# How should I create an api using "OPTIONS" method with the "http in" node?

**URL:** <https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780>\
**Category:** General\
**Tags:** http-request\
**Created:** [4 February 2022 17:42 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780 "2022-02-04T17:42:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![zxsoft](https://avatars.discourse-cdn.com/v4/letter/z/ee59a6/32.png) [@zxsoft](https://discourse.nodered.org/u/zxsoft)\
**Post date:** [4 February 2022 17:42 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780/1 "2022-02-04T17:42:37Z")

</div>

Please note that I'm talking about the "http in" node, not the "http request" node.

I'm developing a http api using node-red, and need to be able to response to the OPTIONS method, but found that the built-in "http in" node only supports "GET,POST,PUT,DELETE,PATCH".

I googled and youtubed and searched the github issue forum, but found nothing. So PLEASE help me, or PLEASE tell me if there is an alternative way to do that, I'm so confused. Thanks a lot !!!

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [4 February 2022 22:29 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780/2 "2022-02-04T22:29:28Z")

</div>

Hi @zxsoft - welcome to the forums.

You could try the below.  
I am not sure where in the pipeline this middleware is executed, so this is a stab in the dark, so may not work.

But,  
in **settings.js** , you can opt to handle the request before it reaches the flow workspace.

```javascript
/** The following property can be used to add a custom middleware function
     * in front of all http in nodes. This allows custom authentication to be
     * applied to all http in nodes, or any other sort of common request processing.
     * It can be a single function or an array of middleware functions.
     */
    httpNodeMiddleware: function(req,res,next) {
        // do something: (check request method for OPTIONS as an example).
        // if the request is to proceed to the flow - call next()
        next();
    }

```

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [4 February 2022 22:31 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780/3 "2022-02-04T22:31:05Z")

</div>

> [@zxsoft](#):
>
> OPTIONS

@zxsoft there isn't an easy way to do that today. I've added an item on the backlog at add support for other HTTP methods in the node. - [Trello](https://trello.com/c/eNWiM5Cn)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [4 February 2022 22:35 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780/4 "2022-02-04T22:35:02Z")

</div>

@knolleary,

Just out of curiosity, where in the pipeline is this middleware called?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [4 February 2022 22:48 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780/5 "2022-02-04T22:48:16Z")

</div>

It get inserted before a request reaches its handler - but it needs to have a handler in place.

So there isn't any way of using it to add OPTIONS support to the node.

> <https://github.com/node-red/node-red/blob/master/packages/node_modules/@node-red/nodes/core/network/21-httpin.js#L255>

---

<div class="post-metadata">

**Author:** ![zxsoft](https://avatars.discourse-cdn.com/v4/letter/z/ee59a6/32.png) [@zxsoft](https://discourse.nodered.org/u/zxsoft)\
**Post date:** [5 February 2022 14:56 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780/6 "2022-02-05T14:56:34Z")

</div>

Thank you SO MUCH for accepting this!

The "options" methods DOES MATTER becase the Browsers like Chrome will automatic use "options" method to check api http header "Access-Control-Allow-Origin" before doing a "post" method for security in my case(the browser calls it "preflight"), and it doesn't allow the "\*" value for security.

BUT, unfortunately, there is NO WAY I know for node-red to avoid this, EVEN when I edited "settings.js" and modified the "httpNodeCors.origin"! The setting did take effect when http method was in "get,post,put,delete,patch", but when the method is "options", the "Access-Control-Allow-Origin" header of http response is always "\*" ! So the only way I can solve this now is to deploy an nginx server before node-red api to edit the http header when $request\_method is "options".

I wrote this much just because I really think this important, thank you very much,a lot much if you can really agree with that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [6 April 2022 14:56 UTC](https://discourse.nodered.org/t/how-should-i-create-an-api-using-options-method-with-the-http-in-node/57780/7 "2022-04-06T14:56:52Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
