# Digest authentication support in HttpRequest node

**URL:** <https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131>\
**Category:** Feature Requests\
**Created:** [19 October 2018 21:45 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131 "2018-10-19T21:45:35Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [19 October 2018 21:45 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/1 "2018-10-19T21:45:35Z")

</div>

Hi folks,

I got a question last week from a poor bastard who had bought a box full of chinese IP camera's. He could access the IP camera's from within the browser without problems. However from within a Node-RED flow (e.g. httprequest node) he received an **unauthorised** exception, although he entered the SAME url/username/password combination ...

I found out that his camera expected _digest authentication_, while the httprequest node only offers _basic authentication_. Here is the difference in a nutshell:

- **Basic authentication** : The client sends a HTTP request with an 'authorization' header that contains the word _Basic_ followed by a space and a base64-encoded _string username:password_. For example:

- **Digest authentication** : The client sends a HTTP request with an 'authorization' header that contains an MD5 hashed password. For example:

Fortunately @HirokiUchikawa has recently reworked the [httprequest](https://github.com/node-red/node-red/blob/9fd5d1db56a6b25a5342b55cd893a5f180e07909/nodes/core/io/21-httprequest.js) node, to make use of the '[request](https://www.npmjs.com/package/request)' library. And that library offers digest authentication:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/9/95258b6d4566d5ec1e05e2abaa1c3b1bfa5147bd.png)

And that works fine! When I set the sendImmediately to true, the basic authentication still works on my own IP camera **and** the digest authentication works fine on the chinese IP camera's. Only a single line of code need to be added:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/4/4d10047d1473853d57876795dd3e1a2e6130d675.png)

Some questions about this change:

- Is this an acceptable change?
- Does the node's config screen need to show the 'digest' somewhere?  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/6/65c93e40df3c07d101cb8e974ec98cb877c4251e.png)

Thanks !  
Bart

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [19 October 2018 22:21 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/2 "2018-10-19T22:21:21Z")

</div>

> [@BartButenaers](#):
>
> When I set the sendImmediately to true,

I assume you mean `false` as per the screenshot?

When its sent to false, the library sends the request without any auth info attached. The 401 response it gets back from the server will include the type of auth required, so the library can resubmit the request with the appropriate auth header.

So it works, but it takes two requests over the network. So I don't think we can afford to hard code it in - by definition, all flows that successfully use auth with the node today will be penalised.

That does mean it would need to be exposed as an option in the UI, but at this point of a Friday night, I don't know what that should look like.

A tick box for 'send immediately' doesn't really help the user understand what it means - I had to read the 3 paragraphs of the request module's readme a couple times to understand what it meant.

Maybe a select box for the type of auth - which could be expanded to include Bearer (something that can be done today by setting `msg.headers.authorization` to the right value before the HTTP Request node). Needs more thought about what the different options mean and what they would require the node to actually do.

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [19 October 2018 22:30 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/3 "2018-10-19T22:30:51Z")

</div>

> [@knolleary](#):
>
> I assume you mean `false` as per the screenshot?

Indeed, that was a type error... By setting it to 'false' the digest authentication works fine.

> [@knolleary](#):
>
> So it works, but it takes two requests over the network. So I don't think we can afford to hard code it in

Ok, I agree with that explanation.

> [@knolleary](#):
>
> Maybe a select box for the type of auth

Have been thinking about that also, but I thought I would get lapidated when suggesting it ...

---

<div class="post-metadata">

**Author:** ![rjandsam](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@rjandsam](https://discourse.nodered.org/u/rjandsam)\
**Post date:** [13 February 2019 08:10 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/4 "2019-02-13T08:10:53Z")

</div>

Hi,  
I am new to Node-Red and I am interested in the topic you have discussed.

I am using the HTTP Request node that is part of Node-Red to communicate with a Hikvision PTZ camera and I am doing this successfully but only with basic authentication, I would like to use digest as it is more secure and was wondering if you could explain how I change the options to do this.

do I need to install something extra as I have read all of the above and noticed you have added a line of code but I have no idea how this is done. do you have any pointers or a link to where I can learn more on how to do this type of modification.

Thanks

Rich

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [13 February 2019 09:56 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/5 "2019-02-13T09:56:11Z")

</div>

Hi Richard (@rjandsam

This is indeed a feature that some other folks have already been asked me about, since it is used quited a lot for multiple branches of IP camera's. However as Nick already explained, that single line of code is not a good solution. There would be a better solution, e.g. a dropdown with authentication methods...

