# Trying authorization on flow editor without secret key

**URL:** <https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830>\
**Category:** General\
**Tags:** security\
**Created:** [7 February 2023 09:20 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830 "2023-02-07T09:20:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![henkkas](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/henkkas/32/39844_2.png) [@henkkas](https://discourse.nodered.org/u/henkkas)\
**Post date:** [7 February 2023 09:20 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/1 "2023-02-07T09:20:38Z")

</div>

Until now I used node red without a secret key so I have `credentialSecret: false` ,in de settings.js.

Now I played around with authorization on the flow editor, still with `credentialSecret: false` .

But that doesn't seem to work. Do I need the secret key to make password protect to work for me?

![afbeelding](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/c/9c802af3a33cab6130e74a103c5f7bea281f3ab5.png)

Or do I have to do something with de type-attribute to make it work?

I would like this, because if you give webbrowser `<ip address>:<port>`, without `/ui`it will go directly to flow editor, rather then dashboard.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [7 February 2023 09:24 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/2 "2023-02-07T09:24:55Z")

</div>

Hi @henkkas

`credentialSecret` does not have any relation to how you secure the editor.

What have you tried so far? When you say it doesn't work what exactly do you mean? Does the editor prompt for a login but you can't get in? Or does it not prompt for a login at all? Have you restarted Node-RED to pickup those changes? Are you sure you're editing the right settings file?

If you are trying to setup a user called `admin` with a password `hallo` then it will not work because you need to generate a password hash. This is explained in the link shown in the comment in that screenshot.

---

<div class="post-metadata">

**Author:** ![henkkas](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/henkkas/32/39844_2.png) [@henkkas](https://discourse.nodered.org/u/henkkas)\
**Post date:** [7 February 2023 09:45 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/3 "2023-02-07T09:45:09Z")

</div>

@knolleary Yes, indeed, I didn't read that carefully enough. Thanks, now it is working. 🙂

---

<div class="post-metadata">

**Author:** ![henkkas](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/henkkas/32/39844_2.png) [@henkkas](https://discourse.nodered.org/u/henkkas)\
**Post date:** [8 February 2023 12:07 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/4 "2023-02-08T12:07:04Z")

</div>

@knolleary I said it was working fine and it did.

But then I got the great idea of changing the password, so I generated another hash for new password.  
I pasted that new hash into the settings.js and restarted node-red.  
But now it looks like there is no password check anymore. I tried rebooting and wiping password from browser, but no password check anymore.

Do you have any idea what I did wrong?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [8 February 2023 12:20 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/5 "2023-02-08T12:20:38Z")

</div>

Did you log out of the editor (from the user drop-down menu)?

---

<div class="post-metadata">

**Author:** ![henkkas](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/henkkas/32/39844_2.png) [@henkkas](https://discourse.nodered.org/u/henkkas)\
**Post date:** [8 February 2023 12:44 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/6 "2023-02-08T12:44:44Z")

</div>

@knolleary Indeed, that was the solution.

Is it some how possible that log-out is automatic after x time not being on the editor?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [8 February 2023 12:54 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/7 "2023-02-08T12:54:56Z")

</div>

Login tokens are valid for 7 days by default, but you can reduce that in the settings file.

However it is not activity based - it is an expiry time from the moment you login.

[https://nodered.org/docs/user-guide/runtime/securing-node-red#token-expiration](https://nodered.org/docs/user-guide/runtime/securing-node-red#token-expiration)

---

<div class="post-metadata">

**Author:** ![henkkas](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/henkkas/32/39844_2.png) [@henkkas](https://discourse.nodered.org/u/henkkas)\
**Post date:** [8 February 2023 13:01 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/8 "2023-02-08T13:01:16Z")

</div>

Ok @knolleary , thanks very much, that will do it for me. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [22 February 2023 13:01 UTC](https://discourse.nodered.org/t/trying-authorization-on-flow-editor-without-secret-key/74830/9 "2023-02-22T13:01:35Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
