# Replicate this curl post

**URL:** <https://discourse.nodered.org/t/replicate-this-curl-post/22021>\
**Category:** General\
**Created:** [20 February 2020 16:38 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021 "2020-02-20T16:38:58Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![oliver9523](https://avatars.discourse-cdn.com/v4/letter/o/e68b1a/32.png) [@oliver9523](https://discourse.nodered.org/u/oliver9523)\
**Post date:** [20 February 2020 16:38 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/1 "2020-02-20T16:38:58Z")

</div>

I'm trying to login to a server, the following curl command works

`curl --insecure --request POST "https://IP:PORT/login" --form "username=user" --form "password=pass"`

If I try to replicate this with Node-RED using

```auto
msg.payload = { username: "user", password: "pass" };
msg.headers = {'content-type':'application/x-www-form-urlencoded'};
return msg;

```

I'm using the HTTP request function node, it's set to POST, I've configured the SSL/TLS certificates. But I get an 'unauthorized' message from the server. I can replicate this 'unauthorized' message with curl if, for example, I change the login details to something invalid.

`curl --insecure --request POST "https://IP:PORT/login" --form "username=user" --form "password=wrongpass"`

returns 'unauthorized' from the server

I also get the same response if I use "multipart/form-data" for the header.

What am I missing to replicate the curl command?

---

<div class="post-metadata">

**Author:** ![sambarnes90](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sambarnes90/32/17321_2.png) [@sambarnes90](https://discourse.nodered.org/u/sambarnes90)\
**Post date:** [20 February 2020 18:32 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/2 "2020-02-20T18:32:50Z")

</div>

Can you post the whole message debug from the request?

How exactly is the data body looking in the response?

Anything in Debug or the Console?

---

<div class="post-metadata">

**Author:** ![oliver9523](https://avatars.discourse-cdn.com/v4/letter/o/e68b1a/32.png) [@oliver9523](https://discourse.nodered.org/u/oliver9523)\
**Post date:** [20 February 2020 20:41 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/3 "2020-02-20T20:41:21Z")

</div>

I'm using node-red 0.19.3 on RPi if that makes any difference.  
The full message debug looks like

\_msgid: "c20f6921.631e28"  
topic: ""  
payload: "unauthorized↵"  
headers: object  
server: "nginx/1.17.7"  
date: "Thu, 20 Feb 2020 20:36:34 GMT"  
content-type: "text/plain; charset=utf-8"  
content-length: "13"  
connection: "close"  
x-content-type-options: "nosniff"  
strict-transport-security: "max-age=31536000;"  
x-node-red-request-node: "20a71027"  
statusCode: 401

---

<div class="post-metadata">

**Author:** ![sambarnes90](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sambarnes90/32/17321_2.png) [@sambarnes90](https://discourse.nodered.org/u/sambarnes90)\
**Post date:** [20 February 2020 20:57 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/4 "2020-02-20T20:57:46Z")

</div>

This is going to sound silly but I'm just thinking out loud...

Try and initialise a new object with the body then pass that as the payload?

```auto
let headerObject = {'content-type':'application/x-www-form-urlencoded'};
let bodyObject = { username: "user", password: "pass" };
let newmsg = { headers: headerObject, payload: bodyObject };
return newmsg

```

Just in case it's something to do with the object cloning?

---

<div class="post-metadata">

**Author:** ![oliver9523](https://avatars.discourse-cdn.com/v4/letter/o/e68b1a/32.png) [@oliver9523](https://discourse.nodered.org/u/oliver9523)\
**Post date:** [20 February 2020 21:01 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/5 "2020-02-20T21:01:17Z")

</div>

no luck, still get the 'unauthorized' message...  
curl command still works fine.

---

<div class="post-metadata">

**Author:** ![sambarnes90](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sambarnes90/32/17321_2.png) [@sambarnes90](https://discourse.nodered.org/u/sambarnes90)\
**Post date:** [20 February 2020 21:02 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/6 "2020-02-20T21:02:57Z")

</div>

Hmm - can you change the debug level to trace in settings.js then get us a full output of the console log?

Can you screenshot the setup of the HTTP request settings too?

---

<div class="post-metadata">

**Author:** ![oliver9523](https://avatars.discourse-cdn.com/v4/letter/o/e68b1a/32.png) [@oliver9523](https://discourse.nodered.org/u/oliver9523)\
**Post date:** [20 February 2020 21:56 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/7 "2020-02-20T21:56:28Z")

