        } else {
            next();
        }
    },

```

but it's not easy for the user to use, @knolleary could you consider adding `req` to `adminAuth` so that i can write a `node` (plugin) auth

thx @knolleary and @dceejay

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [30 July 2021 08:32 UTC](https://discourse.nodered.org/t/custom-user-authentication-and-check-request-host/48430/17 "2021-07-30T08:32:36Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
