# Node-red login with google oauth2.0 help

**URL:** <https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927>\
**Category:** General\
**Created:** [16 November 2023 14:34 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927 "2023-11-16T14:34:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ArcanePhysics](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/arcanephysics/32/84910_2.png) [@ArcanePhysics](https://discourse.nodered.org/u/ArcanePhysics)\
**Post date:** [16 November 2023 14:34 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927/1 "2023-11-16T14:34:52Z")

</div>

Hello,

I am, trying to set up my node-red with google oauth login

Following this page [Securing Node-RED : Node-RED](https://nodered.org/docs/user-guide/runtime/securing-node-red)  
section OAuth/OpenID based authentication

I have installed passport-google-oauth20 and filled the config as follows

```auto
    adminAuth: {
        type: "strategy",
        strategy: {
            name: "google",
            label: "Sign in with Google",
            icon: "fa-google",
            strategy: require("passport-google-oauth20").Strategy,
            options: {
                clientID: "myClientId",
                clientSecret: "myClientSecret",
                callbackURL: "https://host/node-red/auth/strategy/callback",
                verify: function(accessToken, refreshToken, profile, done) {
                    done(null, profile);
                }
            },
        },

```

I get node-red to boot and the page with auth with google button is displayed  
however as I press the button I get error in image (no scope)

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/a/9a23344b0068a87bdd62af2e6580961e970c3cee.png)

I gather function below does not request the scope

```auto
app.get('/auth/google', 
  passport.authenticate('google', { scope : ['profile'] }));

```

but I do not understand where in config I should put it.

Am I doing something wrong?

Appreciate any help,  
ArcanePhysics

---

<div class="post-metadata">

**Author:** ![ArcanePhysics](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/arcanephysics/32/84910_2.png) [@ArcanePhysics](https://discourse.nodered.org/u/ArcanePhysics)\
**Post date:** [16 November 2023 16:38 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927/2 "2023-11-16T16:38:46Z")

</div>

Update: I have changed from passport-google-oauth20 to passport-google-oidc and managed to authenticate with google.

However I have encountered a new issue:  
my node-red is published to internet with /node-red/ path

so the address for interface is [https://domain/node-red/](https://domain/node-red/)  
and callback url is set as [https://domain/node-red/auth/strategy/callback](https://domain/node-red/auth/strategy/callback)

However after authentication I am redirected to root domain/ instead of domain/node-red/ and the process breaks

Any advice on how to proceed?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![ArcanePhysics](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/arcanephysics/32/84910_2.png) [@ArcanePhysics](https://discourse.nodered.org/u/ArcanePhysics)\
**Post date:** [16 November 2023 17:40 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927/3 "2023-11-16T17:40:11Z")

</div>

Update 2:

I have changed the **httpAdminRoot** property to "/node-red" in **settings.js** and then pointed **Nginx** to **:1880/node-red**

That solved the redirecting issue.

The final problem was **that passport-google-oidc** profile does not include **username**. In fact it includes only **id** , so I had to write a function to check for my **id** and append **username**.

Not a very elegant solution.

Hopefully, someone can help me to get **passport-google-oauth20** working (see OP).

---

<div class="post-metadata">

**Author:** ![Vevenus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/vevenus/32/84966_2.png) [@Vevenus](https://discourse.nodered.org/u/Vevenus)\
**Post date:** [18 November 2023 09:53 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927/4 "2023-11-18T09:53:20Z")

</div>

Had the same problem. Could not get google oauth 2.0 to work with node-red authorization.

Anybody got it to work?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [18 November 2023 10:02 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927/5 "2023-11-18T10:02:53Z")

</div>

> [@Vevenus](#):
>
> Could not get google oauth 2.0 to work

There are a couple of solutions right here in the forum found by searching "passport-google-oauth20"

> [@Help needed for 2FA with Authy](https://discourse.nodered.org/t/help-needed-for-2fa-with-authy/62764/7):
>
> Ok, that is what I did. In my [Google console project dashboard](https://console.cloud.google.com/home/dashboard) I have first configured the OAuth consent screen. First step: User Type: external. Saved and moved to the next step. Selected my email from the menu, filled the Authorized domains and Developer contact information, saved and moved to the next step. Added the scopes. In the Manually add scopes field I wrote email. Saved and moved to the last step. …

> [@Google OAuth2 issues](https://discourse.nodered.org/t/google-oauth2-issues/3489/10):
>
> I managed to get something that seems to be working. adminAuth: { type:"strategy", strategy: { name: "google", label: 'Sign in with Google', icon:"fa-google", strategy: require("passport-google-oauth20").Strategy, options: { clientID: "myId", clientSecret: "mySecret", scope: "email", callbackURL: "http://my-node-url.com/auth/strategy/callback", verify: function(token, tokenSecret, profile…

---

<div class="post-metadata">

**Author:** ![ArcanePhysics](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/arcanephysics/32/84910_2.png) [@ArcanePhysics](https://discourse.nodered.org/u/ArcanePhysics)\
**Post date:** [18 November 2023 10:37 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927/6 "2023-11-18T10:37:16Z")

</div>

Hey this is great. Thank you so much! The second link solved the problem!

For posterity this is the correct config:

```auto
adminAuth: {
        type: "strategy",
        strategy: {
            name: "google",
            label: "Sign in with Google",
            icon: "fa-google",
            strategy: require("passport-google-oauth20").Strategy,
            options: {
                clientID: "ENTER ID HERE",
                clientSecret: "ENTER SECRET HERE",
                callbackURL: "https://HOST HERE/auth/strategy/callback",
                scope: ["profile", "email"],
                verify: function(accessToken, refreshToken, profile, done) {
                    if(profile.emails) {
                        profile.username = profile.emails[0].value;
                    }
                    done(null, profile);
                }
            },
        },
        users: [
           { username: "USER EMAIL HERE", permissions: ["*"]}
        ]
    },

```

you **MUST** add **scope** to options obj.  
scope can be a string

```auto
scope: "profile",

```

or array of strings

```auto
scope: ["profile", "email"],

```

Then, you have to add **username** to **profile** obj to validate against **users** array below

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [2 December 2023 10:38 UTC](https://discourse.nodered.org/t/node-red-login-with-google-oauth2-0-help/82927/7 "2023-12-02T10:38:01Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
