# I need to get the RAW body from a listener node

**URL:** <https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105>\
**Category:** General\
**Created:** [13 September 2018 09:10 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105 "2018-09-13T09:10:32Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [13 September 2018 09:10 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/1 "2018-09-13T09:10:32Z")

</div>

Hello

I am developping a node as part of a package.  
The node is a WebHook (much like what you can imagine exist in SLACK... so, the user subscribes to events and the target app will deliver those events as POST to the Webhook endpoint).

To create the endpoint I use the following in my code:

RED.httpNode.post('/thisIsMyEndpoint', bodyParser.json(), mySuccessCallback, myErrorCallback);

NOW, **I need to catch the UNPARSED BODY coming from the target application** , before it is parsed.  
Experimenting blindly (I'm not an expert) it seems that the presence or absence of the `bodyParser.json(),` parameter actually does not change the results: "mySuccessCallback" ALWAYS receives a parsed req.body object... WHich is not what I need

I tried to use something like this:  
RED.httpNode.post('/thisIsMyEndpoint', **myOwnFunction** , mySuccessCallback, myErrorCallback);

But my own function also **only receives** a **req, res, next** and \*_req is already parsed_.

Do you have any idea how to

- either intercept the raw body, process it and, eventually PREVENT further processing
- provide a req.raw\_body attribute to the "mySuccessCallback"

Perhaps I am not using the right tools

Thanks  
/Stefano

---

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [13 September 2018 12:17 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/2 "2018-09-13T12:17:45Z")

</div>

alternatively : is there the possibility to use directly the Express app.post ?

---

<div class="post-metadata">

**Author:** ![shrickus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/shrickus/32/517_2.png) [@shrickus](https://discourse.nodered.org/u/shrickus)\
**Post date:** [13 September 2018 18:07 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/3 "2018-09-13T18:07:56Z")

</div>

Although I've never tried it, there is an optional middleware section (commented out) in the node-red settings.js file:

```auto
    // The following property can be used to add a custom middleware function
    // in front of all http in nodes. This allows custom authentication to be
    // applied to all http in nodes, or any other sort of common request processing.
    httpNodeMiddleware: function(req,res,next) {
        // Handle/reject the request, or pass it on to the http in node by calling next();
        // Optionally skip our rawBodyParser by setting this to true;
        req.skipRawBodyParser = true;
        next();
    },

```

So it appears that you can set up some `http in` flows in node-red, which will receive the raw data from the calling application. Of course, this setting will apply to ALL of your exposed endpoints...

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 September 2018 16:24 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/4 "2018-09-15T16:24:33Z")

</div>

Here is some info on how to get round this issue:

> <https://stackoverflow.com/questions/9920208/expressjs-raw-body>

However, I would question exactly why you need the raw body? I suspect that there are better ways to do whatever it is that you want.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [15 September 2018 21:03 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/5 "2018-09-15T21:03:12Z")

</div>

A bit more context on the request - Stefan is trying to handle an http request that includes a checksum of its body in a header. In order to verify the checksum, Stefan needs the raw body.

Unfortunately we don't currently provide any way to prevent the JSON body parser from running if the content-type properly identifies it as JSON.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 September 2018 00:10 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/6 "2018-09-16T00:10:51Z")

</div>

Ah, I see. And it looks like Express doesn't provide it either any more if the stackoverflow answer is to be believed.

Any way it can be reconstructed?

---

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [17 September 2018 08:42 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/7 "2018-09-17T08:42:07Z")

</div>

i haven't understood what you mean by saying that "express doesn't provide it either any more".  
Do you mean that using Express it is no more possible to add Middleware that can be set to intercept the raw body? I think that some of my colleagues were actually able to do it.

Isn't there the possibility (and, if yes, HOW) in the code of my web hook to program directly an Express endpoint instead of using the RED.httpNode..post ?  
I mean, if I could use the app.use and app.post directly....

