# Set Response header for HTTP Request

**URL:** <https://discourse.nodered.org/t/set-response-header-for-http-request/13887>\
**Category:** General\
**Created:** [1 August 2019 05:09 UTC](https://discourse.nodered.org/t/set-response-header-for-http-request/13887 "2019-08-01T05:09:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [1 August 2019 05:09 UTC](https://discourse.nodered.org/t/set-response-header-for-http-request/13887/1 "2019-08-01T05:09:46Z")

</div>

**I am trying to send response header in all HTTP request:**  
I tried two way:  
First by adding below code in settings.js

```auto
    httpNodeMiddleware: function(req,res,next) {
	res.header("X-Frame-Options", "SAMEORIGIN");
        next();
    },

```

Above code is not working,  
Second: I wrote below code in red.js then it is working as expected.

```auto
 app.use(function(req, res, next) {
   res.header("X-Frame-Options", "SAMEORIGIN");
   next();
});

```

Can anyone tell me why first code is not woring?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [1 August 2019 06:04 UTC](https://discourse.nodered.org/t/set-response-header-for-http-request/13887/2 "2019-08-01T06:04:00Z")

</div>

> [@Devbrat](#):
>
> send response header in all HTTP request

You need to read the comments in the settings.js file:

```auto
    // The following property can be used to add a custom middleware function
    // in front of all http in nodes. This allows custom authentication to be
    // applied to all http in nodes, or any other sort of common request processing.

```

It states that the middleware function applies to `http in` nodes. Not to request nodes. Your second example works because you have manually forced Node-RED to always send that header.

For request nodes, you can set headers using the input msg. Set `msg.headers` as it says in the help for that node.

---

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [1 August 2019 06:25 UTC](https://discourse.nodered.org/t/set-response-header-for-http-request/13887/3 "2019-08-01T06:25:49Z")

</div>

I want to implement as middleware.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [1 August 2019 06:46 UTC](https://discourse.nodered.org/t/set-response-header-for-http-request/13887/4 "2019-08-01T06:46:01Z")

</div>

@TotallyInformation I don't think your interpretation is right. The question is about setting a "response header" not a request header.

@Devbrat at a glance, I'd expect your httpNodeMiddleware function to do what you want. Will need to debug it proper to figure out why it isn't working.

---

<div class="post-metadata">

**Author:** ![Devbrat](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@Devbrat](https://discourse.nodered.org/u/Devbrat)\
**Post date:** [1 August 2019 08:59 UTC](https://discourse.nodered.org/t/set-response-header-for-http-request/13887/5 "2019-08-01T08:59:36Z")

</div>

@knolleary That would be great help. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [1 August 2019 13:42 UTC](https://discourse.nodered.org/t/set-response-header-for-http-request/13887/6 "2019-08-01T13:42:12Z")

</div>

> [@knolleary](#):
>
> I don't think your interpretation is right. The question is about setting a "response header" not a request header.

Oops, mea culpa.
