# Node-red-node-dropbox token expiration

**URL:** https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008
**Category:** General
**Created:** [12 July 2022 15:21 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008 "2022-07-12T15:21:34Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [12 July 2022 15:21 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/1 "2022-07-12T15:21:34Z")

</div>

Since the Dropbox API was changed about a year ago, users have found that they need to continually apply for new tokens for the node Auth to work.  
This topic is to discuss the issue, and try and find a resolution to restore functionality.

---

<div class="post-metadata">

### Author: ![krambriw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/krambriw/32/5429_2.png) [@krambriw](https://discourse.nodered.org/u/krambriw)
#### Post date: [11 July 2022 09:05 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/2 "2022-07-11T09:05:02Z")

</div>

I dropped dropbox and instead use a ssd drive on my home network. It is acceptable safety level for me, only problem if the house would burn down (but then problems with a slightly different magnitude would call for higher priority anyway)

---

<div class="post-metadata">

### Author: ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)
#### Post date: [11 July 2022 10:45 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/3 "2022-07-11T10:45:36Z")

</div>

> [@krambriw](#):
>
> use a ssd drive on my home network

Don't leave it permanently connected. A nearby lightning strike can take out multiple devices on a network.

---

<div class="post-metadata">

### Author: ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)
#### Post date: [11 July 2022 10:49 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/4 "2022-07-11T10:49:00Z")

</div>

> [@node-RED Backup Flow](https://discourse.nodered.org/t/node-red-backup-flow/25033/32):
>
> Microsoft have full access to all your code

I thought Microsoft's privacy policy guarantees they will not look at private repositories. If so then, if it were shown that they had been looking, there would be a big fuss and legal suits I think.

---

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [11 July 2022 11:08 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/5 "2022-07-11T11:08:25Z")

</div>

@hardillb - Ben, you did a PR about a year ago for the Dropbox node, was the purpose of that to deal with short-term tokens, as I see that you mention it in the node's amended node tip.

---

<div class="post-metadata">

### Author: ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)
#### Post date: [11 July 2022 11:36 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/6 "2022-07-11T11:36:11Z")

</div>

🤷‍♂️ you exepect me to remember something longer ago than last week?

Do you have a link to a PR/merge?

---

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [11 July 2022 11:38 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/7 "2022-07-11T11:38:47Z")

</div>

> <https://github.com/node-red/node-red-web-nodes/pull/284>
>
> Also fixes #283
> 
> \<!--
> \## Before you hit that Submit button....
> 
> Please read… our \[contribution guidelines\](https://github.com/node-red/node-red-nodes/blob/master/CONTRIBUTING.md)
> before submitting a pull-request.
> 
> \## Types of changes
> 
> What types of changes does your code introduce?
> Put an \`x\` in the boxes that apply
> \--\>
> 
> \- \[x\] Bugfix (non-breaking change which fixes an issue)
> \- \[\] New feature (non-breaking change which adds functionality)
> 
> \<!--
> If you want to raise a pull-request with a new feature, or a refactoring
> of existing code, it \*\*may well get rejected\*\* if it hasn't been discussed on
> the \[mailing list\](https://groups.google.com/forum/#!forum/node-red) or
> \[slack team\](https://nodered.org/slack) first.
> 
> \--\>
> 
> \## Proposed changes
> 
> 
> 
> \## Checklist
> 
> 
> \- \[x\] I have read the \[contribution guidelines\](https://github.com/node-red/node-red-nodes/blob/master/CONTRIBUTING.md)
> \- \[\] For non-bugfix PRs, I have discussed this change on the forum/slack team.
> \- \[x\] I have run \`grunt\` to verify the unit tests pass
> \- \[\] I have added suitable unit tests to cover the new/changed functionality

---

<div class="post-metadata">

### Author: ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)
#### Post date: [11 July 2022 11:47 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/8 "2022-07-11T11:47:48Z")

</div>

Looks like the code got merged, but never published to npm (@dceejay can you publish it please)

Other than that, if dropbox have changed things again then somebody will need to step up and propose a PR to fix it as I don't use the node and don't have the bandwidth to fix/test at the moment.

---

<div class="post-metadata">

### Author: ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)
#### Post date: [11 July 2022 11:51 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/9 "2022-07-11T11:51:59Z")

</div>

done to that level

---

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [11 July 2022 12:35 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/10 "2022-07-11T12:35:48Z")

</div>

> [@hardillb](#):
>
> Looks like the code got merged, but never published to npm

Yes, that's what I thought, thanks.

@FSHelgeland @DiverRich could you update your Dropbox node's to v1.1.0 and try again pls.

