# Http-in node and templated user and password for basic auth (proposal)

**URL:** <https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755>\
**Category:** Feature Requests\
**Created:** [28 July 2022 15:15 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755 "2022-07-28T15:15:04Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![3dimensional](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/3dimensional/32/64992_2.png) [@3dimensional](https://discourse.nodered.org/u/3dimensional)\
**Post date:** [28 July 2022 15:15 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/1 "2022-07-28T15:15:04Z")

</div>

Hi everybody,

I am currently working on an integration project where I connect an OMS (Order Management System) of an ecommerce platform to an ERP. Depending on the context, I have outsourced process flows to separate flows. Usually in such projects you have at least one integration and one production environment, and possibly a third test environment.

In my case, the integration is based on REST APIs on both sides, which means that I use several http-request nodes across the flows, both of which require Basic-Auth for both systems. Currently, I have to determine the hash myself for each process via an upstream function node and set it "manually" via header in order to achieve central management of credentials.

For a central and simplified administration of the credentials when copying or setting up a new instance, the use of the mustache notation for the username and password field would be advantageous from my point of view. Ideally via the global context for providing the credentials. What is your opinion on this? I haven't been with NodeRED long enough to have penetrated the abstract context. Is this pro or contra design pattern http request node? If the idea resonates, I would do the integration and submit a PR.

Greetings

Stefan

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [28 July 2022 15:36 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/2 "2022-07-28T15:36:04Z")

</div>

> [@3dimensional](#):
>
> mustache notation for the username and password field

In case you were not aware, you can already use env vars for these...

> Setting a node property
> 
> Any node property can be set with an environment variable by setting its value to a string of the form `${ENV_VAR}`. When the runtime loads the flows, it will substitute the value of that environment variable before passing it to the node.

[https://nodered.org/docs/user-guide/environment-variables](https://nodered.org/docs/user-guide/environment-variables)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [28 July 2022 15:48 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/3 "2022-07-28T15:48:23Z")

</div>

> [@3dimensional](#):
>
> Basic-Auth

For an ERP? Not in any organisation I've ever worked for or ever would. 🙂

---

<div class="post-metadata">

**Author:** ![3dimensional](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/3dimensional/32/64992_2.png) [@3dimensional](https://discourse.nodered.org/u/3dimensional)\
**Post date:** [28 July 2022 18:12 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/4 "2022-07-28T18:12:25Z")

</div>

Hi, Basic Auth - don't ask about this 🙃 🤷. Hopefully we can add a firewall rule for ip. KR

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [28 July 2022 18:15 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/5 "2022-07-28T18:15:10Z")

</div>

OK, well hopefully you don't work in a certified environment like nuclear, health or finance. You would certainly fail the security audits.

---

<div class="post-metadata">

**Author:** ![3dimensional](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/3dimensional/32/64992_2.png) [@3dimensional](https://discourse.nodered.org/u/3dimensional)\
**Post date:** [28 July 2022 18:16 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/6 "2022-07-28T18:16:30Z")

</div>

> [@Steve-Mcl](#):
>
> In case you were not aware, you can already use env vars for these...

Hi Steve, thanks for that input. But how can i use them in in the password and username field of http-request node? Need smth. like that:

 ![Bildschirmfoto 2022-07-28 um 20.16.00](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/7/e7ade069355d3e05f63da5fd673843787ebb8374.png)

KR

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [28 July 2022 18:18 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/7 "2022-07-28T18:18:19Z")

</div>

As `${env_vars}` NOT `{{{mustache}}}`

> [@Steve-Mcl](#):
>
> In case you were not aware, you can already use env vars for these...
> 
> > Setting a node property
> > 
> > Any node property can be set with an environment variable by setting its value to a string of the form `${ENV_VAR}`. When the runtime loads the flows, it will substitute the value of that environment variable before passing it to the node.

---

<div class="post-metadata">

**Author:** ![3dimensional](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/3dimensional/32/64992_2.png) [@3dimensional](https://discourse.nodered.org/u/3dimensional)\
**Post date:** [28 July 2022 18:18 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/8 "2022-07-28T18:18:29Z")

</div>

> [@TotallyInformation](#):
>
> OK, well hopefully you don't work in a certified environment like nuclear, health or finance. You would certainly fail the security audits.

Only ecommerce. ;).

---

<div class="post-metadata">

**Author:** ![3dimensional](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/3dimensional/32/64992_2.png) [@3dimensional](https://discourse.nodered.org/u/3dimensional)\
**Post date:** [28 July 2022 18:38 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/9 "2022-07-28T18:38:20Z")

</div>

> [@Steve-Mcl](#):
>
> As `${env_vars}` NOT `{{{mustache}}}`

Hi, ok, got it. But this will only work if the password and username are the same for all http-request nodes right? As soon as I have different credentials for the http-request nodes, I can no longer use the ENV. Do I understand this correctly? Thanks and KR Stefan

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [28 July 2022 18:50 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/10 "2022-07-28T18:50:59Z")

</div>

Use different env vars for each set of credentials. Specify the appropriate var in each of the request nodes.

---

<div class="post-metadata">

**Author:** ![3dimensional](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/3dimensional/32/64992_2.png) [@3dimensional](https://discourse.nodered.org/u/3dimensional)\
**Post date:** [28 July 2022 19:12 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/11 "2022-07-28T19:12:58Z")

</div>

Hi, ok - all your replies and some more research let me understood the concept. There is only one major concern: Putting plain passwords to `settings.js` would prefer to store it in `node-red-contrib-credentials`. But thanks for you support, have to think about a proper solution for my requirement. My i fork the http-request node and individualize it for my needs. KR Stefan

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [28 July 2022 19:46 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/12 "2022-07-28T19:46:26Z")

</div>

> [@3dimensional](#):
>
> Putting plain passwords to `settings.js`

They don't have to be in settings.js, they could be set in a script that starts node-red or in the system environment before getting to node red. But yes, they will be in plain text, which is not ideal to say the least.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [26 September 2022 19:46 UTC](https://discourse.nodered.org/t/http-in-node-and-templated-user-and-password-for-basic-auth-proposal/65755/13 "2022-09-26T19:46:52Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
