# Omrid01/node-red-dashboard-2-table-tabulator with Authelia

**URL:** <https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777>\
**Category:** Dashboard\
**Tags:** dashboard-2\
**Created:** [21 January 2025 10:59 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777 "2025-01-21T10:59:40Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![PeterH](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@PeterH](https://discourse.nodered.org/u/PeterH)\
**Post date:** [21 January 2025 10:59 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/1 "2025-01-21T10:59:40Z")

</div>

I have set up Node red with Authelia and noticed two issues with the table-Tabulator ui-node.

**Setting up access via URL-rules (resources) in Authelia:**  
In general, (as far as I have seen) resources for the dashboard client are downloaded via the _base dashboard-url_ (regex): ^/dashboard/.\*  
(e.g. /dashboard/socket.io/?EIO=4&transport=polling&t=PI7xerP)

Tabulator however requests the following resource:  
‘/_admin_/resources/@omrid01/node-red-dashboard-2-table-tabulator/ui-tabulator.umd.js’  
which is via the _base editor-url_ (set to "admin" in my Nodered setup):

Could it be changed to:  
'/_dashboard_/resources/@omrid01/node-red-dashboard-2-table-tabulator/ui-tabulator.umd.js’

This makes is easier to set the rules in Authelia when some users should have access to the dashboard only.

**Missing user object in msg.\_client**  
I have also installed the @aikitori/node-red-dashboard-2-authelia-auth plugin which extends message from the dashboard nodes with a user object under msg.\_client (i.e. msg.\_client.user) which contain information about the authenticated user in Authelia. I have tested this with some of the “build-in” dashboard 2 ui-nodes which works, but the object is not included in messages from the Tabulator node.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [21 January 2025 13:55 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/2 "2025-01-21T13:55:17Z")

</div>

Good spot. I don't believe any of the Dashboard resources should be coming from the admin route and indeed, in some config's Dashboard users would not have permissions to access that route I don't think.

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [21 January 2025 18:56 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/3 "2025-01-21T18:56:45Z")

</div>

With regards to the location of `ui-tabulator.umd.js`, I have been using the dashboard-2 framework as-is, building on top of the `ui-example` prototype (from @joepavitt).

Same goes for adding a user object - I was under the impression it is handled by the framework, transparent to the node.

I'm willing to update the node, if someone could advise how, or point me to relevant documentation.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [21 January 2025 20:30 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/4 "2025-01-21T20:30:18Z")

</div>

I'm not sure how Dashboard 2 works but would expect it to either automatically add a suitable user-facing route for your D2 node or instruct you how to add your own.

Node-RED creates 2 ExpressJS apps. One for the Editor and other admin endpoints and one for user-facing endpoints such as http-in/-response, D1, D2, etc. UIBUILDER adds routes to both (or creates another if you ask it to).

Each of the ExpressJS apps have separate settings.

`RED.httpAdmin` and `RED.server`

---

<div class="post-metadata">

**Author:** ![PeterH](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@PeterH](https://discourse.nodered.org/u/PeterH)\
**Post date:** [22 January 2025 08:24 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/5 "2025-01-22T08:24:14Z")

</div>

Regarding the last issue with the missing user object, I can add that I have also tried with another "3rd-party" ui-node: @cgjgh/node-red-dashboard-2-ui-scheduler which works in that respect.

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [22 January 2025 12:27 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/6 "2025-01-22T12:27:30Z")

</div>

is the first issue you mentioned (web resources location) also happening with the custom dashboard-2 node?

Re the missing user object, I understand the issue is with `ui-tabulator` output commands. It may be related to the fact that `ui-tabulator` widgets send messages in a non-standard way (there's a good reason behind this).

what is the type of the `ui-tabulator` output msg in which the user object is missing:

- Response to a message originated by a dashboard element (e.g. button)?
- Response to a message originated by a server node (e.g. _inject_, _function_)?
- A `ui-tabulator` notification (e.g. cell clicked, row changed etc.)?

---

<div class="post-metadata">

**Author:** ![joepavitt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/joepavitt/32/59722_2.png) [@joepavitt](https://discourse.nodered.org/u/joepavitt)\
**Post date:** [22 January 2025 13:12 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/7 "2025-01-22T13:12:04Z")

</div>

> [@omrid](#):
>
> Same goes for adding a user object - I was under the impression it is handled by the framework, transparent to the node.

Yes, it should be auto-appended, but can investigate as to why it may nt for the tabulator node.

---

<div class="post-metadata">

**Author:** ![PeterH](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@PeterH](https://discourse.nodered.org/u/PeterH)\
**Post date:** [22 January 2025 13:22 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/8 "2025-01-22T13:22:10Z")

</div>

**First issue:**  
Actually yes it does:  
/admin/resources/@cgjgh/node-red-dashboard-2-ui-scheduler/ui-scheduler.umd.js

**Second issue:**  
It is only the last one in your list: notifications from the ui-tablulator element where the user object is missing.  
The user object is not relevant for messages originating fro the server-side, I guess.  
The buttons I tried works. But these are "built-in" ui-nodes. There is no other nodes than the tabulator node i your package?

