# Dashboard Authelia Auth

**URL:** <https://discourse.nodered.org/t/dashboard-authelia-auth/89784>\
**Category:** Share Your Nodes\
**Tags:** dashboard-2\
**Created:** [26 July 2024 09:27 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784 "2024-07-26T09:27:09Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![kitori](https://avatars.discourse-cdn.com/v4/letter/k/f08c70/32.png) [@kitori](https://discourse.nodered.org/u/kitori)\
**Post date:** [26 July 2024 09:27 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/1 "2024-07-26T09:27:09Z")

</div>

Following [this](https://discourse.nodered.org/t/personalised-multi-user-dashboards-with-node-red-dashboard-2-0-flowfuse-webinar/85492/20) discussion, i was inspired by using [Authelia](https://www.authelia.com/) as an Auth provider for the Dashboard.

Thanks to [GitHub - fullmetal-fred/node-red-dashboard-2-cloudflare-auth](https://github.com/fullmetal-fred/node-red-dashboard-2-cloudflare-auth) , it was quickly done 🙂

> **[GitHub - aikitori/node-red-dashboard-2-authelia-auth](https://github.com/aikitori/node-red-dashboard-2-authelia-auth)**
>
> Contribute to aikitori/node-red-dashboard-2-authelia-auth development by creating an account on GitHub.

Hardest part was to setup Authelia locally ...

Any suggestions? Do i missed a part?

The Readme is not ready yet ☹ , i know...

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [26 July 2024 09:32 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/2 "2024-07-26T09:32:40Z")

</div>

Great work @kitori - fyi @fullmetal-fred

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [26 July 2024 09:41 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/3 "2024-07-26T09:41:11Z")

</div>

You should click the "+" button on [flows.nodered.org](https://flows.nodered.org) and add this to the Node-RED Library so that others can install it through their Node-RED Editors.

---

<div class="post-metadata">

**Author:** ![kitori](https://avatars.discourse-cdn.com/v4/letter/k/f08c70/32.png) [@kitori](https://discourse.nodered.org/u/kitori)\
**Post date:** [26 July 2024 10:39 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/4 "2024-07-26T10:39:35Z")

</div>

Thank you! (for making the Dashboard 2 awesome 🙂 )

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 July 2024 11:10 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/5 "2024-07-26T11:10:21Z")

</div>

So, looking into the use of `msg._client` with a view to standardising for UIBUILDER as well so that we can have a standard mechanism across dashboards and ui's.

However, I note that the FlowFuse user extension uses `msg._client.user.userId` ~~but the other two contributions use `msg._client.user.user`~~ but the authelia solution uses `msg._client.user.user` and the cloudflare solution doesn't have anything(?).

This seems like something that should be resolved now before things go too far?

_ **Can we all agree a single property that will contain the unique user identifier?** _

@joepavitt @kitori @fullmetal-fred - apologies for tagging all 3, just want to make sure everyone sees it.

---

<div class="post-metadata">

**Author:** ![kitori](https://avatars.discourse-cdn.com/v4/letter/k/f08c70/32.png) [@kitori](https://discourse.nodered.org/u/kitori)\
**Post date:** [26 July 2024 11:19 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/6 "2024-07-26T11:19:18Z")

</div>

yes, it's a bit of a mess.

The Authelia snippets set these Headers:

> **[NGINX](https://www.authelia.com/integration/proxies/nginx/#authelia-authrequestconf)**
>
> An integration guide for Authelia and the NGINX reverse proxy

```auto
proxy_set_header Remote-User $user;
proxy_set_header Remote-Groups $groups;
proxy_set_header Remote-Email $email;
proxy_set_header Remote-Name $name;

```

Which i access here: [node-red-dashboard-2-authelia-auth/index.js at 712678b2a1f014f0c578c9253522dbb25ad8792b · aikitori/node-red-dashboard-2-authelia-auth · GitHub](https://github.com/aikitori/node-red-dashboard-2-authelia-auth/blob/712678b2a1f014f0c578c9253522dbb25ad8792b/index.js#L37)

```auto
user.user = headers["remote-user"] || null;
user.name = headers["remote-name"] || null;
user.email = headers["remote-email"] || null
user.groups = headers["remote-groups"] || null;

```

Cloudflare sets the email as the unique username.  
In authelia, the user lives in the users.yaml:

```auto
users:
  fabian:
    disabled: false
    displayname: "Fabian"
    password: "ChangeMe" 
    email: authelia@authelia.com
    groups:
      - admins
      - dev

```

In my oppinion, `userId` for the unique identifier is the way

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 July 2024 11:59 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/7 "2024-07-26T11:59:23Z")

</div>

> [@kitori](#):
>
> In my oppinion, `userId` for the unique identifier is the way

I agree so that makes 3 out of 4 😀 Perhaps @fullmetal-fred can be persuaded to add that to his cloudflare offering.

I will be adding a feature to UIBUILDER v7, due out soon (if I can stop adding new things into it!), that will populate the `msg._client` based on all 3 authentication types. I'll probably also add a hook that lets it be overridden in settings.js (uibuilder hooks are another new feature in v7).

