# RED.httpNode.get gives "Unauthorized"

**URL:** <https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749>\
**Category:** Developing Nodes\
**Created:** [8 March 2019 16:30 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749 "2019-03-08T16:30:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [8 March 2019 16:30 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/1 "2019-03-08T16:30:35Z")

</div>

Hi folks,

I have released last week the **node-red-contrib-ui-heatmap** node, which worked fine at the moment...

However I got a Github issue from somebody that cannot see the heatmap in his dashboard. So I have installed the heatmap-node myself from NPM on one my Raspberries, and indeed I cannot see it either.

But I see this in my console log:

![image](https://cdck-file-uploads-us1.s3.dualstack.us-west-2.amazonaws.com/flex026/uploads/nodered/original/2X/7/7ed9f5fd41219bc6f7adf1075d51668ef5cccc7f.png)

This is my [server side](https://github.com/bartbutenaers/node-red-contrib-ui-heatmap/blob/master/heat_map.js#L303) to publish the heatmap.min.js library:

```auto
RED.httpNode.get('/ui/heatmap/js/*', RED.auth.needsPermission('heatmap.read'), function(req, res){
        var options = {
            root: __dirname + '/lib/',
            dotfiles: 'deny'
        };
       
        // Send the requested file to the client (in this case it will be heatmap.min.js)
        res.sendFile(req.params[0], options)
});

```

And this is my [client side](https://github.com/bartbutenaers/node-red-contrib-ui-heatmap/blob/master/heat_map.js#L29) to load the third-party library:

```auto
<script src="heatmap/js/heatmap.min.js"></script>

```

Does anybody have any idea what could cause the authentication issue?

I also don't get why there is a very long number in the console log message (= 155199...).  
Don't know why it worked fine last week ..

Thanks !!!  
Bart

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [8 March 2019 16:34 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/2 "2019-03-08T16:34:00Z")

</div>

You should not be using the `needsPermission` middleware on `RED.httpNode`.

`needsPermission` is for the admin apis - in other words routes that are mounted on `RED.httpAdmin`.

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [8 March 2019 20:43 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/3 "2019-03-08T20:43:07Z")

</div>

Thanks Nick (@knolleary),

I have changed the code of my UI-widget nodet to this:

```auto
RED.httpNode.get('/ui/heatmap/js/*', function(req, res){
        var options = {
            root: __dirname + '/lib/',
            dotfiles: 'deny'
        };
       
        // Send the requested file to the client (in this case it will be heatmap.min.js)
        res.sendFile(req.params[0], options)
});

```

But then I still get this:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/6/68754b781a643f608e8bcb7e4271f6010a7da1ba.png)

And indeed, I don't even arrive on my breakpoint in this code snippet ...

But the weird thing is that it works fine when I copy the **SAME URL** (from the browser console log) in the address bar of my browser:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/0/0d078bb5fe7d8af396227ff463e037ac62dab4c2.png)

Any ideas?

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [8 March 2019 23:12 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/4 "2019-03-08T23:12:10Z")

</div>

Have tried all kind of things (rebooted my Raspberry, cleared browser cache ...) and now suddenly it appears:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/6/6e769cc91c38b3b19ee056bd9d0190b5414ca98e.png)

I will create a new version with your tip, and hopefully the issues are solved for everybody ...

---

<div class="post-metadata">

**Author:** ![howardweng](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/howardweng/32/8532_2.png) [@howardweng](https://discourse.nodered.org/u/howardweng)\
**Post date:** [21 May 2019 05:32 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/5 "2019-05-21T05:32:46Z")

</div>

I have installed the node of Heatmap with sample flow. But my question is that I do not know where to get the heatmap url?

[myurl.com/ui](http://myurl.com/ui) ?

Please help. thanks!

