# Issue with Custom Middleware Not Blocking Access to Dashboard

**URL:** <https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919>\
**Category:** Dashboard\
**Tags:** dashboard-2\
**Created:** [12 September 2024 15:46 UTC](https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919 "2024-09-12T15:46:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DhamodharanGopal](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dhamodharangopal/32/95512_2.png) [@DhamodharanGopal](https://discourse.nodered.org/u/DhamodharanGopal)\
**Post date:** [12 September 2024 15:46 UTC](https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919/1 "2024-09-12T15:46:11Z")

</div>

I'm encountering an issue with custom middleware in ui\_base.js not properly enforcing session validation before serving the dashboard page. Despite setting up the middleware to check for a valid user session, users are still able to access the dashboard page directly without being redirected to the login page if they don't have a valid session.

```auto
const cookieParser = require('cookie-parser'); // Parse the cookie from headers

// Cookie parsing Middleware
uiShared.app.use(cookieParser());

// Middleware to check logged in user session
function checkSession(req, res, next) {
    const sessionId = req.cookies['sessionId']; // session ID is stored in a cookie
    const userSession = global.get(sessionId); // Sessions from global context

    // Validate the session
    if (userSession && userSession[sessionId]) {
        // If session is valid, continue to serve the dashboard
        next();
    } else {
        // If no session or invalid session, redirect to login
        res.redirect('http://localhost:1880/login/');
    }
}

// Serve dashboard with session validation
uiShared.app.get(config.path, uiShared.httpMiddleware, checkSession, (req, res) => {
    // Send the dashboard file only if session is valid
    res.sendFile(path.join(__dirname, '../../dist/index.html'));
});

```

Issue  
Even though `checkSession` middleware is placed before the route handler for the dashboard page, users are able to access the dashboard page directly without being redirected if they don't have a valid session.

Expected Behavior:  
Users without a valid session should be redirected to the login page, and the dashboard page should only be accessible if a valid session is present.

### Questions:

- Is there an issue with the way middleware is set up or ordered?
- How can I ensure that the middleware correctly enforces session validation before serving the dashboard page?

Any insights or suggestions would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 September 2024 16:39 UTC](https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919/2 "2024-09-12T16:39:07Z")

</div>

Have you added logging to check whether your code is called?

---

<div class="post-metadata">

**Author:** ![DhamodharanGopal](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dhamodharangopal/32/95512_2.png) [@DhamodharanGopal](https://discourse.nodered.org/u/DhamodharanGopal)\
**Post date:** [12 September 2024 17:08 UTC](https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919/3 "2024-09-12T17:08:23Z")

</div>

- Thanks for the response !.
- I have added logging for the global context, but it does not appear in the server console.
- Could you please clarify if it is possible to use the global context values within the Express middleware in ui\_base.js?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [13 September 2024 14:36 UTC](https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919/4 "2024-09-13T14:36:46Z")

</div>

> [@DhamodharanGopal](#):
>
> I have added logging for the global context,

I don't know what you mean by that. Can you not log to the console in middleware?

---

<div class="post-metadata">

**Author:** ![DhamodharanGopal](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dhamodharangopal/32/95512_2.png) [@DhamodharanGopal](https://discourse.nodered.org/u/DhamodharanGopal)\
**Post date:** [13 September 2024 14:58 UTC](https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919/5 "2024-09-13T14:58:34Z")

</div>

- I apologize for the confusion earlier.
- I had mistakenly been making changes in the `/home/node-red` directory instead of the correct `./nodered/` location, which is why the log messages weren't appearing. After correcting this, I'm now successfully retrieving logs for the `ui base.js` file

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [13 October 2024 14:59 UTC](https://discourse.nodered.org/t/issue-with-custom-middleware-not-blocking-access-to-dashboard/90919/6 "2024-10-13T14:59:20Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