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 July 2024 16:55 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/8 "2024-07-26T16:55:19Z")

</div>

Please note that I did spot a couple of issues with D2 auth plugins. Documented here:

> [@Standardising authorised user details across dashboards and uibuilder](https://discourse.nodered.org/t/standardising-authorised-user-details-across-dashboards-and-uibuilder/89798):
>
> Hi all, there has been some work done by FlowFuse @joepavitt and a couple of other contribotors @fullmetal-fred and @kitori on standardising authorised client information for Dashboard 2. Having seen this, I thought it would be good to bring the same data standard into UIBUILDER as well. Whereas for D2, you need a plugin, for UIBUILDER I wanted to build in some basics and then allow a hook to allow other methods to be used if needed. In doing so however, I did note a few potential issues wi…

In case it is of use.

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [26 July 2024 17:44 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/9 "2024-07-26T17:44:20Z")

</div>

Other than:

> 1. Client IP addresses are not very easy to correctly obtain.

Not sure I'm seeing much else for us to act upon?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 July 2024 18:52 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/10 "2024-07-26T18:52:22Z")

</div>

That's probably it for FlowFuse I think. 🙂

---

<div class="post-metadata">

**Author:** ![fullmetal-fred](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fullmetal-fred/32/90453_2.png) [@fullmetal-fred](https://discourse.nodered.org/u/fullmetal-fred)\
**Post date:** [29 July 2024 12:56 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/11 "2024-07-29T12:56:12Z")

</div>

Hey all!

Sure, easy enough to populate msg.\_client.user.userId with the user’s email in the case of Cloudflare. I’ll update my plugin.

@joepavitt we might consider stipulating this as a convention in the plugin docs.

Thanks for the interest here @TotallyInformation!

---

<div class="post-metadata">

**Author:** ![fullmetal-fred](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fullmetal-fred/32/90453_2.png) [@fullmetal-fred](https://discourse.nodered.org/u/fullmetal-fred)\
**Post date:** [29 July 2024 12:59 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/12 "2024-07-29T12:59:09Z")

</div>

Oh, @kitori congrats on the plugin and thanks for the shout out!

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [29 July 2024 14:48 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/13 "2024-07-29T14:48:32Z")

</div>

> [@fullmetal-fred](#):
>
> Thanks for the interest here @TotallyInformation!

No worries. Already added to UIBUILDER v7 beta.

---

<div class="post-metadata">

**Author:** ![cgjgh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/cgjgh/32/99867_2.png) [@cgjgh](https://discourse.nodered.org/u/cgjgh)\
**Post date:** [31 July 2024 20:44 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/14 "2024-07-31T20:44:17Z")

</div>

Made an auth plugin for [Authentik](https://goauthentik.io/).  
[node-red-dashboard-2-authentik-auth](https://github.com/cgjgh/node-red-dashboard-2-authentik-auth)  
(Thanks to @fullmetal-fred and @kitori for their example repos)

Think we could definitely use some documentation for user info standardization.

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [31 July 2024 22:08 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/15 "2024-07-31T22:08:47Z")

</div>

> [@cgjgh](#):
>
> Think we could definitely use some documentation for user info standardization.

Yep - I can make it so. I've been caught off guard (in a very good way) at how quickly other plugins have surfaced so it hadn't been a priority.

I'll try and get something together over the next couple of days.

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [31 July 2024 22:10 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/16 "2024-07-31T22:10:49Z")

</div>

Can I trouble @cgjgh and @kitori to publish their respective plugins to npm please? Then we can make them available in the Node-RED Palette Manager.

---

<div class="post-metadata">

**Author:** ![fullmetal-fred](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fullmetal-fred/32/90453_2.png) [@fullmetal-fred](https://discourse.nodered.org/u/fullmetal-fred)\
**Post date:** [31 July 2024 22:35 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/17 "2024-07-31T22:35:56Z")

</div>

@TotallyInformation see updated version 0.1.7 where msg.\_client.user.userId is now also set with the user's email.

> **[@fullmetal-fred/node-red-dashboard-2-cloudflare-auth](https://flows.nodered.org/node/@fullmetal-fred/node-red-dashboard-2-cloudflare-auth)**
>
> When used with Cloudflare Access authentication, this plugin will pass the email address of an authenticated user into the \_client object under \_client.user.email

---

<div class="post-metadata">

**Author:** ![cgjgh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/cgjgh/32/99867_2.png) [@cgjgh](https://discourse.nodered.org/u/cgjgh)\
**Post date:** [31 July 2024 23:55 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/18 "2024-07-31T23:55:19Z")

</div>

> **[@cgjgh/node-red-dashboard-2-authentik-auth](https://flows.nodered.org/node/@cgjgh/node-red-dashboard-2-authentik-auth)**
>
> Dashboard Auth with Authentik

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [1 August 2024 09:05 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/19 "2024-08-01T09:05:54Z")

</div>

Darn it, another set of different headers. Wish tools would stick to standards!

---

<div class="post-metadata">

**Author:** ![Pepex7](https://avatars.discourse-cdn.com/v4/letter/p/a88e57/32.png) [@Pepex7](https://discourse.nodered.org/u/Pepex7)\
**Post date:** [2 August 2024 01:50 UTC](https://discourse.nodered.org/t/dashboard-authelia-auth/89784/20 "2024-08-02T01:50:26Z")

</div>

Do you have any guide to implement Authelia locally? I've been struggling with this for several days?

[Next page](https://discourse.nodered.org/t/dashboard-authelia-auth/89784.md?page=2)
