# How to Forcefully Close WebSocket on Session Timeout in Node-RED Dashboard 2?

**URL:** <https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681>\
**Category:** Dashboard\
**Tags:** dashboard-2\
**Created:** [4 December 2024 11:17 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681 "2024-12-04T11:17:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nandhini-Subramaniya](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/nandhini-subramaniya/32/92882_2.png) [@Nandhini-Subramaniya](https://discourse.nodered.org/u/Nandhini-Subramaniya)\
**Post date:** [4 December 2024 11:17 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681/1 "2024-12-04T11:17:42Z")

</div>

I am working on a project using Node-RED 2.x Dashboard and have the following requirements:

Understand where and how the WebSocket connection is established in the Node-RED Dashboard 2.

Determine how to disconnect or close the WebSocket connection programmatically when a user session times out.

- On session timeout:
- 

```
    Send a message to the UI.

```

- 

```
    Display a dialog informing the user about the timeout.

```

- 

```
    Redirect the user to the login page after acknowledging the dialog.

```

Could someone guide me on how to achieve these tasks? Specifically:

Where is the WebSocket created in the Node-RED Dashboard 2 codebase?  
How can I forcefully close the WebSocket when a session times out?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [4 December 2024 11:57 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681/2 "2024-12-04T11:57:16Z")

</div>

Do you have a way of knowing when an individual session times out? If you do, is that server side or client side?

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [4 December 2024 12:52 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681/3 "2024-12-04T12:52:32Z")

</div>

I assume you want this on the client side, as you will have multiple sessions.  
You need to determine inactivity based on you application requirements, for example listen to events such as:

```auto
window.onload = resetTimer;
document.onmousemove = resetTimer;
document.onkeypress = resetTimer;
document.onscroll = resetTimer;
document.onclick = resetTimer;
document.ontouchstart = resetTimer;

```

Once the timer expires, you can open a warning pop-up, and then set `window.location.href` to move to a login page. If you want to force the socket close, then the login page should be on a different site (not Node-red dashboard) or just close the current page using `window.close()`

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [4 December 2024 15:10 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681/4 "2024-12-04T15:10:23Z")

</div>

> [@Nandhini-Subramaniya](#):
>
> Where is the WebSocket created in the Node-RED Dashboard 2 codebase?

The connection is setup as part of the `ui-base.js`, specifically here:

> <https://github.com/FlowFuse/node-red-dashboard/blob/e3b2791aec2602c1eae685bbbc4ea7c8742ca8df/nodes/config/ui_base.js#L186>

As for forcing a connectin to close, we don't have anything built in for that currently, but to echo @Colin's question, how are you determining that a session has timed out?

---

<div class="post-metadata">

**Author:** ![Nandhini-Subramaniya](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/nandhini-subramaniya/32/92882_2.png) [@Nandhini-Subramaniya](https://discourse.nodered.org/u/Nandhini-Subramaniya)\
**Post date:** [5 December 2024 03:55 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681/5 "2024-12-05T03:55:36Z")

</div>

I'm working with the `ui_base.js` file in Node-RED and handling socket connections using the `onConnection` method. Here's my code snippet:

```auto
function onConnection(socket) {
            // Record mapping from connection to the ui-base node
            socket._baseId = node.id;
        
            // Handle cookies
            let cookies = socket.request.headers.cookie;
            console.log(" **************** cookies in socket: ", cookies);
        
            if (!cookies) {
                console.log("@@@@@@@@@@@@@@@@@@@No cookies found, closing socket connection.");
             // handleDisconnect(socket, 'no cookies found');
                socket.disconnect(true); // Close the WebSocket connection if cookies are missing

                return;
            }
            

             // node.connections[socket.id] = socket // store the connection for later use
                    uiShared.connections[socket.id] = socket // store the connection for later use
        
                    emitConfig(socket)
        
                    // clean up then re-register listeners
                    // cleanupEventHandlers(socket)
                    // setup connections, and fire any 'on('connection')' events
                    setupEventHandlers(socket, true)
        }

```

Currently, when there are no cookies, I disconnect the WebSocket connection using `socket.disconnect(true);`. However, I would like to redirect the user to my login portal, located at `http://localhost:1880/api/login`.

How can I achieve this redirection from the server-side? Is there a standard way to inform the client to perform the redirection when the connection is closed or through some event?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [5 December 2024 09:24 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681/6 "2024-12-05T09:24:11Z")

</div>

Do you really want to disconnect the [socket.io](http://socket.io) connection? Doing so means that the client can't get ANY comms without reloading the page. Indeed, I think that the client will probably try to auto-reconnect.

Instead, wouldn't it be better to control comms from Node-RED? If the client's session is closed, prevent comms getting to the client - except for something like a redirect instruction to take it to the login page - or even to simply display a login overlay on the current page which would be better since Dashboard is a single-page app. Similarly block all comms from the client except the login data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [5 March 2025 09:25 UTC](https://discourse.nodered.org/t/how-to-forcefully-close-websocket-on-session-timeout-in-node-red-dashboard-2/93681/7 "2025-03-05T09:25:07Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
