# In SSO after receiving auth code, gets unauthorized 401 in javascript console

**URL:** <https://discourse.nodered.org/t/in-sso-after-receiving-auth-code-gets-unauthorized-401-in-javascript-console/65555>\
**Category:** General\
**Tags:** node-red-dashboard\
**Created:** [25 July 2022 04:30 UTC](https://discourse.nodered.org/t/in-sso-after-receiving-auth-code-gets-unauthorized-401-in-javascript-console/65555 "2022-07-25T04:30:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kiru](https://avatars.discourse-cdn.com/v4/letter/k/a9a28c/32.png) [@kiru](https://discourse.nodered.org/u/kiru)\
**Post date:** [25 July 2022 04:30 UTC](https://discourse.nodered.org/t/in-sso-after-receiving-auth-code-gets-unauthorized-401-in-javascript-console/65555/1 "2022-07-25T04:30:38Z")

</div>

Hi, i am trying to enable SSO for my nodered editor. Using azure ad as Identity provider, **i could receive the authentication code** having response type as code. But the problem is the code is not getting authenticated, and the editor is not getting loaded, it remains in the same page after receiving the code.

adminAuth:{  
Type:”strategy”,  
Strategy:{  
Name:—-  
Label:—  
Icon:—-  
Strategy : require(“passport-azure-ad”).OIDCStrategy,  
Options:{  
Identitymetadata: metadata url  
Clientid:  
Clientsecret:  
Responsetype: “code”,  
Responsemode:”query”,  
Redirecturl: localhost,  
AllowhttpforredirectURL: true,  
Scope:[openid, profile, email, offline\_access],  
Verify: function ( code, profile, done){  
Console.log(code);// nothing gets printed here not sure why, not even string  
Done(null, profile);  
Return profile;  
}  
}  
},  
users: function (user){  
return Promise.Resolve({username: user, permissions:”\*”});  
}

When does that verify function gets called, and not sure why the console.log is not printing anything.

I get unauthorized 401 in javascript console.

Is this a right way of handling the auth code and how can i access my editor page after this.

Kindly ignore the syntax errors if Any, posted just for a reference.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [25 July 2022 09:39 UTC](https://discourse.nodered.org/t/in-sso-after-receiving-auth-code-gets-unauthorized-401-in-javascript-console/65555/2 "2022-07-25T09:39:59Z")

</div>

> [@kiru](#):
>
> adminAuth:{

Are you trying to use the auth in Dashboard? Your code is only for the Editor and admin API's.

---

<div class="post-metadata">

**Author:** ![kiru](https://avatars.discourse-cdn.com/v4/letter/k/a9a28c/32.png) [@kiru](https://discourse.nodered.org/u/kiru)\
**Post date:** [25 July 2022 10:43 UTC](https://discourse.nodered.org/t/in-sso-after-receiving-auth-code-gets-unauthorized-401-in-javascript-console/65555/3 "2022-07-25T10:43:31Z")

</div>

As of now only enabling for editor. [quote="TotallyInformation, post:2, topic:65555, full:true"]

> [@kiru](#):
>
> adminAuth:{

Are you trying to use the auth in Dashboard? Your code is only for the Editor and admin API's.  
[/quote]

---

<div class="post-metadata">

**Author:** ![kiru](https://avatars.discourse-cdn.com/v4/letter/k/a9a28c/32.png) [@kiru](https://discourse.nodered.org/u/kiru)\
**Post date:** [25 July 2022 13:28 UTC](https://discourse.nodered.org/t/in-sso-after-receiving-auth-code-gets-unauthorized-401-in-javascript-console/65555/4 "2022-07-25T13:28:15Z")

</div>

Kindly let me know for any idea on this issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [23 September 2022 13:29 UTC](https://discourse.nodered.org/t/in-sso-after-receiving-auth-code-gets-unauthorized-401-in-javascript-console/65555/5 "2022-09-23T13:29:12Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