All proposals are welcome!!  
Bart

---

<div class="post-metadata">

**Author:** ![rjandsam](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@rjandsam](https://discourse.nodered.org/u/rjandsam)\
**Post date:** [14 February 2019 21:10 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/6 "2019-02-14T21:10:26Z")

</div>

My programmer Darren has recreated both files to do exactly that and it works a treat is this something that you would like me to share if so what is the protocol, if any for this?

 ![Request](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/2/27e9e08bfc126bd4eb9e2d0db7fb1ab754276c64.png)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [14 February 2019 21:50 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/7 "2019-02-14T21:50:10Z")

</div>

> [@rjandsam](#):
>
> My programmer Darren has recreated both files to do exactly that and it works a treat is this something that you would like me to share if so what is the protocol, if any for this?

A pull-request to allow us to see the proposed changes and to review them would be a next step.

Also some discussion around the actual implementation that covers some of the questions I raised in my previous post would be useful.

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [14 February 2019 22:15 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/8 "2019-02-14T22:15:40Z")

</div>

Hey Nick (@knolleary),  
I thought (from the above discussion) that you wanted to add also **Bearer** authentication. Which would make sense, since then the HttpRequest node would support all 3 [available](https://github.com/request/request#http-authentication) authentication methods.

Something like this (with checkbox description changed and dropdown added):

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/6/6902757e4638cb172363f3f4134608b29741d599.png)

Containing following options in the dropdown:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/9/9028f87eed77d960db02c38550383aec28d70a99.png)

With 'Basic authentication' **default** selected, to avoid impact on existing flows ...

Bart

---

<div class="post-metadata">

**Author:** ![1iveowl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/1iveowl/32/6081_2.png) [@1iveowl](https://discourse.nodered.org/u/1iveowl)\
**Post date:** [17 February 2019 12:48 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/9 "2019-02-17T12:48:12Z")

</div>

@BartButenaers Looks very nice and handy. Is there an ETA 🙂 ?

As a related side note:

I'm struggling with Digest Authentican using http-request. Since it's not currently supported I manage the flow manually through headers and function and md5.

I can get it to work, however, I've run into an annoying issue. For my manual implementatio of Digest Authentication to work, I disable "Use basic authentication". The annoying issue is that it keep enabling itself again, messing up my manual Digest Auth implementation. Here are my observations:

1. If I open the Http Reqeust node and exit with Done, it will re-enable the "Use BAsic Authentication".

2. If I open the Http Request node and exit with Cancel, it will stay disabled.

Seems like a bug to me.

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [17 February 2019 16:44 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/10 "2019-02-17T16:44:29Z")

</div>

> [@1iveowl](#):
>
> Is there an ETA

@1iveowl :  
Since the http-request node is a standard node, it is adviced to wait for feedback from @knolleary (before creating a pull-request). Because the above proposal might have some drawbacks, that I haven't thought about. And once we have an agreement, hopefully Darren (the programmer from @rjandsam) has some time left to implement it 😉

And at the end, I will create an _ **identical** _ solution for my [node-red-contrib-multipart-stream-decoder](http://node-red-contrib-multipart-stream-decoder) node, since users have the same problem there (to get an mjpeg stream from a camera with digest authentication) ...

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [17 February 2019 17:48 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/11 "2019-02-17T17:48:06Z")

</div>

@BartButenaers yes, your suggestion is closer to what I had in mind than what @rjandsam shared - but I wasn't sure if you were offering it up as a contribution or just a mocked up UI to clarify to @rjandsam what was needed.

Either way, there's only a few days left to get anything in 0.20.

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [17 February 2019 18:50 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/12 "2019-02-17T18:50:12Z")

</div>

> [@knolleary](#):
>
> but I wasn't sure if you were offering it up as a contribution or just a mocked up UI to clarify to @rjandsam what was needed.

@knolleary: Well I 'thought' you had something like that in mind, but I was not sure. Will next time try to be a bit more specific when I need your opinion...

> [@knolleary](#):
>
> Either way, there's only a few days left to get anything in 0.20.

I can try to do the contribution myself, but I haven't got a device that supports digest authentication. Will need someone else to test that for me ... Will see what I can do. And if it is too late for the release, no problem. We can't keep going on pushing you to add new stuff into the release.

