# \[EDIT\] Displays if a new Node-Red update is available online, and update it from the Dashboard

**URL:** <https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061>\
**Category:** Share Your Projects\
**Created:** [14 July 2020 14:05 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061 "2020-07-14T14:05:01Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [23 July 2020 12:19 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/21 "2020-07-23T12:19:14Z")

</div>

in `settings.js` i read this :

```auto
    // Securing Node-RED
    // -----------------
    // To password protect the Node-RED editor and admin API, the following
    // property can be used. See http://nodered.org/docs/security.html for details.
    //adminAuth: {
    // type: "credentials",
    // users: [{
    // username: "xxxxxxxxxxxxxx",
    // password: "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
    // permissions: "*"
    // }]
    //},

```

So , mine is not secure . Can you test with modification in the 'HTTP local request' node:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/0/c0a71cec8f42ea321cb64b7c6794dfa0cdb98f54.png)  
put your credentials

---

<div class="post-metadata">

**Author:** ![WhiteLion](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/whitelion/32/12266_2.png) [@WhiteLion](https://discourse.nodered.org/u/WhiteLion)\
**Post date:** [24 July 2020 14:00 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/22 "2020-07-24T14:00:53Z")

</div>

Thank you for your fast reply. Thats what I already tried but that didn´t worked:  
[pic](http://puu.sh/GauUN/e6da8a95eb.png)

EDIT: My code in the settings is not disabled but you posted the part which is the one I enabled to have a password protection. I wouldn´t like to disable the password.

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [24 July 2020 14:37 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/23 "2020-07-24T14:37:40Z")

</div>

can you say more about the hardware? Node-Red is running on which device?  
Have you tried typing this address in a browser (chrome ...) : `http://192.168.1.54:1880/settings` to access the settings from another device on the same network.  
Replace 192.168.1.54 with the IP address of your hardware where run Node-Red

---

<div class="post-metadata">

**Author:** ![WhiteLion](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/whitelion/32/12266_2.png) [@WhiteLion](https://discourse.nodered.org/u/WhiteLion)\
**Post date:** [24 July 2020 17:13 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/24 "2020-07-24T17:13:31Z")

</div>

Sure. I am running it on an Raspberry Pi 4 and I tried to access the settings from the browser of the raspberry itself. The result is the same: "Unauthorized".  
This: [pic](http://puu.sh/GaxVA/3841a1b00e.png)  
PS: setting are also included.

EDIT: I am no expert in auth-stuff but I think it s no typical basic auth used by Node Red.

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [25 July 2020 17:56 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/25 "2020-07-25T17:56:27Z")

</div>

> [@WhiteLion](#):
>
> I am no expert in auth-stuff

Same as you ! I am not an expert in security. Maybe @TotallyInformation can help us?

---

<div class="post-metadata">

**Author:** ![WhiteLion](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/whitelion/32/12266_2.png) [@WhiteLion](https://discourse.nodered.org/u/WhiteLion)\
**Post date:** [25 July 2020 18:31 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/26 "2020-07-25T18:31:09Z")

</div>

Maybe I know the file where the version is stored in I could use "file in" node to read / parse it from there.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [25 July 2020 19:49 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/27 "2020-07-25T19:49:14Z")

</div>

If you have admin auth set up, you cannot access the settings unless your current browser session is logged in. If you go to the normal Editor page in the same browser session and log in, you should then be able to see the output. Just tested that on 2 of my instances and it works.

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [26 July 2020 08:08 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/28 "2020-07-26T08:08:00Z")

</div>

Thanks Julian, If I understood correctly :

1. we connect to the NR editor with his credentials
2. we open, from the same editor, the Dashboard
3. the local "http request" can access the parameters because it is already logged by the editor.

Have you try this @WhiteLion ?

---

<div class="post-metadata">

**Author:** ![WhiteLion](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/whitelion/32/12266_2.png) [@WhiteLion](https://discourse.nodered.org/u/WhiteLion)\
**Post date:** [26 July 2020 18:08 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/29 "2020-07-26T18:08:43Z")

</div>

Even if I use the opened editor tab where I logged in and change the address from:  
"[http://192.168.0.60:1880/#flow/5662d35d.4bffec](http://192.168.0.60:1880/#flow/5662d35d.4bffec)" to "[http://192.168.0.60:1880/settings](http://192.168.0.60:1880/settings)" it will give me the "unauthorized" message.

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [26 July 2020 19:34 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/30 "2020-07-26T19:34:21Z")

</div>

> [@WhiteLion](#):
>
> EDIT: My code in the settings is not disabled but you posted the part which is the one I enabled to have a password protection. I wouldn´t like to disable the password.

