# Encrypted credentials show in clear text in flows.json

**URL:** <https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525>\
**Category:** Developing Nodes\
**Tags:** security\
**Created:** [29 August 2024 08:19 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525 "2024-08-29T08:19:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [29 August 2024 08:19 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/1 "2024-08-29T08:19:08Z")

</div>

In have set an encryption key in `settings.js`, and my credentials are being encrypted properly into `flows_cred.json`. However, I can still see the password value in clear text in the `flows.json` file. Only after some time it is converted to an obfuscated, "` __PWD__ `" format.  
Is there a reason for this (temporary) security breach?  
(I am not using 'Projects' mode here)

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [29 August 2024 11:09 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/2 "2024-08-29T11:09:33Z")

</div>

There is something I don't understand: if the property is a password how can it be defined in the flows file?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [29 August 2024 13:21 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/3 "2024-08-29T13:21:24Z")

</div>

> [@omrid](#):
>
> can still see the password value in clear text in the `flows.json` file. Only after some time it is converted to an obfuscated, "` __PWD__ `" format.

Exactly which credentials are you talking about? Can you post a simple flow showing the problem and explain what we have to do to see the password unencrypted?

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [29 August 2024 14:56 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/4 "2024-08-29T14:56:49Z")

</div>

Plain text credentials are never written to the `flows.json` on disk and they are never returned to the browser from the backend, they will always be replaced by ` __PWD__ `.

If you enter a new credential into a node, it will be in memory in the browser until that change is deployed (because it has to be somewhere until it's sent to the backend). But at the point it is deployed it should be updated with the placeholder.

As Colin asked, if you can provide more details of exactly where you are seeing this and what nodes you are seeing it with then we can investigate if the above description does not match what you are seeing.

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [30 August 2024 16:29 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/5 "2024-08-30T16:29:09Z")

</div>

Thank you for your replies. Here is the walkthrough:  
I Developed a custom node called " **FV\_Credentials**", which includes a config node which stores various connection parameters, some of which are passwords. I defined these passwords as "Credentials" in the HTML & JS files and they are saved & retrieved properly.

But watch the sequence below:

1. I open a new, clean implementation. Both `flows.json` and` flows_cred.json` files are empty:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/6/86732d19863e68566699b786d0c81f9aa0a98d9f.png)  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/6/c60b56256df960fa7363394685cd30b3e457b6bb.png)
2. I now drag the node to the empty canvas, open it, add a new config node, and enter `User name=Omri, password=1234` (the password's parameter name is `fv_b_Password`)  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/f/5f37d3c43b982560c242af0e6af0eafd005b2661.png).
3. Now I close the node and **DEPLOY**
4. I reload the cred file - it has been encrypted & populated properly.  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/2/6/268b1d2c9e1ab03f361c9d03522ceacd0676eac9.png)
5. However, when I reload the flows file, I can clearly see the password value ("1234")  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/2/8/2809446f2b40c84f74db573971c48524554b2c21.png)
6. once I start playing with the flow - add nodes, run flows etc., the password value is changed to ` __PWD__ ` as it should

Am I doing something wrong? Below are the relevant node code segments where I, specify the credentials.  
HTML:

```auto
    RED.nodes.registerType('FV_Set-Credentials-config',{
        category: 'config',
		credentials: {
			fv_b_Password: {type:"password"},
			fv_o_Password: {type:"password"},
			fv_o_ClientSecret:	{type:"password"}
		},
        defaults: {
            name: {value:""},
            fvHost: {value:"http://"},
            fvAuthMode: {value:"basic"},

			fv_b_User: {value:""},
            fv_b_Password: {value:""},
            ...

```

```auto
    ...
	<div class="form-row">
        <label for="node-config-input-fv_b_Password"><i class="fa fa-tag"></i> Password</label>
        <input type="password" id="node-config-input-fv_b_Password">
    </div>
    ...

```

JS:

```auto
    ...
	RED.nodes.registerType("FV_Set-Credentials-config",FV_SetCredentialsConfigNode, {
		credentials:
		{
			fv_b_Password: {type:"password"},
			fv_o_Password: {type:"password"},
			fv_o_ClientSecret:	{type:"password"}
		}
	});

```

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [30 August 2024 17:07 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/6 "2024-08-30T17:07:29Z")

</div>

Remove all properties you have declared in the `credentials` object from the `defaults` object. (Don't put the properties in both)

Also, since you are developing a node, please use the #Developing Nodes category (that way we know you are developing a node and not just asking a general question about using node-red)

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [30 August 2024 22:56 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/7 "2024-08-30T22:56:09Z")

</div>

Thanks, Steve! This makes sense and indeed solved the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [13 September 2024 22:56 UTC](https://discourse.nodered.org/t/encrypted-credentials-show-in-clear-text-in-flows-json/90525/8 "2024-09-13T22:56:46Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