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [17 February 2019 22:04 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/13 "2019-02-17T22:04:16Z")

</div>

Nick (@knolleary),

I have installed version **0.20.0-beta.5** and changed the config screen behaviour:

![digest](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/f/f30288bc1d29475b49bc921328dc1b5d7f15c7dd.gif)

- By default the '_basic authentication_' is selected, to make sure we don't break existing flows.
- The username and password fields are displayed both for basic and digest authentication.
- When bearer authentication is selected, a bearer token can be entered (which is stored in the credentials section).

Is the config screen ok for you?  
My only doubt is whether the "_ **bearer token** _" label should be changed to simply " **_token_**"??

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [17 February 2019 22:05 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/14 "2019-02-17T22:05:54Z")

</div>

@BartButenaers looks good - but ultimately we'll review it fully once there's a PR. Thanks

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 February 2019 08:09 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/15 "2019-02-18T08:09:31Z")

</div>

@rjandsam,  
I have created a [fork](https://github.com/bartbutenaers/node-red/tree/dev) of Node-RED, with an implementation of this feature request. Seems all to be working fine, even for existing flows. Everything is ready (incl. test flows) for a pull request. I have also added the Bearer Authentication.

But now I have been loosing quite some time installing **grunt** , but it keeps giving me errors. Don't know how that grunt thing works. Contributing to the Node-RED core is not easy for normal hobbyists like myself ...

My time is up for today. Will try to get grunt running this evening.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [18 February 2019 10:10 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/16 "2019-02-18T10:10:01Z")

</div>

@BartButenaers if you have code that is working, stick the PR. You can tussle with Grunt in parallel.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [18 February 2019 10:57 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/17 "2019-02-18T10:57:59Z")

</div>

( I usually have to install grunt-cli as a global.... `sudo npm i -g grunt-cli` so that the grunt command is available everywhere... )

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 February 2019 19:43 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/18 "2019-02-18T19:43:12Z")

</div>

> [@dceejay](#):
>
> I usually have to install grunt-cli as a global

Hey Dave (@dceejay),  
I had also installed it global (for same reason), but still get a lot of errors. For example:

_Error: Cannot find module 'should'_  
\_ at Function.Module._resolveFilename (internal/modules/cjs/loader.js:603:15)_  
\_ at Function.Module._load (internal/modules/cjs/loader.js:529:25)_  
\_ at Module.require (internal/modules/cjs/loader.js:657:17)\_  
...

Could you please explain a bit more which parameters I have to add to the grunt command, for a pull-request? Because I saw last night [here](https://github.com/node-red/node-red/wiki/Testing) that there are multiple options available...

> [@knolleary](#):
>
> if you have code that is working, stick the PR. You can tussle with Grunt in parallel.

Hi Nick (@knolleary),  
I have created a [pull request](https://github.com/node-red/node-red/pull/2061), but I wasn't able to run grunt on it. How stupid ...

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [18 February 2019 20:22 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/19 "2019-02-18T20:22:39Z")

</div>

usually you only need either `grunt build` if you want to build the runtime for running Node-RED... or just `grunt` - which will build it then run all the tests.

---

<div class="post-metadata">

**Author:** ![Jude.Robise](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jude.robise/32/13970_2.png) [@Jude.Robise](https://discourse.nodered.org/u/Jude.Robise)\
**Post date:** [29 April 2020 06:44 UTC](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131/20 "2020-04-29T06:44:43Z")

</div>

Dear all,

I have some camera units which has http alertStream. I can use some **API GET requests** to get those Stream. Authentication mode is **basic** and I can only use node red **Multipart decoder** to get that stream continuously. No issue.

Now I have another device which has only **Digest authentication**. Still I have the alertStream but I cannot use **Multipart decoder** node for this case because it has only **basic authentication**.

Even though Node red **http request** node has both basic and digest authentication modes, it cannot handle those Streams. Only multipart decoder could handle that stream with basic auth.

Question is How can I use multipart decoder for digest authentication mode. ?

Correct if I'm wrong at any point.  
Thanks in advance.  
-Jude

 ![4523](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/a/ba6cde3a64b75dcd029a724adca071c2b40df3fe.jpeg)

[Next page](https://discourse.nodered.org/t/digest-authentication-support-in-httprequest-node/4131.md?page=2)
