# Password is shown in context of node in plain text

**URL:** <https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007>\
**Category:** General\
**Created:** [11 June 2021 04:42 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007 "2021-06-11T04:42:58Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![kiran007](https://avatars.discourse-cdn.com/v4/letter/k/74df32/32.png) [@kiran007](https://discourse.nodered.org/u/kiran007)\
**Post date:** [11 June 2021 04:42 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/1 "2021-06-11T04:42:58Z")

</div>

I have a custom node which accepts username and password, if the user submits the details and click on node to view node info/content information then password field is displayed in clear text.  
please refer to the image

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/6/66430483bf03eb995ad3ca9cdb6316fb720e5443.png)

Any way to hide it ?

---

<div class="post-metadata">

**Author:** ![kiran007](https://avatars.discourse-cdn.com/v4/letter/k/74df32/32.png) [@kiran007](https://discourse.nodered.org/u/kiran007)\
**Post date:** [11 June 2021 04:46 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/2 "2021-06-11T04:46:46Z")

</div>

@knolleary

---

<div class="post-metadata">

**Author:** ![kiran007](https://avatars.discourse-cdn.com/v4/letter/k/74df32/32.png) [@kiran007](https://discourse.nodered.org/u/kiran007)\
**Post date:** [11 June 2021 05:22 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/3 "2021-06-11T05:22:58Z")

</div>

@craigcurtin

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [11 June 2021 05:25 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/4 "2021-06-11T05:25:44Z")

</div>

Probably should not annoy Nick on there sorts of things - we want to keep him busy on NR development !!

Did you write the custom node or is it someone elses you are using ? They would need to adapt the node to support some form of hashing/salting etc of the password and then store that on disk - its not something NR can do for a custom node

Craig

---

<div class="post-metadata">

**Author:** ![kiran007](https://avatars.discourse-cdn.com/v4/letter/k/74df32/32.png) [@kiran007](https://discourse.nodered.org/u/kiran007)\
**Post date:** [11 June 2021 05:32 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/5 "2021-06-11T05:32:25Z")

</div>

Sorry and thanks Craig for the information

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [11 June 2021 05:55 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/6 "2021-06-11T05:55:46Z")

</div>

@kiran007 as @craigcurtin says, please dont tag individuals into questions.

The node needs to identify the property as a credential. Node-RED will then store it in the credentials file and not expose it in the editor.

[https://nodered.org/docs/creating-nodes/credentials](https://nodered.org/docs/creating-nodes/credentials)

---

<div class="post-metadata">

**Author:** ![kiran007](https://avatars.discourse-cdn.com/v4/letter/k/74df32/32.png) [@kiran007](https://discourse.nodered.org/u/kiran007)\
**Post date:** [18 June 2021 06:58 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/7 "2021-06-18T06:58:55Z")

</div>

It just hides the password at export function but in context are its shown the password  
please refer to the image

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/7/574fe49b19224d3c28be14d6e71888ee4c43f970.png)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [18 June 2021 07:15 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/9 "2021-06-18T07:15:14Z")

</div>

That suggests you have a `credentials` property in the nodes `defaults` object. That is wrong. Check the docs I linked to.

---

<div class="post-metadata">

**Author:** ![kiran007](https://avatars.discourse-cdn.com/v4/letter/k/74df32/32.png) [@kiran007](https://discourse.nodered.org/u/kiran007)\
**Post date:** [18 June 2021 11:41 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/10 "2021-06-18T11:41:20Z")

</div>

> [@knolleary](#):
>
> at is wro

I did 3 steps as per your documentation

1. I added credential in default section of HTML file please refer the screenshot 1
2. in JS file added same please refer screenshot 2
3. HTML thing screenshot

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/6/76c144a5f23078db6f8f522cf9c16ef75181392c.png)  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/2/e22a0c9f29da6cd0f75b3f02da21063cd5eb4538.png)  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/d/bd99da089e1cb5ff35a8ec018f57c6e0b20b6677.png)

anything I miss?

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [18 June 2021 11:56 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/11 "2021-06-18T11:56:22Z")

</div>

it doesn't say add to defaults anywhere - it says " Add a new `credentials` entry to the node’s definition:" So in step 1 add them after defaults for example - not inside.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [2 July 2021 11:56 UTC](https://discourse.nodered.org/t/password-is-shown-in-context-of-node-in-plain-text/47007/12 "2021-07-02T11:56:29Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
