# How to use the node-red customer form

**URL:** <https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717>\
**Category:** General\
**Created:** [6 March 2020 13:30 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717 "2020-03-06T13:30:33Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![gbond](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gbond/32/38851_2.png) [@gbond](https://discourse.nodered.org/u/gbond)\
**Post date:** [6 March 2020 13:30 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/1 "2020-03-06T13:30:33Z")

</div>

#### Custom user authentication

Rather than hardcode users into the settings file, it is also possible to plug in custom code to authenticate users. This makes it possible to integrate with existing authentication schemes.

The following example shows how an external module can be used to provide the custom authentication code.

- Save the following in a file called `<node-red>/user-authentication.js`

I have created this file but I dont understand what I need to change or set up the actual "usernames" and passwords (Do I some how add them into this file)?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [6 March 2020 13:34 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/2 "2020-03-06T13:34:36Z")

</div>

Hi @gbond

what _exactly_ do you want to do? Why do you want to go down the route of creating a custom user-authentication plugin for your Node-RED instance?

Being able to plugin a custom auth system is usually to integrate with existing authentication mechanisms.

I want to understand _why_ you want to do this so I can help point you in the right direction.

---

<div class="post-metadata">

**Author:** ![gbond](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gbond/32/38851_2.png) [@gbond](https://discourse.nodered.org/u/gbond)\
**Post date:** [6 March 2020 14:19 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/3 "2020-03-06T14:19:21Z")

</div>

I have mutiple pi's(node-red) and thought it was away to have one file setup that can be copied to my multiple pi rather than copying the settings.js which might be different on the other pi

it also mentions about the hash method is a bit unsecure and is being phased out?!!

---

<div class="post-metadata">

**Author:** ![gbond](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gbond/32/38851_2.png) [@gbond](https://discourse.nodered.org/u/gbond)\
**Post date:** [8 March 2020 16:41 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/4 "2020-03-08T16:41:53Z")

</div>

ok sorry to get back to this

but now i have my new setup and working node-red can I set the security up as a seperate file that I can link into the settings.js on several different setups ,or am I just best to use this #hash password method that mentions has a vanarability?

---

<div class="post-metadata">

**Author:** ![gbond](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gbond/32/38851_2.png) [@gbond](https://discourse.nodered.org/u/gbond)\
**Post date:** [10 March 2020 13:17 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/5 "2020-03-10T13:17:33Z")

</div>

is anyone able to advise on this or am I just misunderstanding again!!!!  
(I take it these updates r being seen and there just hasnt been any up date on it 1 way or the other?)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [12 March 2020 22:46 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/6 "2020-03-12T22:46:54Z")

</div>

So, to clarify, your goal is to have a consistent username/password for logging into Node-RED across multiple devices? But you don't want to copy the settings file as some devices will have customised settings file.

You can achieve that by:

1. Create a file called `.node-red/user-authentication.js`
2. In that file paste the following:

```auto
module.exports = {
    type: "credentials",
    users: [
        {
            username: "admin",
            password: "$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN.",
            permissions: "*"
        }
    ]
}

```

You can change `username` to whatever you want the username to be. The password is a hashed version of the actual password you want to use. To generate the hash you can follow the instructions on [this page](https://nodered.org/docs/user-guide/runtime/securing-node-red) under the 'Generating the password hash' section.

1. In each of your devices' settings files, set the `adminAuth` property to:

```auto
adminAuth: require("./user-authentication.js")

```

You can then copy the `user-authentication.js` file to all your devices.

* * *

I would suggest you consider how much of a saving this will make. If the goal is to have a consistent login on all your devices, then you could just set adminAuth normally on each of your devices and copy the password hash - I doubt you change the password very often, so having to manually copy the new hash to each device isn't much more than copy the `user-auth...js` file around.

---

<div class="post-metadata">

**Author:** ![gbond](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gbond/32/38851_2.png) [@gbond](https://discourse.nodered.org/u/gbond)\
**Post date:** [12 March 2020 23:04 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/7 "2020-03-12T23:04:25Z")

</div>

adminAuth: {  
type: "credentials",  
users: [{  
username: "admin",  
password: "\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*",  
permissions: "\*"}]  
},

```
// To password protect the node-defined HTTP endpoints (httpNodeRoot), or
// the static content (httpStatic), the following properties can be used.
// The pass field is a bcrypt hash of the password.
// See http://nodered.org/docs/security.html#generating-the-password-hash

```

httpNodeAuth: {user:"user",pass:"\***"},  
//httpStaticAuth: {user:"user",pass:"**"},

```
// The following property can be used to enable HTTPS#
// See http:

```

can it do the httpNodeAuth and is it more secure as it rean as the #hash thing could be compermised  
or am I miss understanding again?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [12 March 2020 23:09 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/8 "2020-03-12T23:09:20Z")

</div>

You can follow the same approach for any property in the settings file.

If you follow the docs on generating the password hash - as it links to in the settings file - then you will be fine.

The comment you have read that has alarmed you is saying that `httpNodeAuth` also supports using the less secure `md5` hashing algorithm for historical reasons. But if you do what the docs says then you won't be using md5 and you have nothing to worry about.

---

<div class="post-metadata">

**Author:** ![gbond](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gbond/32/38851_2.png) [@gbond](https://discourse.nodered.org/u/gbond)\
**Post date:** [12 March 2020 23:13 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/9 "2020-03-12T23:13:36Z")

</div>

ok just to be clear  
ether the saperate file or the setting.js file is safe to do?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [12 March 2020 23:14 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/10 "2020-03-12T23:14:39Z")

</div>

I'm not sure what you mean by 'safe' - depends what you are trying to protect yourself from.

Personally I'd keep it simple and keep it in your settings file.

---

<div class="post-metadata">

**Author:** ![gbond](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gbond/32/38851_2.png) [@gbond](https://discourse.nodered.org/u/gbond)\
**Post date:** [12 March 2020 23:15 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/11 "2020-03-12T23:15:43Z")

</div>

great I will leave it as it is thank you for clarifing

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [11 May 2020 23:18 UTC](https://discourse.nodered.org/t/how-to-use-the-node-red-customer-form/22717/12 "2020-05-11T23:18:50Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