Thanks so much

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [17 September 2018 23:40 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/8 "2018-09-17T23:40:59Z")

</div>

> [@stefanopog](#):
>
> express doesn't provide it either any more

See the quoted article. Express used to have the raw body returned but according to that post, doesn't any more.

> [@stefanopog](#):
>
> Do you mean that using Express it is no more possible to add Middleware that can be set to intercept the raw body? I think that some of my colleagues were actually able to do it.

No, middleware is a really important concept in Express and I use it extensively in my uibuilder node.

> [@stefanopog](#):
>
> Isn't there the possibility (and, if yes, HOW) in the code of my web hook to program directly an Express endpoint instead of using the RED.httpNode..post ?

Check here:

> <https://github.com/TotallyInformation/node-red-contrib-uibuilder/blob/main/nodes/uibuilder.js#L227>

This gives you access to Express directly & immediately after that, it shows the use of Express middleware.

Note that Node-RED has two different Express instances to work with. One for the admin UI and one for everything else. In truth, I think that my code is serious overkill but I took it from core code. When the admin UI gets split from the runtime, that kind of defensive coding may be more useful.

As you can tell from my var name, this gives you an Express app reference to work with. The middleware can be "use", "get", "post", etc. "use" is the most generic.

uibuilder is very heavily commented (the only way I can ever follow my own code later!) so hopefully everything is pretty well explained. I also have an example repo on GitHub that may be easier to follow. Not all of the example node's code is necessarily correct now as I've not updated it but it might be easier to start with it as it works through and shows each stage of the node's process.

---

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [19 September 2018 15:32 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/9 "2018-09-19T15:32:06Z")

</div>

@TotallyInformation : i do not see in the code where you handler is getting to the **req.on** in order to get the raw data....

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [19 September 2018 15:49 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/10 "2018-09-19T15:49:25Z")

</div>

With all due respect to @TotallyInformation, his reply misses a key point.

By the time a node gets access to `RED.httpNode`, the default set of body parsers have _already been applied_.

As I've said a few times, as the person who wrote the code, there is no way for you to get ahold of the raw request in the current code.

If I wasn't snowed under with high priority work right now, I'd be able to spend some time devising a way to expose it in a future release of Node-RED. But right now, I don't have time to do that. If someone wants to help on that - please do.

---

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [19 September 2018 16:19 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/11 "2018-09-19T16:19:29Z")

</div>

pls contact me **offline** @knolleary . If it will not take too much i may be willing to give a try

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [20 September 2018 19:56 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/12 "2018-09-20T19:56:20Z")

</div>

> [@knolleary](#):
>
> With all due respect to @TotallyInformation, his reply misses a key point.

Sorry, I probably confused things there. I was only answering the question about getting the reference to the Express app. Of course, most of the middleware has already been applied.

I also mentioned previously that Express no longer provides access to the raw return as indicated in the StackOverflow question that I referenced.

@stefanopog, if you want to confirm whether Express provides some form of access to the raw return. I suggest creating a simple Express app, you will be able to easily examine the data directly without the complexity of Node-RED wrapped around it.

---

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [24 September 2018 16:48 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/13 "2018-09-24T16:48:41Z")

</div>

I had some colleagues of mines getting to the RAW Body using Express @TotallyInformation

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [24 September 2018 20:16 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/14 "2018-09-24T20:16:57Z")

</div>

> [@stefanopog](#):
>
> I had some colleagues of mines getting to the RAW Body using Express @TotallyInformation

OK, so maybe that StackOverflow answer isn't correct. Never-the-less, as Nick says, Node-RED itself doesn't currently expose it anyway. It would need changes to the Node-RED core.

An easier way right now, if Express _is_ exposing the raw body would be to set up your own Express server. It isn't hard to create a simple server and you could easily then link it to Node-RED by one of the many comms methods ranging from MQTT, WS, HTTP, TCP, UDP or UNIX sockets. But maybe this isn't possible in your setup?

