# How to protect the dashboard with credentials for more than 1 users?

**URL:** <https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999>\
**Category:** Dashboard\
**Created:** [28 January 2024 18:28 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999 "2024-01-28T18:28:22Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 18:28 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/1 "2024-01-28T18:28:22Z")

</div>

Hi everybody.

At first: I'm new on this site. Is there a forum in german language available?

My inquiry:  
I'm trying to set a username/password protection for my dashboard.  
This already works for my flow-editor, but the dashboard is still without protection.

I tried to set up the ~↓/.node-red/settings.js with these changes:

```auto
    httpNodeMiddleware: function(req,res,next) {

        var basicAuth = require('basic-auth');
        var user = basicAuth(req);

        if (!user || !user.name || !user.pass) {
            res.set('WWW-Authenticate', 'Basic realm=Authorization Required');
            return res.sendStatus(401);
        }

        var users = [
            { username: 'user1', password: 'passwd1' },
            { username: 'user2', password: 'passwd2' },
            { username: 'user3', password: 'passwd3' },
            { username: 'user4', password: 'passwd4' },
        ];

        var isValid = users.some(function(u) {
            return u.username === user.name && u.password === user.pass;
        });

        if (isValid) {
            return next();
        } else {
            res.set('WWW-Authenticate', 'Basic realm=Authorization Required');
            return res.sendStatus(401);
        }
    },

```

But my site [http://xx.xxx.xx.xxx:1880/ui](http://xx.xxx.xx.xxx:1880/ui) ist still adressable without a login prompt.  
(Link removed)

What did I do wrong?

PS: `httpNodeAuth` is already disabled.

```auto
    /** To password protect the node-defined HTTP endpoints (httpNodeRoot),
     * including node-red-dashboard, or the static content (httpStatic), the
     * following properties can be used.
     * The `pass` field is a bcrypt hash of the password.
     * See http://nodered.org/docs/security.html#generating-the-password-hash
     */
    //httpNodeAuth: {user:"user",pass:"$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN."},
    //httpStaticAuth: {user:"user",pass:"$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN."},

/ *******************************************************************************

```

I'm running NodeRED on a RPi4.  
NodeRED version: v3.1.3  
Node.JS version: v18.19.0

Thx for your help.

Best regards.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [28 January 2024 19:00 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/2 "2024-01-28T19:00:53Z")

</div>

**REMOVE YOUR LINK!**

The internet will be having fun with your home/devices right now!

**REMOVE YOUR LINK!**

Do not post your IP address on the forums - with a Node RED instance behind it

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:03 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/3 "2024-01-28T19:03:36Z")

</div>

Thx for your tip.  
All functions are actual deactivated until I will have solved the problem.... of course! 😉

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:07 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/4 "2024-01-28T19:07:12Z")

</div>

(Link removed)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [28 January 2024 19:08 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/5 "2024-01-28T19:08:07Z")

</div>

I'm not a pro with how dashboard works - plenty around who are.

---

<div class="post-metadata">

**Author:** ![E1cid](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/e1cid/32/77971_2.png) [@E1cid](https://discourse.nodered.org/u/E1cid)\
**Post date:** [28 January 2024 19:20 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/6 "2024-01-28T19:20:58Z")

</div>

Your node-red is open to the internet and is accessible via http.  
You really need to secure this page using https and insure you password is very strong. It will not take long to sniff your password if you remain with no TLS encryption. please sort this issue as soon as possible.

I advise that you disconnect your node-red from the internet until you have fully secured with encrypted https the connection [Safely accessing Node-RED over the Internet](https://discourse.nodered.org/t/safely-accessing-node-red-over-the-internet/45024)

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:21 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/7 "2024-01-28T19:21:00Z")

</div>

Thx for your effort.  
I'm no expecting a solution within 1 hour 😉

I already had a long discussion with ChatGPT - after all ideas didn't work he/she/it said: please ask the community. So we see - finally, we need human to fix some problems 😉

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [28 January 2024 19:21 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/8 "2024-01-28T19:21:17Z")

</div>

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/2/32c89c9f48ce86d085cade153f4700fec00927f6.png)

Sei nett zu Dir - und lass' das sein.  
Es gibt hier einige Beiträge zum Thema "My Node-RED was hacked!" Lies' sie ganz genau durch & dann ... lass' das sein!  
Es gibt auch einige Beiträge zu "How to secure my Node-RED." Ebenfalls durchlesen & umsetzen; ansonsten ... lass' das sein!

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:26 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/9 "2024-01-28T19:26:16Z")

</div>

@E1cid Also thanks to you.

How I told before - everything is disabled. I am still in the first phase of configuring and learning. Before my system will go online in a final configuration, I will set up a new debian on that device.

So I would like to solve the basic issues first - like this of this topic here.

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:28 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/10 "2024-01-28T19:28:47Z")

</div>

Oh schön - auf deutsch:

Hallo @ralphwetzel.

Hast Du eine Idee, wo mein Fehler in der settings.js liegt?

VG

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:37 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/11 "2024-01-28T19:37:15Z")

</div>

@ Ralph.

And big THX for your screenshot in this thread... after I have already removed the link from my post!

Best regards

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [28 January 2024 19:37 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/12 "2024-01-28T19:37:23Z")

</div>

> [@SheldonC](#):
>
> Hast Du eine Idee, wo mein Fehler in der settings.js liegt?

