# Implementing Authorization for users

**URL:** https://discourse.nodered.org/t/implementing-authorization-for-users/82704
**Category:** General
**Tags:** security
**Created:** [8 November 2023 08:08 UTC](https://discourse.nodered.org/t/implementing-authorization-for-users/82704 "2023-11-08T08:08:49Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![dharmaraj-bytes](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dharmaraj-bytes/32/84645_2.png) [@dharmaraj-bytes](https://discourse.nodered.org/u/dharmaraj-bytes)
#### Post date: [8 November 2023 08:08 UTC](https://discourse.nodered.org/t/implementing-authorization-for-users/82704/1 "2023-11-08T08:08:49Z")

</div>

I have added user login in my node red app. Now I want to create a solution where individual user can have their own separate environment/session where then can create/edit their own flows. So User A can have access to all the flows the he/she created, they won't be able to access the flows created by User B.

I want to display flows for individual users on front end (next.js) using iframe or any thing similar to that, where they can have a separate environment in the specific section of the website.

Can anyone provide a fesiable solution, as having seperate servers for each user is not fesiable because the users are not fixed in the site, we can have multiple new users after 2-3 months.

Tech Stack for the site,

Backend: Nest.js  
Database: MongoDB  
FrontEnd: Next.js

---

<div class="post-metadata">

### Author: ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)
#### Post date: [8 November 2023 08:30 UTC](https://discourse.nodered.org/t/implementing-authorization-for-users/82704/2 "2023-11-08T08:30:27Z")

</div>

I have removed all the tags that you added that are not relevant.

Node RED by its self does not support separate user environments.

For your type of setup, I recommend FlowFuse.

> **[FlowFuse • DevOps for Node-RED](https://flowfuse.com/)**
>
> FlowFuse and Node-RED allows your engineers to deliver fast, low-cost, low-code manufacturing applications.

Which is built on Node RED, and uses a teams approach to environments.

@Steve-Mcl

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [8 November 2023 14:32 UTC](https://discourse.nodered.org/t/implementing-authorization-for-users/82704/3 "2023-11-08T14:32:32Z")

</div>

If you need to run your own service, there are a couple of ways to do it.

Firstly, you will almost certainly want a reverse proxy such as NGINX to hide the port numbers and use URL paths or sub-domains instead.

Then, you will need to create multiple Node-RED instances, 1 per user. Node-RED allows for this but each instance requires its own IP port. Hence the probably need to hide those using a proxy.

Multiple instances can be run on bare metal utilising multiple startup scripts with separate userDir folders or you could use Docker/Kubernetes.

Also, if you need to accommodate a variable set of users, you will also need to create some automation to deal with that.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [7 January 2024 14:32 UTC](https://discourse.nodered.org/t/implementing-authorization-for-users/82704/4 "2024-01-07T14:32:54Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