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [22 January 2025 17:24 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/9 "2025-01-22T17:24:13Z")

</div>

> [@PeterH](#):
>
> It is only the last one in your list: notifications from the ui-tablulator element where the user object is missing.

In `ui-tabulator` notifications, I am currently appending a `_client` object with a `socketId` property. This may be unnecessary, if the framework is doing this automatically. Moreover, maybe _because_ the framework sees a `_client` object, it lets it go and does not enrich it with a user object.

I will see what happens when I don't add a `_client`. Is there a way I can test your plug-in in my development environment?

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [23 January 2025 09:33 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/10 "2025-01-23T09:33:33Z")

</div>

OK. I see that when a widget emits notifications to the standard `widget-action` handler, the framework adds the `_client` object automatically, hence I assume it will include the user object.

The `ui-tabulator` widget notifications do not require the special (de-duplication) treatment used for message responses, so I will simply send them trough `widget-action` which will solve the issue.

As for message responses (which are sent through a custom handler), there is no need for any change, since:

- Responses to server-originated messages do not (and should not) have client information
- Responses to client-originated messages retain the `_customer` object from the input message

I will implement this in the next node release

---

<div class="post-metadata">

**Author:** ![PeterH](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@PeterH](https://discourse.nodered.org/u/PeterH)\
**Post date:** [23 January 2025 10:03 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/11 "2025-01-23T10:03:27Z")

</div>

> [@omrid](#):
>
> I will see what happens when I don't add a `_client`. Is there a way I can test your plug-in in my development environment?

The @aikitori/node-red-dashboard-2-authelia-auth plugin requires the Nodered instance to be behind a proxy with Authelia to function properly, I think. I have this setup in my test environment so please let me know if I can test anything for you.  
Should I register it as an issue on the Github repository?

Regarding the first issue with "admin urls". I installed a couple of other "3rd-party" ui-node and its all the same:  
/admin/resources/@omrid01/node-red-dashboard-2-table-tabulator/ui-tabulator.umd.js  
/admin/resources/@cgjgh/node-red-dashboard-2-ui-scheduler/ui-scheduler.umd.js  
/admin/resources/@hotnipi/node-red-dashboard-2-ui-edgewise-meter/ui-edgewise-meter.umd.js  
/admin/resources/@colinl/node-red-dashboard-2-ui-gauge-classic/ui-gauge-classic.umd.js

So this is rather a framework issue, I suppose?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [23 January 2025 13:14 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/13 "2025-01-23T13:14:35Z")

</div>

Confirming that 3rd-party D2 components appear to be loading their JS from my Node-RED admin route not from the user route.

---

<div class="post-metadata">

**Author:** ![omrid](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@omrid](https://discourse.nodered.org/u/omrid)\
**Post date:** [26 January 2025 17:48 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/14 "2025-01-26T17:48:00Z")

</div>

> [@omrid](#):
>
> I will see what happens when I don't add a `_client`. Is there a way I can test your plug-in in my development environment?

I have just released v0.6.4, now the notifications take the client object from the framework, I assume it shall include the user object and solve the issue.

---

<div class="post-metadata">

**Author:** ![PeterH](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@PeterH](https://discourse.nodered.org/u/PeterH)\
**Post date:** [27 January 2025 09:33 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/15 "2025-01-27T09:33:08Z")

</div>

Super, thank you!  
I have updated and now the user object is included..

---

<div class="post-metadata">

**Author:** ![PeterH](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@PeterH](https://discourse.nodered.org/u/PeterH)\
**Post date:** [27 January 2025 10:12 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/16 "2025-01-27T10:12:40Z")

</div>

> [@PeterH](#):
>
> Regarding the first issue with "admin urls". I installed a couple of other "3rd-party" ui-node and its all the same:  
> /admin/resources/@omrid01/node-red-dashboard-2-table-tabulator/ui-tabulator.umd.js  
> /admin/resources/@cgjgh/node-red-dashboard-2-ui-scheduler/ui-scheduler.umd.js  
> /admin/resources/@hotnipi/node-red-dashboard-2-ui-edgewise-meter/ui-edgewise-meter.umd.js  
> /admin/resources/@colinl/node-red-dashboard-2-ui-gauge-classic/ui-gauge-classic.umd.js
> 
> So this is rather a framework issue, I suppose?

@joepavitt should I register an issue on github for this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [26 February 2025 10:13 UTC](https://discourse.nodered.org/t/omrid01-node-red-dashboard-2-table-tabulator-with-authelia/94777/17 "2025-02-26T10:13:36Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
