# httpAdminMiddleware setting for authentication from parent website

**URL:** <https://discourse.nodered.org/t/httpadminmiddleware-setting-for-authentication-from-parent-website/30158>\
**Category:** General\
**Created:** [16 July 2020 01:25 UTC](https://discourse.nodered.org/t/httpadminmiddleware-setting-for-authentication-from-parent-website/30158 "2020-07-16T01:25:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashish-y](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@ashish-y](https://discourse.nodered.org/u/ashish-y)\
**Post date:** [16 July 2020 01:25 UTC](https://discourse.nodered.org/t/httpadminmiddleware-setting-for-authentication-from-parent-website/30158/1 "2020-07-16T01:25:46Z")

</div>

Hi All,

I have an instance of node red running on a digital ocean server. and I’m using iframe to embed it into a react website. Now the react website has auth0 integrated so I plan to use the token generated by auth0 _(after the user logs in)_ to authenticate node-red bypassing node-reds adminAuth setting. Any recommendation or reference resources on how to achieve this? I think I need to use httpAdminMiddleware setting? Please correct me if I’m wrong.

Thanks.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 July 2020 08:24 UTC](https://discourse.nodered.org/t/httpadminmiddleware-setting-for-authentication-from-parent-website/30158/2 "2020-07-16T08:24:58Z")

</div>

Hi @ashish-y

with the 1.1.2 release you can now specify a custom token handler in your `adminAuth` configuration - this lets you use your own code to verify the auth token node-red is using, rather than use the built-in tokens.

[https://nodered.org/docs/user-guide/runtime/securing-node-red#custom-authentication-tokens](https://nodered.org/docs/user-guide/runtime/securing-node-red#custom-authentication-tokens)

---

<div class="post-metadata">

**Author:** ![ashish-y](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@ashish-y](https://discourse.nodered.org/u/ashish-y)\
**Post date:** [16 July 2020 18:25 UTC](https://discourse.nodered.org/t/httpadminmiddleware-setting-for-authentication-from-parent-website/30158/3 "2020-07-16T18:25:21Z")

</div>

> [@knolleary](#):
>
> e your own code to verify the auth token node-red is using, rather than use the built-in tokens.

Hi @knolleary

I was already using this to achieve the desired functionality. Actually I was patiently waiting for the 1.1.1 release, especially to use this feature. So Thanks a lot for including this in the release.

The only issue with using adminAuth custom authentication token is an extra logout button. I want the user to login and logout from the parent app and not have the option in the node-red menu. I can probably hide the logout button if I use adminAuth but thought I'll check for a better and efficient solution before manually hiding the logout button from the UI.  
That's when I stumbled upon httpAdminMiddleware setting hoping to use it as an access\_token validator but couldn't figure it out.

Do you think I should stick to adminAuth and just hide the UI logout? Or if there is better way to make all this work.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [14 September 2020 18:25 UTC](https://discourse.nodered.org/t/httpadminmiddleware-setting-for-authentication-from-parent-website/30158/4 "2020-09-14T18:25:26Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