</div>

20 Feb 21:54:13 - [trace] runtime event: {"id":"runtime-state","retain":true}  
20 Feb 21:54:13 - [trace] runtime event: {"id":"runtime-deploy","payload":{"revision":"4f3162d66a107a10a0dc91d86dfc0adc"},"retain":true}  
20 Feb 21:54:13 - [info] Starting flows  
20 Feb 21:54:13 - [debug] red/nodes/flows.start : starting flow : global  
20 Feb 21:54:13 - [debug] red/nodes/flows.start : starting flow : b6263066.0ae12  
20 Feb 21:54:13 - [trace] [flow:global] start flow  
20 Feb 21:54:13 - [trace] [flow:global] ------------------|--------------|-----------------  
20 Feb 21:54:13 - [trace] [flow:global] id | type | alias  
20 Feb 21:54:13 - [trace] [flow:global] ------------------|--------------|-----------------  
20 Feb 21:54:13 - [trace] [flow:global] b8131fa3.0b165 | tls-config |  
20 Feb 21:54:13 - [trace] [flow:global] ------------------|--------------|-----------------  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] start flow  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] ------------------|--------------|-----------------  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] id | type | alias  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] ------------------|--------------|-----------------  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] eda0f865.9a64f8 | http request |  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] 1315f340.2a058d | function |  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] b34d3406.aa03c8 | inject |  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] 4bf05c2d.b856f4 | debug |  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] 3558d5c3.9914ca | debug |  
20 Feb 21:54:13 - [trace] [flow:b6263066.0ae12] ------------------|--------------|-----------------  
20 Feb 21:54:13 - [trace] runtime event: {"id":"runtime-state","retain":true}  
20 Feb 21:54:13 - [info] Started flows  
20 Feb 21:54:13 - [audit] {"event":"comms.open","level":98,"timestamp":1582235653572}  
20 Feb 21:54:13 - [trace] comms.open I5fPOrqeyPzcO7mXxKEiE3Hv9o5o1Eig  
20 Feb 21:54:22 - [metric] {"level":99,"nodeid":"b34d3406.aa03c8","event":"node.inject.receive","msgid":"c4b5dd99.95a43","timestamp":1582235662999}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"b34d3406.aa03c8","event":"node.inject.send","msgid":"c4b5dd99.95a43","timestamp":1582235663020}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"1315f340.2a058d","event":"node.function.receive","msgid":"c4b5dd99.95a43","timestamp":1582235663021}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"1315f340.2a058d","event":"node.function.send","msgid":"c4b5dd99.95a43","timestamp":1582235663025}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"eda0f865.9a64f8","event":"node.http request.receive","msgid":"c4b5dd99.95a43","timestamp":1582235663025}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"3558d5c3.9914ca","event":"node.debug.receive","msgid":"c4b5dd99.95a43","timestamp":1582235663026}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"1315f340.2a058d","event":"node.function.duration","msgid":"c4b5dd99.95a43","value":3.98,"timestamp":1582235663027} 20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"eda0f865.9a64f8","event":"node.http request.duration.millis","msgid":"c4b5dd99.95a43","value":"210.636","timestamp":1582235663241}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"eda0f865.9a64f8","event":"node.http request.size.bytes","msgid":"c4b5dd99.95a43","value":260,"timestamp":1582235663241}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"eda0f865.9a64f8","event":"node.http request.send","msgid":"c4b5dd99.95a43","timestamp":1582235663242}  
20 Feb 21:54:23 - [metric] {"level":99,"nodeid":"4bf05c2d.b856f4","event":"node.debug.receive","msgid":"c4b5dd99.95a43","timestamp":1582235663242}  
20 Feb 21:54:26 - [metric] {"level":99,"event":"runtime.memory.rss","value":60993536,"timestamp":1582235666566}  
20 Feb 21:54:26 - [metric] {"level":99,"event":"runtime.memory.heapTotal","value":20738048,"timestamp":1582235666566}  
20 Feb 21:54:26 - [metric] {"level":99,"event":"runtime.memory.heapUsed","value":18586432,"timestamp":1582235666567}  
20 Feb 21:54:41 - [metric] {"level":99,"event":"runtime.memory.rss","value":60329984,"timestamp":1582235681590}  
20 Feb 21:54:41 - [metric] {"level":99,"event":"runtime.memory.heapTotal","value":20475904,"timestamp":1582235681591}  
20 Feb 21:54:41 - [metric] {"level":99,"event":"runtime.memory.heapUsed","value":17733764,"timestamp":1582235681591}

---

<div class="post-metadata">

**Author:** ![oliver9523](https://avatars.discourse-cdn.com/v4/letter/o/e68b1a/32.png) [@oliver9523](https://discourse.nodered.org/u/oliver9523)\
**Post date:** [20 February 2020 21:58 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/8 "2020-02-20T21:58:59Z")

</div>

![](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/5/057e174de3669645dd858ef9630f9247b81b2aff.jpeg)

obviously the url is actually set correctly but it's not a public server so i've hidden it for now

---

<div class="post-metadata">

**Author:** ![sambarnes90](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sambarnes90/32/17321_2.png) [@sambarnes90](https://discourse.nodered.org/u/sambarnes90)\
**Post date:** [20 February 2020 22:05 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/9 "2020-02-20T22:05:17Z")

</div>

Can you temporarily try accessing over http instead of https in case it's something to do with the TLS configuration?

Or make another endpoint on the API you're trying to reach accessible without authentication?

Nothing I've seen so far is jumping out at me - all seems to be correct!

Can you send the output of the request to a function node and JSON stringify the entire object then log that?

---

<div class="post-metadata">

**Author:** ![oliver9523](https://avatars.discourse-cdn.com/v4/letter/o/e68b1a/32.png) [@oliver9523](https://discourse.nodered.org/u/oliver9523)\
**Post date:** [20 February 2020 22:23 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/10 "2020-02-20T22:23:11Z")

</div>

yeah there's something funky going on...  
[http://IP:8080/login2/](http://IP:8080/login2/)  
works in node-red

---

<div class="post-metadata">

**Author:** ![sambarnes90](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sambarnes90/32/17321_2.png) [@sambarnes90](https://discourse.nodered.org/u/sambarnes90)\
**Post date:** [20 February 2020 22:25 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/11 "2020-02-20T22:25:19Z")

</div>

Trailing slashes redirected?

Try it with the / after /login?

TLS/SSL settings not working - how's that all set up?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [20 April 2020 22:25 UTC](https://discourse.nodered.org/t/replicate-this-curl-post/22021/12 "2020-04-20T22:25:27Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