---

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [26 September 2018 10:45 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/15 "2018-09-26T10:45:38Z")

</div>

I think it may become too complex ☹

---

<div class="post-metadata">

**Author:** ![chrisnie](https://avatars.discourse-cdn.com/v4/letter/c/d07c76/32.png) [@chrisnie](https://discourse.nodered.org/u/chrisnie)\
**Post date:** [11 October 2018 05:47 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/16 "2018-10-11T05:47:01Z")

</div>

Hi,

@stefanopog , did you find a solution in the meantime? I have a quite similar requirement - i have to hmac-sha256 the raw body for authentication purposes...

I've already tested with the `httpNodeMiddleware` but it seems the body already has been parsed here...

thanks & bye,  
Chris

---

<div class="post-metadata">

**Author:** ![stefanopog](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stefanopog/32/2547_2.png) [@stefanopog](https://discourse.nodered.org/u/stefanopog)\
**Post date:** [14 October 2018 21:09 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/17 "2018-10-14T21:09:15Z")

</div>

no i did not unfortunately  
For which reason do you need to apply the encrypting? WWS ?

---

<div class="post-metadata">

**Author:** ![chrisnie](https://avatars.discourse-cdn.com/v4/letter/c/d07c76/32.png) [@chrisnie](https://discourse.nodered.org/u/chrisnie)\
**Post date:** [15 October 2018 06:29 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/18 "2018-10-15T06:29:37Z")

</div>

Hi @stefanopog,

we receive messages from internet connected systems. To authenticate the validity of these messages the originator builds a hmac-SHA256 checksum over the body with a shared secret. And to validate this message we need to access the raw body as the transmitted json has some line-breaks and other formatting applied that also influences the checksum...

Cheers,  
Chris

---

<div class="post-metadata">

**Author:** ![chrisnie](https://avatars.discourse-cdn.com/v4/letter/c/d07c76/32.png) [@chrisnie](https://discourse.nodered.org/u/chrisnie)\
**Post date:** [24 October 2018 08:07 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/19 "2018-10-24T08:07:13Z")

</div>

Hi @stefanopog,

i had some time digging into it and now it might i've found a solution by picking up @shrickus hint with the `httpNodeMiddleware`.

In the first tests with the `httpNodeMiddleware` I discovered that the request already has ben parsed at this point. So I started tracking down where it got parsed and found it: It seems to be a default handler from the admin-UI at this point:

> <https://github.com/node-red/node-red/blob/9d219c163df67c0acab7868e2f45aea65d8fe879/red/api/index.js#L42>

  
After discovering this line 36 gave me the right hint: We just get the admin UI away form the default path by setting something like `httpAdminRoot: '/admin',` in `settings.js` and voila - the request is unparsed in `httpNodeMiddleware`.

As next step I've created an own jsonParser setting me the raw body. I've also placed this code into `settings.js` just before the `module.exports = {` line:

```auto
var bodyParser = require('body-parser');
var jsonParserWithRawBody = bodyParser.json({
    verify: function (req, res, buf, encoding) {
        req.rawBody = buf;
    }
})

```

This parser stores the body into `req.rawBody` for later usage...

some lines down in `settings.js` i've commented in the httpNodeMiddleware and conditionally added my parser:

```auto
    httpNodeMiddleware: function(req,res,next) {
        if (req.url === '/my/httpin/url/where/i/want/to/have/the/raw/body') {
           jsonParserWithRawBody(req, res, next);
        } else
           next();
    },

```

Now i have the rawBody for my httpin to do all my authentication stuff...

Cheers, Chris

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [24 October 2018 10:40 UTC](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105/20 "2018-10-24T10:40:22Z")

</div>

@chrisnie - good digging! I'm currently looking to see if there's a way we can expose a way to do this more gracefully without having edit the settings file - as that makes it harder to just import a node and use it. But glad to see you've found a solution for the time being.

[Next page](https://discourse.nodered.org/t/i-need-to-get-the-raw-body-from-a-listener-node/3105.md?page=2)
