# New node for HTTP Basic Auth

**URL:** <https://discourse.nodered.org/t/new-node-for-http-basic-auth/82014>\
**Category:** Share Your Nodes\
**Created:** [13 October 2023 21:52 UTC](https://discourse.nodered.org/t/new-node-for-http-basic-auth/82014 "2023-10-13T21:52:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alkarex](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alkarex/32/24709_2.png) [@Alkarex](https://discourse.nodered.org/u/Alkarex)\
**Post date:** [13 October 2023 21:52 UTC](https://discourse.nodered.org/t/new-node-for-http-basic-auth/82014/1 "2023-10-13T21:52:37Z")

</div>

Hello,  
The situation was messy for Basic HTTP Authentication for HTTP In, as some have noticed (e.g. [HTTP Auth node is obsolete](https://discourse.nodered.org/t/http-auth-node-is-obsolete/74272) , but the topic is closed), with several abandoned nodes, several forks, and pending pull requests.

Here is a new node, which is the result of the fusion:

> **[@alexandrainst/node-red-http-basic-auth](https://flows.nodered.org/node/@alexandrainst/node-red-http-basic-auth)**
>
> Node-RED node for HTTP Basic Authorization

I have made an honest effort to merge several nodes and their forks and some of their pending PRs back into one. So all the features should be there, though sometimes with some modifications. This includes the support of multiple credentials, and a second output for logging failed authentications.

The node has also been modernised, allowing in particular the storage of passwords using bcrypt in addition to the previous only option of plain-text, as well as compatibility with Apache htpasswd format.

Tests and feedback welcome. Repository: [GitHub - alexandrainst/node-red-http-basic-auth: Node-RED node for HTTP Basic Auth](https://github.com/alexandrainst/node-red-http-basic-auth)  
Enjoy!

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/9/19c7380c8be1ec688dc5158675632eeb22c2c39b.png)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [13 October 2023 22:36 UTC](https://discourse.nodered.org/t/new-node-for-http-basic-auth/82014/2 "2023-10-13T22:36:51Z")

</div>

Thanks for bringing things together like that. One thing, sorry, I've not read your documentation but it is important to tell people to use HTTP **S** for any authentication. So if that isn't in your docs, it really should be there.
