# Secure source code file flow.json

**URL:** <https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188>\
**Category:** General\
**Created:** [19 November 2020 10:52 UTC](https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188 "2020-11-19T10:52:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AnusudhanK7](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/anusudhank7/32/25579_2.png) [@AnusudhanK7](https://discourse.nodered.org/u/AnusudhanK7)\
**Post date:** [19 November 2020 10:52 UTC](https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188/1 "2020-11-19T10:52:18Z")

</div>

Hi,

we have developed our IoT application on the node red platform. And now we want to deploy the developed application in the client production system. We have enabled HTTPS access and secured the editor by user name and password.

So no one from outside can connect to our node red platform.

but here the problem is, developed flow\_hostname.json file is present in the local storage on the client production system. i.e. Under **.nodered** folder.

So our client can have the copy of our source file flow\_hostname.json file. So how to protect the source file.?

Like in python, we can convert the .py file to .pyc (compiled python file) which means when we open the file it is not easy to understand.  
Similarly, how we have to secure the flow\_hostname.Json file on the client system.

Please do the needful. We are in the deployment phase.

I am looking forward to hear your valuable advices in this.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [19 November 2020 10:57 UTC](https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188/2 "2020-11-19T10:57:06Z")

</div>

> [@AnusudhanK7](#):
>
> I am looking forward to hear your valuable advices in this.

My advice is - dont lock your customer out.

If a contractor does this to me, i simply stop using them or I put it in the T+Cs.  
If I have access to the internals, where I can debug a problem and fix it myself (i.e avoid unnecessary extended outages), I will re-use that contractor again and again.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [19 November 2020 11:06 UTC](https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188/3 "2020-11-19T11:06:14Z")

</div>

Even if you could encrypt the flows file, it would need to be decrypted for node-RED to use it in the runtime, then what would stop the client from simply exporting your flow, and then importing it again in another system?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [19 November 2020 11:12 UTC](https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188/4 "2020-11-19T11:12:43Z")

</div>

Hi @AnusudhanK7

this question gets asked from time to time on the forum - it's worth having a search to see the previous discussions so we don't have to repeat them all over again.

From a technical standpoint, it is a **hard** problem to fully secure any program if the end user has access to the device.

You cite compiling python to pyc as an example - there are lots of tools out there that can decompile pyc back into readable python. The same is true of all compiled languages.

There are certainly steps you could take to make it _harder_ for the end user to access the information, but it will never be fully secure if they have command-line access.

For example, you could create a custom storage plugin for node-red that can handle decrypting the flows file. But you'd have to acknowledge the code to do that decrypting would be node.js code that a user could look at and reproduce for themselves. It would avoid the casual user from opening the flows file directly, but any determined user would be able to access the flow information.

As I said, have a search of the previous discussions on this topic. You'll soon see there isn't a magic solution to this.

---

<div class="post-metadata">

**Author:** ![AnusudhanK7](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/anusudhank7/32/25579_2.png) [@AnusudhanK7](https://discourse.nodered.org/u/AnusudhanK7)\
**Post date:** [19 November 2020 11:29 UTC](https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188/5 "2020-11-19T11:29:39Z")

</div>

Yeah, I understand. We don't want casual user to access the flows file. Could you please share the link,So that I can implement the same.

I have searched, but I was not able to find the topic you said. All we need is the primary level of source code(flow.json) protection.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [18 January 2021 11:29 UTC](https://discourse.nodered.org/t/secure-source-code-file-flow-json/36188/6 "2021-01-18T11:29:42Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
