# Http-request password - 401 error

**URL:** <https://discourse.nodered.org/t/http-request-password-401-error/10313>\
**Category:** General\
**Created:** [18 April 2019 01:59 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313 "2019-04-18T01:59:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![va3mw](https://avatars.discourse-cdn.com/v4/letter/v/dec6dc/32.png) [@va3mw](https://discourse.nodered.org/u/va3mw)\
**Post date:** [18 April 2019 01:59 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/1 "2019-04-18T01:59:55Z")

</div>

This is some pretty basic stuff that is challenging me as a new user of Node-Red.

I have a web switch I am trying to control that is password protected. I created the http-request to the page with basic authentication.

When I execute it, I get a 401, password required.

401 Unauthorized: Password required

As a test, I turned off 'use basic authentication' and coded the get like this:

[http://username:password@192.168.1.10/status.xml](http://username:password@192.168.1.10/status.xml)

This still returns a 401 error.

As a test, on the same RPI that NodeRed is running, I issued the same command using curl

curl [http://username:password@192.168.1.10/status.xml](http://username:password@192.168.1.10/status.xml)

The curl command works as expected and the password is accepted.

Any guidance will be appreciated on what might be blocking me?

Many thanks, Mike

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [18 April 2019 05:13 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/2 "2019-04-18T05:13:43Z")

</div>

Do you use a backslash or any other uncommon character in your password ?

---

<div class="post-metadata">

**Author:** ![va3mw](https://avatars.discourse-cdn.com/v4/letter/v/dec6dc/32.png) [@va3mw](https://discourse.nodered.org/u/va3mw)\
**Post date:** [18 April 2019 14:49 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/3 "2019-04-18T14:49:22Z")

</div>

No... in fact, for the test, the username and password are plain text. It is actually "a" and "a". 🙂  
Mike

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 April 2019 16:11 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/4 "2019-04-18T16:11:39Z")

</div>

That is indeed weird. The **http-request** node (currently) uses the " **request**" NPM library under the cover, and when you look at their [readme](https://www.npmjs.com/package/request) page you see that they even support credentials embedded in the URL like you do:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/7/7f889552120c82c82f1497cd78cbc7c51c0cce64.png)

I thought we had a similar issue in the past, but cannot remember anymore what the outcome was. And most likely that was on an older version of Node-RED, where the http-request node was using the [follow-redirects](https://www.npmjs.com/package/follow-redirects) NPM library underneath ...

P.S. But to make sure, which version of Node-RED are you using?

Bart

---

<div class="post-metadata">

**Author:** ![va3mw](https://avatars.discourse-cdn.com/v4/letter/v/dec6dc/32.png) [@va3mw](https://discourse.nodered.org/u/va3mw)\
**Post date:** [18 April 2019 16:33 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/5 "2019-04-18T16:33:41Z")

</div>

Thanks Bart for your time.

I am using v0.19.6 on a Pi. I see that 0.20 is out.

I guess I should look into upgrading.

Mike

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [18 April 2019 17:58 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/6 "2019-04-18T17:58:32Z")

</div>

Hey Mike,  
I would indeed upgrade, but now I'm not sure if your problems is going to be solved. If you have a look at the Node-RED [changelog](https://github.com/node-red/node-red/blob/master/CHANGELOG.md#019-milestone-release), you will see that the httprequest node uses the "request" library since 0.19.0:

> HTTP Request: Move to request module

And there is another problem. I wrote some time ago the [node-red-contrib-http-logger](https://github.com/bartbutenaers/node-red-contrib-http-logger) to see which http request is being send underneath. However that node doesn't work anymore with newer NodeJs versions. Have been working on it this week, but my new version isn't complete yet. But perhaps it works on your NodeJs version, and then you can see what is being send. Perhaps you can see something strange ...

---

<div class="post-metadata">

**Author:** ![va3mw](https://avatars.discourse-cdn.com/v4/letter/v/dec6dc/32.png) [@va3mw](https://discourse.nodered.org/u/va3mw)\
**Post date:** [19 April 2019 19:42 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/7 "2019-04-19T19:42:17Z")

</div>

Some more data. I'm not bad at gathering Wireshare data. I'm bad at reading it. 🙂

Here is a successful http-request from chrome:

```auto
GET /status.xml HTTP/1.1

Host: 192.168.110.12

Connection: keep-alive

Cache-Control: max-age=0

Authorization: Basic YTph

Upgrade-Insecure-Requests: 1

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36

DNT: 1

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3

Accept-Encoding: gzip, deflate

Accept-Language: en-US,en;q=0.9

HTTP/1.1 200 OK

Connection: close

Content-Type: text/xml

Cache-Control: no-cache

<response> 

blah blah blah and off we go with the xml data.

This is the failing request from NodeRed

```

GET /status.xml HTTP/1.1  
host: 192.168.110.12  
Connection: close

HTTP/1.1 401 Unauthorized  
WWW-Authenticate: Basic realm="Protected"  
Connection: close

401 Unauthorized: Password required

```auto

```

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [19 April 2019 21:56 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/8 "2019-04-19T21:56:23Z")

</div>

Mike,  
I'm not a security expert, but in this older [post](https://discourse.nodered.org/t/http-request-digest-auth/3854) there was a rather similar problem.

Could it be that your web switch also uses **digest authentication** instead of _basic authentication_? Both methods require a username and password. But the request library uses basic authentication, unless it is specified explicit that digest authentication is required.

If you update to the latest Node-RED version, then your http-request node will [support](https://github.com/node-red/node-red/pull/2061) Digest Authentication:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/2/2aaec74f142d75769e684c7c38a142e30e46c3d2.png)

Would be nice if you could test whether that solves the problem!

---

<div class="post-metadata">

**Author:** ![va3mw](https://avatars.discourse-cdn.com/v4/letter/v/dec6dc/32.png) [@va3mw](https://discourse.nodered.org/u/va3mw)\
**Post date:** [21 April 2019 13:35 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/9 "2019-04-21T13:35:17Z")

</div>

Hi Bart

I will give that a try after I upgrade to the latest version.

This works:

curl [http://a:a@192.168.110.12/status.xml](http://a:a@192.168.110.12/status.xml)

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/f/fb1a52b41cccdb349032db843fcaf86f5cc1cf50.png)

Thanks for your help.

Mike

---

<div class="post-metadata">

**Author:** ![CABrouwers](https://avatars.discourse-cdn.com/v4/letter/c/5f8ce5/32.png) [@CABrouwers](https://discourse.nodered.org/u/CABrouwers)\
**Post date:** [10 January 2020 19:47 UTC](https://discourse.nodered.org/t/http-request-password-401-error/10313/10 "2020-01-10T19:47:36Z")

</div>

Have you found out more about this?  
I am brand new to Node-Red and running into the exact same issue.  
I am trying to pull data from a device. The curl version works perfectly but not the http-request node runs into an authentication error. Exactly as you describe.
