# Oauth2 login with only with gmail domain

**URL:** <https://discourse.nodered.org/t/oauth2-login-with-only-with-gmail-domain/89992>\
**Category:** General\
**Created:** [4 August 2024 20:58 UTC](https://discourse.nodered.org/t/oauth2-login-with-only-with-gmail-domain/89992 "2024-08-04T20:58:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marty1982](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marty1982/32/20162_2.png) [@Marty1982](https://discourse.nodered.org/u/Marty1982)\
**Post date:** [4 August 2024 20:58 UTC](https://discourse.nodered.org/t/oauth2-login-with-only-with-gmail-domain/89992/1 "2024-08-04T20:58:47Z")

</div>

Hi all!

I have a strange scenario where i want to integrate nodered login using oauth2 but only for gmail users and not another google domain.

In the following code, i'm checking if the email address is from gmail and then fill in the empty array that is declared outside the "modules" block.  
Then the array is used in the "users" block. But is not working.

```auto
// declare the empty users arrays...
let users = [];

module.exports = {
//.....following code....

   adminAuth: {
        type: "strategy",
        strategy: {
            name: "google",
            label: 'Sign in with Google',
            icon: "fa-google",
            strategy: require("passport-google-oauth20").Strategy,
            options: {
                clientID: "xxxxxxxxx",
                clientSecret: "xxxxxxxxxxxxx",
                callbackURL: "http://localhost:1880/auth/strategy/callback",
                scope: ['profile', 'email'],

                verify: function (token, tokenSecret, profile, done) {
                    profile.username = profile.emails.find(x => x.verified).value;

                    const getUsernameEmail = profile.username;

                    console.log('Username:', getUsernameEmail);

                    if (getUsernameEmail.includes('@gmail.com')) {
                        console.log('The email address is from gmail.com');
                    }

                    if (!users.some(user => user.username === getUsernameEmail)) {
                        users.push({ username: getUsernameEmail, permissions: ["*"] });
                    }

                    console.log('Users array:', users);

                      return done(null, profile)
                }
            }
        },
        users: users

```

The output is:

```auto
The email address is from gmail.com
Users array: [{ username: 'lalala@gmail.com', permissions: [ '*'] } ]

```

Ok, but i have the following UI message:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/e/ee7af2e9c3bf2b1b01ea677df586288a33965fff.png)

What i'm missing here?.

If i hardcode the "users" block like this it works fine.

```auto
users: [
             { username: 'lalala@gmail.com', permissions: ["*"] },
             { username: "usuario2@gmail.com", permissions: ["read"] }
         ]

```

The main goal is to only allow a certain domain.  
Other ideas if how to implement this?.

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [8 August 2024 08:23 UTC](https://discourse.nodered.org/t/oauth2-login-with-only-with-gmail-domain/89992/3 "2024-08-08T08:23:19Z")

</div>

Hi @Marty1982

A bit of a guess on my part, but try removing the `return` keyword at the end of your verify function - just call `done(....)` without returning it

---

<div class="post-metadata">

**Author:** ![Marty1982](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marty1982/32/20162_2.png) [@Marty1982](https://discourse.nodered.org/u/Marty1982)\
**Post date:** [8 August 2024 13:34 UTC](https://discourse.nodered.org/t/oauth2-login-with-only-with-gmail-domain/89992/4 "2024-08-08T13:34:04Z")

</div>

HI @knolleary Thanks for the reply.

If i do that the login screen get in blank. Like if it get waiting for something to happend.  
I could solved it adding this block:

```auto
users: function (varName) {
            return new Promise(function (resolve) {
                resolve({ username: varName, permissions: "*" });
            })

```

This block logs in the @gmail.com user (without the profile picture ☹ ) and works fine.

Either way...I will go for "hardcoded" users, i decided that is the best approach by now.

Maybe i'm thinking that Passport-google-oauth20 is not the best option to have and should another passport strategy....

Regards!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [6 November 2024 13:34 UTC](https://discourse.nodered.org/t/oauth2-login-with-only-with-gmail-domain/89992/5 "2024-11-06T13:34:51Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
