# Input needed for a fix in the dropbox node (refresh tokens)

**URL:** https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949
**Category:** Developing Nodes
**Created:** [30 December 2022 11:04 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949 "2022-12-30T11:04:51Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![Buckskin](https://avatars.discourse-cdn.com/v4/letter/b/b9e5f3/32.png) [@Buckskin](https://discourse.nodered.org/u/Buckskin)
#### Post date: [3 January 2023 21:45 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/21 "2023-01-03T21:45:04Z")

</div>

> [@BartButenaers](#):
>
> So when you want to request a new refresh token, you will have to get the App Key again from your Dropbox account

Not a problem for me because I save all that kind of stuff in my password manager

Does the OAuth stuff need to be in the frontend?

All the security stuff - over my head I'm afraid. If I have simple examples I can follow along & implement, but other than that ...

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [3 January 2023 21:52 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/22 "2023-01-03T21:52:30Z")

</div>

> [@Buckskin](#):
>
> Does the OAuth stuff need to be in the frontend?

Yes you need to call the authentication flow from your node's config screen, and then Dropbox will show a few pages where you need to confirm that this Node-RED node is allowed to access your Dropbox folders. The communication to dropbox is of course SSL. So it is better if I add a bit more code to the frontend, to calculate the authentication url also there. Then I don't need to send anything to Node-RED. Of course the resulting refresh token will be send - as a credential - to Node-RED. Don't know if that can be intercepted. But that is again application level stuff, not specific to this Dropbox node.

> [@Buckskin](#):
>
> All the security stuff - over my head I'm afraid.

That is no problem! I am already glad that there was some response. By thinking out loud to answer the questions, things became more clear.

Would be a shame if I introduce a security leak, while only trying to help some folks in this community...

I think I know enough for now, to continue the development.

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [3 January 2023 21:57 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/23 "2023-01-03T21:57:06Z")

</div>

> [@BartButenaers](#):
>
> I think I know enough for now, to continue the development.

Although one more question.  
If I add a third-party code snippet to a semi-core node like this, does anybody know which licence it should have? For example found another sha256 implementation [here](https://www.movable-type.co.uk/scripts/sha256.html), which has an _ **MIT license** _. Is that ok to include? Perhaps something that @dceejay knows?

---

<div class="post-metadata">

### Author: ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)
#### Post date: [3 January 2023 23:25 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/24 "2023-01-03T23:25:46Z")

</div>

IANAL but I think either MIT or Apache2 should be fine, as long as attributed correctly.

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [5 January 2023 22:01 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/25 "2023-01-05T22:01:06Z")

</div>

> [@dceejay](#):
>
> IANAL

Oh my apologies. My mistake! By looking at your profile picture I was so certain you were one 😂

> [@BartButenaers](#):
>
> I think I know enough for now, to continue the development.

**I got something working, both with and without SSL** (towards Node-RED) 🍾 🥂 🥳 🎉  
But don't panic: towards Dropbox it is always SSL 😉

- When SSL is used between the flow editor and Node-RED, then I generate the SHA256 hash with the browser's Crypto Web API. Because such a hash function implementation is reviewed by experts and probably more secure.

- When plain http is being used between the flow editor and Node-RED, then I generate the SHA256 hash with [this](https://github.com/emn178/js-sha256) implementation. Tried some others but failed to get the correct output format. That file is stored in a "resources" subfolder of the dropbox nodes, which is a standard [way](https://nodered.org/docs/creating-nodes/resources) of working in Node-RED:

I have now removed my last endpoint in the dropbox node, which means that no data is being communicated anymore with Node-RED. I have implemented instead the logic of the Dropbox SDK [generatePKCECodes](https://github.com/dropbox/dropbox-sdk-js/blob/main/src/auth.js#L198) inside the frontend (i.e. code verifier and code challenge calculations), so I could compose the Dropbox authentication URL myself. By removing the communication with Node-RED, I can now support both http and https traffic. Summarized:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/1/11ec15daba26114b54062f1e9751d96b4b230a99.png)

So the only crypto data send to Node-RED (via http or https) is the refresh token at the end, to store it in Node-RED as a credential. I assume that people only use http behind a firewall. If people use this across a WAN over the internet, then I cannot help it if their refresh token gets intercepted (between their flow editor and Node-RED)...

The codebase has become very short and clean. I am very pleased with the result.

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [5 January 2023 22:39 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/26 "2023-01-05T22:39:45Z")

</div>

BTW I have to be honest. Have been searching like a maniac the last two evenings, why Dropbox kept complaining about _ **"invalid code identifier"** _. There was tiny difference between my code challenge calculation and how Dropbox calculates it. Dropbox calculates the challenge again and it must be exactly the same as mine. In my previous version I used their Javascript SDK in my endpoint, so then it was always correct. But not now that I calculate it by myself.

An hour ago I was getting desperate, and then I thought: perhaps I can ask it to the OpenAi chatbot. And I have to admit that (s)he provided me with the missing puzzle piece...

---

<div class="post-metadata">

### Author: ![tve](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/tve/32/59475_2.png) [@tve](https://discourse.nodered.org/u/tve)
#### Post date: [5 January 2023 23:16 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/27 "2023-01-05T23:16:49Z")

</div>

what did you ask and what was the reply?

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [6 January 2023 05:58 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/28 "2023-01-06T05:58:30Z")

</div>

Don't ask me. I have already forgotten 😂

This was really too much detailed stuff after a hard dat at work. By typing the questions in my brain here and reading the doubts from other people, I finally came to a solution that I "think" is safe enough. I have tested it both on http and https.

