# Node-red-contrib-jwt passing signing secret in via flow

**URL:** <https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247>\
**Category:** General\
**Created:** [2 March 2022 17:11 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247 "2022-03-02T17:11:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [2 March 2022 17:11 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247/1 "2022-03-02T17:11:14Z")

</div>

Hi.

I making a subflow that will incorporate [jwt verify](https://flows.nodered.org/node/node-red-contrib-jwt), I have a signing secret that normally would be added to the environment variables of the jwt verify node.

I have my own environment variable for my subflow with the signing secret but there does not seem an option to pass the secret in with the message object.

I can not set the environment variable in the flow. any ideas?

@chameleonbr

thanks  
Harry

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [2 March 2022 17:16 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247/2 "2022-03-02T17:16:08Z")

</div>

> [@HarryPottar](#):
>
> I can not set the environment variable in the flow. any ideas

Why not? Because of security reasons or you are unable to?

You should be able to use environment variables in the nodes secret field. Have you tried?

"Using environment variables : Node-RED" [Using environment variables : Node-RED](https://nodered.org/docs/user-guide/environment-variables#:~:text=Any%20node%20property%20can%20be,passing%20it%20to%20the%20node).

---

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [2 March 2022 17:23 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247/3 "2022-03-02T17:23:03Z")

</div>

You can only read environment variables, you can not set them dynamically. You can add them in your settings.js but this defeats the object of the subflow.

Harry

---

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [2 March 2022 18:32 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247/4 "2022-03-02T18:32:51Z")

</div>

I see looking at the github issue page that a few people had the same issue.

I ended up downloading the master branch and adding the feature myself.

In the function JwtVerify(n)

Before :

```auto
node.on('input', function (msg, send, done) {
            send = send || function() { node.send.apply(node,arguments) }
            done = done || function(err) { if(err)node.error(err, msg); }
            if (node.signvar === 'bearer') {

```

After:

```auto
node.on('input', function (msg, send, done) {
            send = send || function() { node.send.apply(node,arguments) }
            done = done || function(err) { if(err)node.error(err, msg); }
            
            if ( msg.secret !== undefined && !node.jwk) {
                node.secret = msg.secret;
            }
            if (node.signvar === 'bearer') {

```

repackage and added to my node-red  
Harry

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [2 March 2022 19:48 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247/5 "2022-03-02T19:48:21Z")

</div>

Hi.

That workaround is fine for your own use, but if you were to fork the repo and publish a Pull Request back to the source repo, I'd not recommend setting `node.secret` as any following `msg` without a `.secret` would end up using the previous `secret`.

The preferred pattern for providing a property via a msg is to either use a typedInput OR use a local variable and only if the field is left blank - something like this...

```auto
node.on('input', function (msg, send, done) {
            send = send || function() { node.send.apply(node,arguments) }
            done = done || function(err) { if(err)node.error(err, msg); }
            const secret = node.secret || msg.secret;
            if (node.signvar === 'bearer') {

```

---

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [2 March 2022 20:28 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247/6 "2022-03-02T20:28:34Z")

</div>

> [@Steve-Mcl](#):
>
> `const secret = node.secret || msg.secret;`

Good point and thanks for the advise.

I changed it to

```auto
node.secret = node.secret || msg.secret;

```

Again workaround is fine for internal use, incidentally I encapsulate a lot of routines into subroutines and make it a habit of cleaning up the message object before returning.

I use environmental variables and then delete them in a change node, so not to contaminate the msg going forward.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [16 March 2022 20:29 UTC](https://discourse.nodered.org/t/node-red-contrib-jwt-passing-signing-secret-in-via-flow/59247/7 "2022-03-16T20:29:23Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