Denke schon:

> [@SheldonC](#):
>
> PS: `httpNodeAuth` is already disabled.

Sieht so aus, als ob Du `httpNodeAuth` definieren solltest.  
Und noch einmal:

> [@SheldonC](#):
>
> everything is disabled

Ich bin überzeugt, Du bist überzeugt, dass das so ist. 😉  
Jedoch kann jeder node einen Endpoint definieren & über einen solchen Endpoint kann alles mögliche manipuliert werden.  
Daher ein weiteres & ein letztes Mal: Lass das sein. **You have been warned.** 👍

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [28 January 2024 19:39 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/13 "2024-01-28T19:39:43Z")

</div>

Beschwer' Dich nicht; der Link ist weiterhin sichtbar.

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:40 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/14 "2024-01-28T19:40:52Z")

</div>

Ja... mit `httpNodeAuth` funktioniert das tatsächlich auch - aber dann nur für einen User. Wenn ich mehrere Einträge für `httpNodeAuth` setze, funktioniert gar kein Login mehr.

Da hieß es dann an anderer Stelle: NodeAuth wieder disablen und stattdessen bei httpNodeMiddleware setzen.

Wenn ich jetzt einen einzigen User zusätzlich bei NodeAuth setze, dann werden alle Einträge unter NodeMiddleware ignoriert und es kann wieder nur der eine User unter NodeAuth rein.

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:41 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/15 "2024-01-28T19:41:55Z")

</div>

> [@ralphwetzel](#):
>
> Beschwer' Dich nicht; der Link ist weiterhin sichtbar.

Tu ich doch gar nicht. War nur ein Hinweis.  
Aber nochmal: danke für die vielen Tipps.

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [28 January 2024 19:49 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/16 "2024-01-28T19:49:41Z")

</div>

> [@SheldonC](#):
>
> httpNodeMiddleware

Wenn ich das richtig interpretiere...

```auto
    /** If you installed the optional node-red-dashboard you can set it's path
     * relative to httpNodeRoot
     * Other optional properties include
     * readOnly:{boolean},
     * middleware:{function or array}, (req,res,next) - http middleware
     * ioMiddleware:{function or array}, (socket,next) - socket.io middleware
     */
    //ui: { path: "ui" },

```

dann läuft das für `node-red-dashboard` über `ui.middleware` ... und nicht `httpXXMiddleware`.  
Also:

```auto
ui: {
    path: "ui",
    middleware: function(req, res, next) { ... } 
}

```

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 19:59 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/17 "2024-01-28T19:59:55Z")

</div>

Jetzt lädt die Seiute gerade gar nicht mehr.  
Ich check jetzt nochmal alle Klammern ab; hab da vielleicht zu hastig gewerkelt.

Also der gesamte Code aus meinem ersten Post dann eingerückt in ui: {}, korrekt?  
und das httpNodeMiddleware ersetzen durch middleware, ja?

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [28 January 2024 20:03 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/18 "2024-01-28T20:03:37Z")

</div>

```auto
ui: {
    path: "ui",
    middleware: function(req, res, next) {
        var basicAuth = require('basic-auth');
        var user = basicAuth(req);
        ...
    } 
}

```

Nebenbei:

```auto
    var dashboardMiddleware = function(req, res, next) { next(); }

```

Dein `return next();` sieht für mich daher ... fragwürdig... aus.

---

<div class="post-metadata">

**Author:** ![SheldonC](https://avatars.discourse-cdn.com/v4/letter/s/a6a055/32.png) [@SheldonC](https://discourse.nodered.org/u/SheldonC)\
**Post date:** [28 January 2024 20:09 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/19 "2024-01-28T20:09:29Z")

</div>

Oh moment.

Wo genau bist Du jetzt? Finde den String `var dashboardMiddleware` gar nicht in meiner settings.js

So sieht der (fehlerhafte) Code aktuell aus:

```auto
    ui: {
        path: "ui",
        middleware: function(req,res,next) {

            var basicAuth = require('basic-auth');
            var user = basicAuth(req);

            if (!user || !user.name || !user.pass) {
                res.set('WWW-Authenticate', 'Basic realm=Authorization Required');
                return res.sendStatus(401);
            }

            var users = [
                { username: 'user1', password: 'foo' },
                { username: 'user2', password: 'bar' },
                { username: 'user3', password: 'test' },

            ];

            var isValid = users.some(function(u) {
                return u.username === user.name && u.password === user.pass;
            });

            if (isValid) {
                return next();
            } else {
                res.set('WWW-Authenticate', 'Basic realm=Authorization Required');
                return res.sendStatus(401);
            }
        }
    }

```

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [28 January 2024 20:13 UTC](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999/20 "2024-01-28T20:13:51Z")

</div>

`dashboardMiddleware` ist im Quellcode von `node-red-dashboard` definiert.  
Ich würde erst einmal prüfen, ob die Funktion aufgerufen wird ... und damit die weitere Fehlersuche starten:

> [@SheldonC](#):
>
> ```auto
> var user = basicAuth(req);
> 
> console.log(user); // <-- einfügen & dann Fehler eingrenzen.
> 
> if (!user || !user.name || !user.pass) {
> 
> ```

[Next page](https://discourse.nodered.org/t/how-to-protect-the-dashboard-with-credentials-for-more-than-1-users/84999.md?page=2)
