# Help - Middleware for httpin node Auth

**URL:** https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296
**Category:** General
**Tags:** security
**Created:** [3 August 2023 14:25 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296 "2023-08-03T14:25:51Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Anders](https://avatars.discourse-cdn.com/v4/letter/a/59ef9b/32.png) [@Anders](https://discourse.nodered.org/u/Anders)
#### Post date: [3 August 2023 14:25 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296/1 "2023-08-03T14:25:51Z")

</div>

Hello all, first post.

I'm six months in to using Node Red (what a great package). I don't have a JS background, skill set is IT / networking. I've hit my first stumbling block and wondered if anyone can shed some light.

I need to have admin interface and dashboard secured, while allowing unsecured access to two httpin nodes on two paths. Data will be transmitted two these nodes over SSL, I've set up a self signed cert for this.

From research so far, I need to write some middleware to handle the Auth? I've commented out the sections below in settings.js, I read those paths / routes are higher priority and conflict if enabled:

adminAuth  
httpNodeAuth  
httpStaticAuth

Middleware code in settings.js:

```auto
httpAdminMiddleware: function (req, res, next) {
    const basicAuth = require('express').basicAuth({
      users: {
        'admin': 'hashxxxxxxxxx',
        'dashboard': 'hashxxxxxxxxx',
      },
      challenge: true,
    });

    // Check if the request is for the admin interface or dashboard
    if (req.url.startsWith('/admin') || req.url.startsWith('/ui')) {
      // Use basicAuth middleware for admin interface and dashboard authentication
      return basicAuth(req, res, next);
    } else if (req.url.startsWith('/unsecure-path1')) {
      // No authentication needed for the first unsecured path
      return next();
    } else if (req.url.startsWith('/unsecure-path2')) {
      // No authentication needed for the second unsecured path
      return next();
    }
    return next();
  },

```

When I save and reboot and refresh the admin interface, I get the below error. I don't know if it's an error in my code or missing express module. Node v20.5.0, npm v9.8.0 installed. Do I have to install express? I don't know why but I thought it was part of Node Red.

If I have to install it, where does it need to go?

Error:

Error: Cannot find module 'express'  
Require stack:  
/home/username/.node-red/settings.js  
/usr/lib/node\_modules/node-red/red.js  
at Module.\_resolveFilename (node:internal/modules/cjs/loader:1048:15)  
at Hook.\_require.Module.require (/usr/lib/node\_modules/pm2/node\_modules/require-in-the-middle/index.js:81:25)  
at require (node:internal/modules/helpers:119:18)  
at httpAdminMiddleware (/home/username/.node-red/settings.js:194:23)  
at Layer.handle [as handle\_request] (/usr/lib/node\_modules/node-red/node\_modules/express/lib/router/layer.js:95:5)  
at trim\_prefix (/usr/lib/node\_modules/node-red/node\_modules/express/lib/router/index.js:328:13)  
at /usr/lib/node\_modules/node-red/node\_modules/express/lib/router/index.js:286:9  
at Function.process\_params (/usr/lib/node\_modules/node-red/node\_modules/express/lib/router/index.js:346:12)  
at next (/usr/lib/node\_modules/node-red/node\_modules/express/lib/router/index.js:280:10)  
at cors (/usr/lib/node\_modules/node-red/node\_modules/cors/lib/index.js:188:7)

Many thanks in advance.

Anders

---

<div class="post-metadata">

### Author: ![Shan](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Shan](https://discourse.nodered.org/u/Shan)
#### Post date: [3 August 2023 14:30 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296/2 "2023-08-03T14:30:12Z")

</div>

Have you tried installing `express` using `npm install -g express` and trying things out again?

If you have installed `express` and still getting the error try setting the following in the `settings.js` file:

```auto
functionGlobalContext: {
        express:require("express")
    },

```

and then try it out.

---

<div class="post-metadata">

### Author: ![Anders](https://avatars.discourse-cdn.com/v4/letter/a/59ef9b/32.png) [@Anders](https://discourse.nodered.org/u/Anders)
#### Post date: [3 August 2023 14:40 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296/3 "2023-08-03T14:40:26Z")

</div>

Shan, thanks for the quick reply. I haven't installed express, the only modules I installed previously were all done via the manage pallete menu on the GUI.

I'll give that a go, do I have to install express in a specific location or the standard path the installer uses?

Cheers

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [3 August 2023 14:58 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296/4 "2023-08-03T14:58:26Z")

</div>

Packages like that would need to be installed in your userDir (normally `~/.node-red`).

Try:

```auto
cd ~/.node-red
npm install express

```

(or might be expressjs, I can never remember).

Don't use the `-g` suggested by Shan as that will install it globally and cause other issues.

---

<div class="post-metadata">

### Author: ![Anders](https://avatars.discourse-cdn.com/v4/letter/a/59ef9b/32.png) [@Anders](https://discourse.nodered.org/u/Anders)
#### Post date: [3 August 2023 15:40 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296/5 "2023-08-03T15:40:06Z")

</div>

Some progress, express error has gone and replaced with this one.

TypeError: require(...).basicAuth is not a function

I thought I'd named the module wrong, I updated to the below but the error just says Error: Cannot find module 'express-basic-auth'

```auto
 const basicAuth = require('express-basic-auth')({

```

Do I need to install this auth module too?

> **[express-basic-auth](https://www.npmjs.com/package/express-basic-auth)**
>
> Plug & play basic auth middleware for express. Latest version: 1.2.1, last published: 2 years ago. Start using express-basic-auth in your project by running \`npm i express-basic-auth\`. There are 372 other projects in the npm registry using...

Cheers

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [3 August 2023 15:52 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296/6 "2023-08-03T15:52:39Z")

</div>

> [@Anders](#):
>
> Do I need to install this auth module too?

Yes. 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [2 October 2023 15:53 UTC](https://discourse.nodered.org/t/help-middleware-for-httpin-node-auth/80296/7 "2023-10-02T15:53:26Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