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [21 May 2019 20:11 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/6 "2019-05-21T20:11:34Z")

</div>

Hello Howard (@howardweng),

The above discussion is about an url that I use internally in my heatmap node, so you don't need to bother about this. I assume you have installed the [dashboard](https://flows.nodered.org/node/node-red-dashboard) nodes? Then the heatmap widget should be visible in your Node-RED dashboard, which is running at _http://\<your\_ip\_address\>:1880/ui_ (or _http **s** ://\<your\_ip\_address\>:1880/ui_ if you have setup ssl).f

---

<div class="post-metadata">

**Author:** ![howardweng](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/howardweng/32/8532_2.png) [@howardweng](https://discourse.nodered.org/u/howardweng)\
**Post date:** [21 May 2019 23:17 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/7 "2019-05-21T23:17:40Z")

</div>

thanks for your reply. @BartButenaers , and sorry for not directly meet this topic for my question.

I know you are author of this good function node, thanks!

I did what you said, and I expect to see the heatmap in my /ui as dashboard chart did, but not happening.

here is my config. version. It will be good if you can help me to debug for this.

node-red  
0.20.5  
node-red-contrib-ui-heatmap  
2.0.0  
node-red-dashboard  
2.15.2

simple flow:

[{"id":"b1cb294a.84a818","type":"heat-map","z":"5b9ab371.3a9f7c","group":"85148c3d.ed438","order":0,"width":"6","height":"5","name":"","rows":"20","columns":"10","minMax":false,"minimumValue":0,"maximumValue":0,"backgroundColor":"#ffffff","radius":"40","opacity":0.6,"blur":0.85,"x":610,"y":680,"wires":[]},{"id":"a2a437.33b32bc8","type":"function","z":"5b9ab371.3a9f7c","name":"Generate random matrix","func":"// Generate some random data\n// See [https://www.patrick-wied.at/static/heatmapjs/example-minimal-config.html\nvar](https://www.patrick-wied.at/static/heatmapjs/example-minimal-config.html%5Cnvar) len = 200;\n\nmsg.payload = ;\n\nwhile (len--) {\n var value = Math.floor(Math.random()\*100);\n msg.payload.push(value);\n}\n\nreturn msg;","outputs":1,"noerr":0,"x":400,"y":680,"wires":[["b1cb294a.84a818"]]},{"id":"aa26a036.f4c55","type":"inject","z":"5b9ab371.3a9f7c","name":"Show heatmap","topic":"","payload":"","payloadType":"date","repeat":"","crontab":"","once":false,"onceDelay":0.1,"x":170,"y":680,"wires":[["a2a437.33b32bc8"]]}]

if you can see node still have problem showing Heatmap node, when I replace with new node, and inject the array, nothing happening at /ui dashboard

[https://github.com/howardweng/mk100/blob/master/test/heatmap\_problem1.jpg](https://github.com/howardweng/mk100/blob/master/test/heatmap_problem1.jpg)

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [22 May 2019 19:40 UTC](https://discourse.nodered.org/t/red-httpnode-get-gives-unauthorized/8749/8 "2019-05-22T19:40:24Z")

</div>

@howardweng,  
P.S. Your jpg image link isn't valid (i.e. there is no image available).

I see that there is a **syntax error** in your function node:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/1/11e58c11c7f6fbf88a8068d4d2e5b664c11c061e.png)

Could it be that you have accidentally removed that by yourself? When I import my original heatmap example flow via the Node-RED menu, then the function node is correct:

```auto
msg.payload = [];

```

The heatmap can only be drawn when you inject values into it. So when you press your Inject node's button, your function node cannot fill the message payload with numbers (due to the syntax error), so no heatmap is drawn ...

After adding `[]`, it seems to work correctly.  
I have specified to show it here in the dashboard tree:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/1/120cc177d3dd7d5b077bbccfaf53c4b228123fc9.png)

And it indeed appears at that position in my dashboard:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/e/e4963d539aa4af46882eb1140a1f0b6e086c182a.png)

When you start next time with your **own** new discussion in this forum, most likely you will get more help from the rest of the community. Some users (that are more experienced with this kind of issues) might not read "_development related discussions_" like this one.  
Bart
