# Projects, github, ssh and basic-auth deprecation

**URL:** <https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557>\
**Category:** General\
**Created:** [22 April 2021 15:33 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557 "2021-04-22T15:33:12Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [22 April 2021 15:33 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/1 "2021-04-22T15:33:12Z")

</div>

I've seen a few threads here about similar topics but they seem to be timed out or not exactly what I want to figure out.

I connected my nodered instance to a remote github repository about a year ago and used it without an ssh key.

I now created a new ssh key in nodered settings \> Git config.

I then did another little change to my flows, deployed, committed to local repository and then pushed to remote.  
=\> I got the little popup for github user authentication with user and password.

I did another little change to my flows, deployed, committed to local repository and pushed to remote.  
=\> no little popup for github user authentication.

I'm now not sure whether nodered ever started using the new ssh key to connect to github, or whether it's still using basic auth despite my having added an ssh key.

I guess I'm asking:

1. How do I know whether nodered is connecting to github via ssh key?
2. How can I force nodered to connect with ssh key?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [22 April 2021 21:25 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/2 "2021-04-22T21:25:32Z")

</div>

To force the use of an SSH key, I believe that you have to clone your repos using the SSH URI instead of the HTTPS one. If you use HTTPS, you will be using OAuth tokens. That is why you see the login page once.

This page may be helpful: [GitHub’s Move Away From Passwords: A Sign Of Things To Come? | Hackaday](https://hackaday.com/2020/09/15/githubs-move-away-from-passwords-a-sign-of-things-to-come/)

While you are thinking about GitHub security, I strongly urge you to turn on 2FA for your GitHub account as well if you haven't already.

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 10:11 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/3 "2021-04-23T10:11:54Z")

</div>

Thanks for this valuable little insight!

I just deleted the old remote repository from project settings and tried adding the ssh URI instead.

Then I go to Project History, Commit history, click on the arrows ("Manage remote branch") and see "Remote: None"

I click on "Remote: None", assuming it will show me my newly added ssh-connection, but it just stays in the progress bar/waiting thingy.

any ideas?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [23 April 2021 12:24 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/4 "2021-04-23T12:24:38Z")

</div>

I guess you have to add an upstream repo. I'm not terribly familiar with all that I'm afraid, my git-foo is pretty basic 🙂

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 12:46 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/5 "2021-04-23T12:46:21Z")

</div>

Well that's what I'm trying to do but it never shows anything, instead just the Knightrider waiting gif thingy.

I'm now wondering if it's even possible to add a new remote repository (well actually the same one, just with a different mode-of-connecting) after the local repository already exists.

I'm not seeing any firewall activitiy or any nodered log entries that tell me anything is going wrong. But it never stops the knightrider-thing.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [23 April 2021 12:47 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/6 "2021-04-23T12:47:25Z")

</div>

> [@jadster](#):
>
> I'm now wondering if it's even possible to add a new remote repository (well actually the same one, just with a different mode-of-connecting) after the local repository already exists.

You can always add/change the upstream. That is one of the features of git.

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 12:47 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/7 "2021-04-23T12:47:59Z")

</div>

Yeah but does nodered support it?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [23 April 2021 12:48 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/8 "2021-04-23T12:48:45Z")

</div>

Node-RED only uses git under the hood, it doesn't handle anything itself.

And of course, I should have been saying "remote" rather than "upstream".

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 12:54 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/9 "2021-04-23T12:54:02Z")

</div>

I'm using the nodered UI so I have not idea what's happening between nodered and its under-the-hood git installation. (but I also have only a superficial understanding of git, so that doesn't help)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [23 April 2021 13:05 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/10 "2021-04-23T13:05:40Z")

</div>

You can add/remove remotes via the Node-RED Project Settings dialog as much as you like.

Can you open up the browser developer console (View-\>Developer-\>JavaScript Console on Chrome... other browsers have it somewhere...) and check for any error messages?

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 13:11 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/11 "2021-04-23T13:11:13Z")

</div>

how do I _always_ forget to do this?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/0/d0a7d0bbbb715cede09160e3597dec8c7809074e.jpeg)

any idea what this might be?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [23 April 2021 13:13 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/12 "2021-04-23T13:13:48Z")

</div>

It may be the case that its got into a slightly odd state with all the add/removing you've been trying.

Can you restart Node-RED on the server and then reload the editor - that'll get all of the internal state into a clean and consistent state.

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 13:14 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/13 "2021-04-23T13:14:36Z")

</div>

the screenshot was done right after a docker container restart.

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 13:15 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/14 "2021-04-23T13:15:31Z")

</div>

I'm running v1.0.2 in case that matters

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 13:18 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/15 "2021-04-23T13:18:58Z")

</div>

can you think of anything I need to worry about when upgrading from 1.0.2 to the latest version? (I've done it before with my current docker-compose setup with the /data in its own volume, so I'm assuming it'll work as smooth as ever?)

---

<div class="post-metadata">

**Author:** ![jadster](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jadster/32/40585_2.png) [@jadster](https://discourse.nodered.org/u/jadster)\
**Post date:** [23 April 2021 14:05 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/16 "2021-04-23T14:05:35Z")

</div>

Well I updated to 1.3.3.

I now see a popup window when I hit the "Remote:none" button (trying to push to remote).

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/1/4179c24c355f5be25984737b2dce21e1beeabff7.png)

Any suggestions?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [22 June 2021 14:06 UTC](https://discourse.nodered.org/t/projects-github-ssh-and-basic-auth-deprecation/44557/17 "2021-06-22T14:06:26Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
