# Setting.js file protection

**URL:** <https://discourse.nodered.org/t/setting-js-file-protection/92420>\
**Category:** General\
**Created:** [15 October 2024 22:37 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420 "2024-10-15T22:37:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rromele](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rromele/32/18431_2.png) [@rromele](https://discourse.nodered.org/u/rromele)\
**Post date:** [15 October 2024 22:37 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420/1 "2024-10-15T22:37:29Z")

</div>

How to protect "setting.js" and "flow.json" files from modifications by unauthorized users?  
Which is the best technique?

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [15 October 2024 23:05 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420/2 "2024-10-15T23:05:00Z")

</div>

Are you on Windows or Linux?

The best technique for both is to prevent unauthorised users from accessing your system.

Don't make your Node-red installation accessible from the internet.  
Use secure passwords to protect your OS user account and access to the editor.

There is a section of the documentation on Securing Node-red.

If you are on Linux your user should not have passwordless access to sudo.  
Change the ownership of settings.js to root:root  
But note that if someone has access to your OS login there is no simple way to fully protect Node-red.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [16 October 2024 06:48 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420/3 "2024-10-16T06:48:39Z")

</div>

> [@rromele](#):
>
> unauthorized users?

Please define who these users are. Users who have physical access to the server? Those who have direct access to your local network? Hackers trying to break in via node red access from the Internet? Others?

---

<div class="post-metadata">

**Author:** ![rromele](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rromele/32/18431_2.png) [@rromele](https://discourse.nodered.org/u/rromele)\
**Post date:** [16 October 2024 18:22 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420/4 "2024-10-16T18:22:47Z")

</div>

Hi,  
Users who have physical access to the server with administrator rights.  
Operating System: Windows

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [16 October 2024 18:27 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420/5 "2024-10-16T18:27:48Z")

</div>

> [@rromele](#):
>
> Users who have physical access to the server with administrator rights

Consider moving Node-red to a different machine that nobody else has admin access to.

As long as it's on the same network, you can still access the editor from the PC as `<IP Address>:1880` or `<Hostname>:1880`

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [16 October 2024 19:30 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420/6 "2024-10-16T19:30:52Z")

</div>

If somebody has physical access to the machine, all bets are off, let alone if they already have admin access.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [14 January 2025 19:31 UTC](https://discourse.nodered.org/t/setting-js-file-protection/92420/7 "2025-01-14T19:31:22Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