---

<div class="post-metadata">

### Author: ![FSHelgeland](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fshelgeland/32/64260_2.png) [@FSHelgeland](https://discourse.nodered.org/u/FSHelgeland)
#### Post date: [11 July 2022 13:52 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/11 "2022-07-11T13:52:44Z")

</div>

I will have a go.

---

<div class="post-metadata">

### Author: ![DiverRich](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/diverrich/32/64523_2.png) [@DiverRich](https://discourse.nodered.org/u/DiverRich)
#### Post date: [11 July 2022 16:54 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/12 "2022-07-11T16:54:23Z")

</div>

Updated. I won't know for sure if the token stayed active until tomorrow. Unless there is another way to check that you'd like me to try.

---

<div class="post-metadata">

### Author: ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)
#### Post date: [11 July 2022 23:50 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/13 "2022-07-11T23:50:28Z")

</div>

> [@Colin](#):
>
> I thought Microsoft's privacy policy guarantees they will not look at private repositories. If so then, if it were shown that they had been looking, there would be a big fuss and legal suits I think.

Not sure about that one - but there is a huge stink in the open source community at the moment about it as the Microsoft Copilot siphons code from within Github and includes it (with no attribution)

[https://github.com/features/copilot](https://github.com/features/copilot)

Craig

---

<div class="post-metadata">

### Author: ![DiverRich](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/diverrich/32/64523_2.png) [@DiverRich](https://discourse.nodered.org/u/DiverRich)
#### Post date: [12 July 2022 08:37 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/15 "2022-07-12T08:37:17Z")

</div>

@Paul-Reed, unfortunately it didn't retain the token.

---

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [12 July 2022 11:49 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/16 "2022-07-12T11:49:49Z")

</div>

Let's see how it works out for Freddy.

I can't test, or try things at the moment as I'm on holiday, and working from my phone, but I'll give it some attention when I return home.

---

<div class="post-metadata">

### Author: ![FSHelgeland](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fshelgeland/32/64260_2.png) [@FSHelgeland](https://discourse.nodered.org/u/FSHelgeland)
#### Post date: [12 July 2022 11:59 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/17 "2022-07-12T11:59:44Z")

</div>

@Paul-Reed sorry to inform you that it did not work here either. Dropbox only provides short-lived tokens now so we probably have to do something with Oauth.

---

<div class="post-metadata">

### Author: ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)
#### Post date: [12 July 2022 13:06 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/18 "2022-07-12T13:06:09Z")

</div>

Looking at the changes that were introduced in the latest node version, if you go to 'Add new Dropbox config' in the Dropbox node, you will note that the bottom paragraph was amended to be:  
"On the subsequent page, **click the button to ensure the token does not expire** , then generated an access token. Copy it into the box above."

Did you create a new config & follow that paragraph, or used your existing configs?

 ![Screenshot_20220712-145454](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/9/09653f0ce93b1d337f2ee66b97740852fda0ca9a.png)

---

<div class="post-metadata">

### Author: ![FSHelgeland](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fshelgeland/32/64260_2.png) [@FSHelgeland](https://discourse.nodered.org/u/FSHelgeland)
#### Post date: [12 July 2022 14:05 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/19 "2022-07-12T14:05:34Z")

</div>

I did not follow your recipe, will try now.

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [12 July 2022 16:59 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/20 "2022-07-12T16:59:01Z")

</div>

I've had direct dealings with Microsoft security and with their UK CISO and I can tell you that while the central support teams CAN access your data, it is extremely tightly controlled. Their processes ensure that only a direct customer request will be considered and that support personnel are only given access for a very limited period.

As Colin implies, their big cash-cows are large enterprises and governments, they are not about to risk that looking at your or my personal data.

But if you are really worried, the fix is very simple - pre-encrypt the data. If you have a backup script, add a local encryption step to it.

Oh, and if you think that Dropbox has better security than Microsoft's infrastructure - hmm, well I have an e-lock I'd like to sell you 🙂

---

<div class="post-metadata">

### Author: ![DiverRich](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/diverrich/32/64523_2.png) [@DiverRich](https://discourse.nodered.org/u/DiverRich)
#### Post date: [12 July 2022 21:01 UTC](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008/21 "2022-07-12T21:01:12Z")

</div>

Perhaps I've found the issue. What I see in the dropbox developer app console doesn't match your instructions. Specifically, item #2 just isn't a thing. Nowhere can I select 'Dropbox API app." I am able to create an app and set permissions and generate a token, but there is also no option on the subsequent page to click any button related to the token. The subsequent page is all about app permissions. I assume I'm missing something obvious (which is often the case when it comes to these matters.)

 ![Screenshot 2022-07-12 at 1.58.17 PM](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/3/c3c0c399343a982383ad2ab81a6191a8a07200ee.png)

[Next page](https://discourse.nodered.org/t/node-red-node-dropbox-token-expiration/65008.md?page=2)