It has become a very cryptic discussion, but it helped 😉

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [6 January 2023 06:01 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/29 "2023-01-06T06:01:33Z")

</div>

Ah now I see. You wondered what I have asked the chatbot and not what I have asked you people here. Seems I am not awake yet 🤣

Will share it later on the day with you.

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [6 January 2023 06:51 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/30 "2023-01-06T06:51:18Z")

</div>

About my questions I have asked to the OpenAi chatbot:

Owkay, the problem was that in an unsecure context (i.e. I was in the config screen of a flow editor that was connected to Node-RED via plain HTTP) the Web Crypto API has no digest function to calculate a SHA256 hash. Had already tried some other libraries to calculate such a hash in my browser, but the output was most of time already converted to a string. And the Web Crypto digest function returned me an arraybuffer, which was also converted by the dropbox SDK to a string. But the Dropbox SDK returned another string.

1. I first asked him/her _"Give a javascript alternative to crypto.subtle.digest to create an sha256 hash"_. But that didn't work because he didn't understand "alternative", so he showed an example with the crypto.subtle.digest function (which I don't have).

2. Then I asked him/her _"give a javascript program to create an sha256 hash in the browser without using the crypto web api"_, but I was not sure whether his alternative would work because he was telling that it somehow used the Web Crypto API under the hood...

3. Then I asked him/her _"give a javascript program to create an sha256 hash in the browser when in a not secure environment"_. And now he gave me clear instructions which library I needed to use and a code example.

Of course you still need to know what you are doing and give him good questions. But it really helps. Although I like it, I am very sure that it will be misabused by some people in the future. But please let's not discuss that here 😉

BTW I have to admit that first I wrote 3 times in my post _"I asked him"_ instead of _"I asked her"_. So although I am really a guy that likes equality between woman and man, somehow my brain thought that the OpenAi bot was male ☺. So my sincere apologies to all the ladies on this blue planet for me thinking that a chatbot with high quality technical answers can only be male.

Ok hopefully the ladies accept my apologies. Although I wonder if any of them will ever read a cryptic technical discussion like this. Damn now my brain did it again 😂 🤣

---

<div class="post-metadata">

### Author: ![tve](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/tve/32/59475_2.png) [@tve](https://discourse.nodered.org/u/tve)
#### Post date: [6 January 2023 08:06 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/31 "2023-01-06T08:06:31Z")

</div>

English has the convenient "it" 😉

---

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [6 January 2023 10:30 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/32 "2023-01-06T10:30:11Z")

</div>

Definitely an 'it' 🙄

 ![gender](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/c/9cb9854f90e9c3e698d1a5aa3775ac82c504f005.jpeg)

---

<div class="post-metadata">

### Author: ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)
#### Post date: [6 January 2023 11:24 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/33 "2023-01-06T11:24:35Z")

</div>

Ask it what it's pronouns are...

---

<div class="post-metadata">

### Author: ![hotNipi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hotnipi/32/383_2.png) [@hotNipi](https://discourse.nodered.org/u/hotNipi)
#### Post date: [6 January 2023 11:42 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/34 "2023-01-06T11:42:14Z")

</div>

... your profile image

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/5/f5e05d342167bf37157fc4429659d48637ee72e7.jpeg)

---

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [6 January 2023 11:47 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/35 "2023-01-06T11:47:08Z")

</div>

> [@dceejay](#):
>
> Ask it what it's pronouns are

![gender](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/2/e21473ac4c2e7a6f4c26e9d7a0748b28f589db42.jpeg)

There's too many letters to type in 'Assistant'...

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [6 January 2023 11:54 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/36 "2023-01-06T11:54:48Z")

</div>

I think you can safely shorten it to just 3 letters! 😁

---

<div class="post-metadata">

### Author: ![hotNipi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hotnipi/32/383_2.png) [@hotNipi](https://discourse.nodered.org/u/hotNipi)
#### Post date: [6 January 2023 12:03 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/37 "2023-01-06T12:03:19Z")

</div>

"sis" then. Definitely she 🙂

---

<div class="post-metadata">

### Author: ![hotNipi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hotnipi/32/383_2.png) [@hotNipi](https://discourse.nodered.org/u/hotNipi)
#### Post date: [6 January 2023 12:10 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/38 "2023-01-06T12:10:22Z")

</div>

Mystery solved. "Photo of the mirror in front of you"

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/6/e6c601814944ad13dda5870993ed2cd0866f6efe.jpeg)

---

<div class="post-metadata">

### Author: ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)
#### Post date: [6 January 2023 22:06 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/39 "2023-01-06T22:06:50Z")

</div>

The pull request has been submitted.  
Announcement started in another discussion:

> [@\[ANNOUNCEMENT\] Dropbox node versie 2.1.0 (beta) - refresh token refactored](https://discourse.nodered.org/t/announcement-dropbox-node-versie-2-1-0-beta-refresh-token-refactored/73312):
>
> Hi folks, We introduced in version 2.0.0 of the dropbox node the concept of refresh tokens, to allow this node to support the new stronger Dropbox security guidelines. However our mechanism was based on OAauth2 redirect url's, which required the connection between Node-RED and the flow editor to be SSL with certificates signed by a trusted CA (e.g. LetsEncrypt). Normally it is bad practice to use plain HTTP, however when everything (flow editor, Node-RED, ...) is located in a secure LAN behin…

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [7 March 2023 22:07 UTC](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949/40 "2023-03-07T22:07:09Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.

[Previous page](https://discourse.nodered.org/t/input-needed-for-a-fix-in-the-dropbox-node-refresh-tokens/72949.md?page=1)
