# File read write security

**URL:** https://discourse.nodered.org/t/file-read-write-security/96252
**Category:** General
**Tags:** docker
**Created:** [25 March 2025 16:15 UTC](https://discourse.nodered.org/t/file-read-write-security/96252 "2025-03-25T16:15:14Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ebimohi](https://avatars.discourse-cdn.com/v4/letter/e/9fc29f/32.png) [@ebimohi](https://discourse.nodered.org/u/ebimohi)
#### Post date: [25 March 2025 16:15 UTC](https://discourse.nodered.org/t/file-read-write-security/96252/1 "2025-03-25T16:15:14Z")

</div>

Hi,  
I use Node-RED in a project where users can create flows and export data from the server to other systems through a specific endpoint (I have created a custom node for this). If I allow the **"Write File"** and **"Read File"** nodes, it seems that someone could potentially gain access to the `/data` folder. This folder contains important files, such as the `settings.js` file, which I do not want users to read.

How can I secure or restrict file read/write operations in a Docker environment so that users can only access a **temporary folder** during runtime without being able to read or write to any other files or directories?

thank you!

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/a/4abf3858de491c3a0a70698934ad102c6f4b188c.png)

---

<div class="post-metadata">

### Author: ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)
#### Post date: [25 March 2025 17:17 UTC](https://discourse.nodered.org/t/file-read-write-security/96252/2 "2025-03-25T17:17:34Z")

</div>

You would need to ship modified versions of the file nodes.

You can do this by excluding the `10-file.js` in your settings.js file and then installing your version like any other node.

---

<div class="post-metadata">

### Author: ![ebimohi](https://avatars.discourse-cdn.com/v4/letter/e/9fc29f/32.png) [@ebimohi](https://discourse.nodered.org/u/ebimohi)
#### Post date: [25 March 2025 21:26 UTC](https://discourse.nodered.org/t/file-read-write-security/96252/3 "2025-03-25T21:26:31Z")

</div>

Thanks for your answer!  
I understand that I can disable the "Write File" and "Read File" nodes as you suggested. However, my goal is not to completely disable them but rather to **restrict their access** so that they can only read from and write to a specific folder (e.g., `/data/tmp`) while preventing access to other directories, such as `/data/settings.js`.

Since I am running Node-RED in a Docker environment, I am looking for a way to enforce this restriction; either through container-level configurations (e.g., volume mounts, permissions) or by modifying the behavior of the file nodes.

---

<div class="post-metadata">

### Author: ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)
#### Post date: [25 March 2025 21:26 UTC](https://discourse.nodered.org/t/file-read-write-security/96252/4 "2025-03-25T21:26:38Z")

</div>

Also don't forget the Exec node which can do anything that the node red user has permissions to do.

---

<div class="post-metadata">

### Author: ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)
#### Post date: [25 March 2025 21:47 UTC](https://discourse.nodered.org/t/file-read-write-security/96252/5 "2025-03-25T21:47:57Z")

</div>

Yes, I understood your requirement and I'm saying there is no way to do what you want with the standard nodes and still allow saving of flows to `/data` or installing new nodes (which go in `/data/node_modules`).

You can't just bind mount a file to `/data/flows.json` because Node-RED writes temp copies first, then moves them over the top to help prevent corruption if a crash happens mid write.

The only way is to create a copy of the existing file nodes and modify them to only accept path prefixes you want, because out of the box the file nodes don't support a "Allow list" of paths.

Also worth pointing out that if the user can install arbitrary nodes or use the function node to load arbitrary modules, they can do pretty much anything at all.

The other option is to build a custom Node-RED launcher (embedding) that loads the settings.js from somewhere else.

A better question is what is in the `settings.js` file you don't want the users to see? Because if you move to a different storage module and a auth plugin it then you should be able to get the point where there are no useful secrets in the `settings.js` file so it doesn't matter if they see it. This is basically the approach we've taken with FlowFuse.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [23 June 2025 21:48 UTC](https://discourse.nodered.org/t/file-read-write-security/96252/6 "2025-06-23T21:48:13Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
