# Is http node secure?

**URL:** <https://discourse.nodered.org/t/is-http-node-secure/34432>\
**Category:** General\
**Created:** [17 October 2020 22:12 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432 "2020-10-17T22:12:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guacamole-1](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/guacamole-1/32/30530_2.png) [@Guacamole-1](https://discourse.nodered.org/u/Guacamole-1)\
**Post date:** [17 October 2020 22:12 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432/1 "2020-10-17T22:12:27Z")

</div>

hi, im new to node red and i would like to know if the http nodes are secure if exposed to the internet?  
is it secure if i have a simple website with node exposed to the internet?

---

<div class="post-metadata">

**Author:** ![michaelblight](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/michaelblight/32/445_2.png) [@michaelblight](https://discourse.nodered.org/u/michaelblight)\
**Post date:** [18 October 2020 01:48 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432/2 "2020-10-18T01:48:00Z")

</div>

You can put NR behind a reverse proxy (eg. NGINX) and use SSL, or configure NR to use SSL (see [https://notenoughtech.com/home-automation/how-to-add-ssl-certification-to-nodered/](https://notenoughtech.com/home-automation/how-to-add-ssl-certification-to-nodered/)). And I use `node-red-contrib-httpauth` for simple authentication.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 October 2020 16:40 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432/3 "2020-10-18T16:40:48Z")

</div>

Quick answer is that Node-RED is not secure without additional protection. This is not the "fault" of the http-in node nor of Node-RED, it is common amongst applications that provide microservices. They focus on what is important to them and assume that you will do whatever is needed in order to protect your services and devices.

As Michael says, one of the best approaches for protection is to use something like NGINX, HAproxy or Caddy to provide a reverse proxy and configured to provide HTTPS. You can also use it to take care of authentication too if you want to.

There are plenty of blog posts and articles that cover this.

---

<div class="post-metadata">

**Author:** ![ristomatti](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ristomatti/32/5857_2.png) [@ristomatti](https://discourse.nodered.org/u/ristomatti)\
**Post date:** [19 October 2020 13:29 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432/4 "2020-10-19T13:29:56Z")

</div>

I wonder if @Guacamole-1 meant if the http in nodes pose a risk for Node-RED compromise as such? Not necessarily if the data is transmitted securely/encrypted.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [19 October 2020 16:21 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432/5 "2020-10-19T16:21:26Z")

</div>

I personally would not want to separate those 2.

I don't _think_ that the http-in node represents any _more_ of a risk than Node-RED itself. After all, all it does is to use the existing ExpressJS server to set up an incoming path.

The point that I always try to get across is that Internet/web security is NEVER straight-forwards. It is always easier to get wrong than to get right simply because there are so many moving parts that have all to be correctly configured. This shouldn't be a surprise in this day and age given the number of times - PER DAY - we see security compromises of web-based services.

That's why I nearly always recommend putting your security outside of Node-RED. It is generally easier to correctly configure separated systems doing specific tasks than trying to squeeze everything into a single, complex configuration. It also gives you options for defence-in-depth.

---

<div class="post-metadata">

**Author:** ![ristomatti](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ristomatti/32/5857_2.png) [@ristomatti](https://discourse.nodered.org/u/ristomatti)\
**Post date:** [19 October 2020 16:45 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432/6 "2020-10-19T16:45:33Z")

</div>

Mostly agree and of course without adding a proxy, you would also have to expose the admin endpoints which is not good either (unless disabling it from the settings).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [2 November 2020 16:45 UTC](https://discourse.nodered.org/t/is-http-node-secure/34432/7 "2020-11-02T16:45:43Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
