# OAuth works for the admin flow editor but maybe not the node dashboard httpNodeAuth?

**URL:** <https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695>\
**Category:** General\
**Tags:** security, dashboard-2\
**Created:** [4 December 2024 19:49 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695 "2024-12-04T19:49:20Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![HeneryH](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/heneryh/32/48986_2.png) [@HeneryH](https://discourse.nodered.org/u/HeneryH)\
**Post date:** [4 December 2024 19:49 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/1 "2024-12-04T19:49:20Z")

</div>

Is there really only a single hardcoded user available to protect the dashboard?

> **[Securing Node-RED : Node-RED](https://nodered.org/docs/user-guide/runtime/securing-node-red)**

### HTTP Node security

The routes exposed by the HTTP In nodes can be secured using basic authentication.

The `httpNodeAuth` property in your `settings.js` file can be used to define a single username and password that will be allowed to access the routes.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [4 December 2024 20:25 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/2 "2024-12-04T20:25:16Z")

</div>

Out of the box - yes (But I could be wrong here - docs don't suggest otherwise).

if it really is only 1:

You can employ a self-catered solution, using your own custom middleware, to do the authentication I think in `settings.js`

```auto
function Authenticate(req, res, next) {

    const authHeader = req.headers['authorization'];
    if (!authHeader) {
        return res.status(401).send('Authorization header missing');
    }

    const [scheme, credentials] = authHeader.split(' ');
    const decodedCredentials = Buffer.from(credentials, 'base64').toString('utf-8');
    const [username, password] = decodedCredentials.split(':');

    if (someCustomCheck(username, password)) {
        return next(); 
    } else {
        return res.status(401).send('Unauthorized');
    }
}

module.exports = {
   ...
   httpNodeMiddleware:Authenticate,
}

```

---

<div class="post-metadata">

**Author:** ![HeneryH](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/heneryh/32/48986_2.png) [@HeneryH](https://discourse.nodered.org/u/HeneryH)\
**Post date:** [4 December 2024 21:54 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/3 "2024-12-04T21:54:44Z")

</div>

That looks interesting but I found the root cause of my error. When talking about using external authenticators there are two distinct use cases....

- Protecting the Node-Red flow editor using native adminAuth in the settings.js file (doesn't protect the dashboards). This does not use a reverse-proxy with middleware.
- Protecting the Node-Red Dashboard 2.0 pages using the multi-tenant with auth pluig-in feature. This requires a reverse-proxy and middleware.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [4 December 2024 21:57 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/4 "2024-12-04T21:57:40Z")

</div>

Oh! D2 - I don't use it.  
(I have tagged `dashboard-2`) to highlight

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [6 December 2024 12:03 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/5 "2024-12-06T12:03:03Z")

</div>

The other option you have here is to use [FlowFuse](https://flowfuse.com/) if it's for professional/industrial use cases. Comes with multi-user security included in all your Node-RED instances and Dashboards.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [6 December 2024 12:44 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/6 "2024-12-06T12:44:28Z")

</div>

In my view, you will always be better off using an external proxy to handle authentications and user management. I would never recommend using Node-RED for that except for very simple, mostly home, use cases.

---

<div class="post-metadata">

**Author:** ![HeneryH](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/heneryh/32/48986_2.png) [@HeneryH](https://discourse.nodered.org/u/HeneryH)\
**Post date:** [6 December 2024 14:13 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/7 "2024-12-06T14:13:54Z")

</div>

Yeah. I think I have it now. The two different ways of using Authentik (native via authAdmin and Traefik-Middleware) had me confused a bit when I started. Also the ability in node red to change the editor root path to something other than "/" makes this easier.

Now I can use the Traefik reverse proxy with path rewriting to get me where dashboard users hitting ( Path(`/`) || PathPrefix(`/dashboard`) || PathPrefix(`/outpost`) ) ('outpost' being the auth urls) get sent to the dashboard with user auth  
and administrators wanting to edit the flows can use a newly defined editor path PathPrefix(`/editor`) can use an alternate auth scheme. This is currently using native authAdmin but I can switch it to Traefik pretty easily I think.

Using Dashboard 2 I even get access in NodeRed to the username who is authenticated which was the original real goal of this whole exercise. I wanted to log who did which button presses.

Thank you all for getting the noob up to speed!

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [6 December 2024 14:16 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/8 "2024-12-06T14:16:29Z")

</div>

> [@HeneryH](#):
>
> Using Dashboard 2 I even get access in NodeRed to the username who is authenticated

And when using UIBUILDER as well 😉

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [7 December 2024 07:44 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/9 "2024-12-07T07:44:38Z")

</div>

> [@HeneryH](#):
>
> Using Dashboard 2 I even get access in NodeRed to the username who is authenticated which was the original real goal of this whole exercise. I wanted to log who did which button presses

Yep, thats exactly the use case for the Dashboard 2.0 user plugins, and there is one available for Authentik if you've not already found it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [7 March 2025 07:44 UTC](https://discourse.nodered.org/t/oauth-works-for-the-admin-flow-editor-but-maybe-not-the-node-dashboard-httpnodeauth/93695/10 "2025-03-07T07:44:42Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