Can you temporarily comment the lines about adminAuth and reboot NR. Just to confirm that you have access to the settings, without NR security ?  
Therefore, there is no reason why it should not work, as our security expert testifies 😉

> [@TotallyInformation](#):
>
> Just tested that on 2 of my instances and it works

---

<div class="post-metadata">

**Author:** ![WhiteLion](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/whitelion/32/12266_2.png) [@WhiteLion](https://discourse.nodered.org/u/WhiteLion)\
**Post date:** [29 July 2020 17:13 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/31 "2020-07-29T17:13:11Z")

</div>

I am very sorry for my late answer... real live got me 🙂  
If I disable the password in the settings like you requested it works.  
[pic](http://puu.sh/Gch23/12ea550e35.png)

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [29 July 2020 19:04 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/32 "2020-07-29T19:04:47Z")

</div>

I am happy that it works without authorization, but unfortunately I do not know what to answer you in the event that you activate the security. ☹

---

<div class="post-metadata">

**Author:** ![WhiteLion](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/whitelion/32/12266_2.png) [@WhiteLion](https://discourse.nodered.org/u/WhiteLion)\
**Post date:** [29 July 2020 19:21 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/33 "2020-07-29T19:21:10Z")

</div>

maybe there is a way to parse the version number from a file. I tested to read a file from pi/.node-red/ and it worked (no access violation). But I could not find out where/if the version number is stored there.

---

<div class="post-metadata">

**Author:** ![oywino](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/oywino/32/26457_2.png) [@oywino](https://discourse.nodered.org/u/oywino)\
**Post date:** [4 August 2020 20:16 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/35 "2020-08-04T20:16:27Z")

</div>

It is to be expected that the URL "[http://192.168.0.60:1880/settings](http://192.168.0.60:1880/settings)" will give the "unauthorized" message as long as NodeRED has been secured using `adminAuth:`  
But I was expecting the `http request` node to handle this correctly when adding:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/0/6050fabfede3d03a5bbd67037aad371bbb76e022.png)

.... or am I mistaken? Cause it certainly still returns "unauthorized"

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [5 August 2020 05:35 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/36 "2020-08-05T05:35:35Z")

</div>

I saw that the 1st http (local) request node indicates :  
`actualVersion: "v"`  
Check that there are 36 in the "substring" Function node  
`str.substring (31.36);`  
In this function I extract 5 characters from the payload from position 31 to 36

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [5 August 2020 05:36 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/37 "2020-08-05T05:36:31Z")

</div>

did you try this ? :

> [@\[EDIT\] Displays if a new Node-Red update is available online, and update it from the Dashboard](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/28):
>
> Thanks Julian, If I understood correctly : we connect to the NR editor with his credentials we open, from the same editor, the Dashboard the local "http request" can access the parameters because it is already logged by the editor. Have you try this @WhiteLion ?

---

<div class="post-metadata">

**Author:** ![oywino](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/oywino/32/26457_2.png) [@oywino](https://discourse.nodered.org/u/oywino)\
**Post date:** [5 August 2020 08:22 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/38 "2020-08-05T08:22:59Z")

</div>

@SuperNinja, sorry - but the English in this post doesn't make any sense to me at all. Can you pls "translate" ?

---

<div class="post-metadata">

**Author:** ![SuperNinja](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/superninja/32/5761_2.png) [@SuperNinja](https://discourse.nodered.org/u/SuperNinja)\
**Post date:** [5 August 2020 11:53 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/39 "2020-08-05T11:53:07Z")

</div>

When you open Node Red does it ask you for a username and password like this ?  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/a/4a33e43ab7368cb79bef7ac897b074a782c4d3ee.jpeg)

---

<div class="post-metadata">

**Author:** ![mako](https://avatars.discourse-cdn.com/v4/letter/m/ecc23a/32.png) [@mako](https://discourse.nodered.org/u/mako)\
**Post date:** [6 August 2020 06:01 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/40 "2020-08-06T06:01:14Z")

</div>

Great work 🙂

---

<div class="post-metadata">

**Author:** ![oywino](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/oywino/32/26457_2.png) [@oywino](https://discourse.nodered.org/u/oywino)\
**Post date:** [11 August 2020 10:10 UTC](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061/41 "2020-08-11T10:10:03Z")

</div>

@knolleary pointed me in the right direction. I had to use _bearer authentication_ and supply a valid access token to avoid the "unauthorised" error. Then it works.

[Previous page](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061.md?page=1)

[Next page](https://discourse.nodered.org/t/edit-displays-if-a-new-node-red-update-is-available-online-and-update-it-from-the-dashboard/30061.md?page=3)
