# Request refresh via API - recheck

**URL:** <https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804>\
**Category:** Feature Requests\
**Created:** [27 October 2021 07:24 UTC](https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804 "2021-10-27T07:24:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![RaimondB](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/raimondb/32/3903_2.png) [@RaimondB](https://discourse.nodered.org/u/RaimondB)\
**Post date:** [27 October 2021 07:24 UTC](https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804/1 "2021-10-27T07:24:44Z")

</div>

Continuing the discussion from [Request refresh via API](https://discourse.nodered.org/t/request-refresh-via-api/33008):

I was wondering if maybe some new developments have changed the story in te mean time? Are there now options to do some automated access towards the portal to refresh a node via an automated way?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [27 October 2021 07:35 UTC](https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804/2 "2021-10-27T07:35:24Z")

</div>

No, nothing has changed in that regard.

I don't think anyone raised the topic since you last asked, so it simply hasn't been something we've looked at.

---

<div class="post-metadata">

**Author:** ![RaimondB](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/raimondb/32/3903_2.png) [@RaimondB](https://discourse.nodered.org/u/RaimondB)\
**Post date:** [19 November 2021 09:35 UTC](https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804/3 "2021-11-19T09:35:03Z")

</div>

I have a working solution now that performs a github based login and uses the csrf for a refresh. Also I found somebody else with the same problem and a similar solution: [Automate updating nodes to the Flow Library - Creating Nodes - Node-RED Forum (nodered.org)](https://discourse.nodered.org/t/automate-updating-nodes-to-the-flow-library/46869/7)

Interestingly, he is not using a login at all. Not requiring a login seems to be a security issue to me?

Also, during the automation of the refresh, I stumbled upon the fact that the redirect\_uri that is used for the callback to the node-red site is http and not https.  
Is this on purpose? I would expect the whole login flow to be https based to prevent man-in-the-middle attacks. So I see a security risk there as well.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [19 November 2021 10:39 UTC](https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804/4 "2021-11-19T10:39:45Z")

</div>

> [@RaimondB](#):
>
> Interestingly, he is not using a login at all. Not requiring a login seems to be a security issue to me?

It doesn't require a login to request a refresh, but you do need a CSRF token. There is not a lot to gain by putting the refresh request behind a login - it doesn't do anything if there is no update available.

> [@RaimondB](#):
>
> Also, during the automation of the refresh, I stumbled upon the fact that the redirect\_uri that is used for the callback to the node-red site is http and not https.

Thanks for highlighting - now fixed.

In general, if you have concerns about security issues, its best to raise them with us privately rather than air them in a public forum - just in case there is a genuine issue. That allows us to address any potential issue before it is made public and could get exploited.

---

<div class="post-metadata">

**Author:** ![RaimondB](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/raimondb/32/3903_2.png) [@RaimondB](https://discourse.nodered.org/u/RaimondB)\
**Post date:** [19 November 2021 22:56 UTC](https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804/5 "2021-11-19T22:56:09Z")

</div>

Good to hear it is already fixed 🙂  
In what way can I do the private message? Maybe I overlooked it.

As for the refresh, I assumed you needed a login, since the button only appears when you have logged in.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [18 January 2022 22:57 UTC](https://discourse.nodered.org/t/request-refresh-via-api-recheck/52804/6 "2022-01-18T22:57:04Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
