# Unauthorized when accessing custom admin endpoint

**URL:** <https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201>\
**Category:** Developing Nodes\
**Created:** [11 January 2020 21:38 UTC](https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201 "2020-01-11T21:38:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [11 January 2020 21:38 UTC](https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201/1 "2020-01-11T21:38:21Z")

</div>

Hi folks,

Paul (@Paul-Reed) reported an [issue](https://discourse.nodered.org/t/announce-node-red-contrib-xterm-second-beta-sidebar/19718/64) about my **new node-red-contrib-xterm** node:

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/3/c3f92ae487650bbb9d9ee831e33b5aa646107c38.png)  
Would really to have it solved, since that is the last 'known' issue before I can publish my first version on NPM. But I'm stuck ...

I found out that I can reproduce the problem, by activating the (_default_) username and password in the settings.js file:

```auto
    adminAuth: {
        type: "credentials",
        users: [{
            username: "admin",
            password: "$2a$08$VPSeTFDg09qElIvYvD0MjOlK1zdgi0109kNB6.gWU7XC.y1/h0Hz2",
            permissions: "*"
        }]
    },

```

As a result of that change, my flow editor keeps loading (due to my xterm node) 🥴

Found following details by debugging:

1. Due to this change in the settings.js file, the [needsPermissions](https://github.com/node-red/node-red/blob/master/packages/node_modules/%40node-red/editor-api/lib/auth/index.js#L60) function will initiate **Bearer authentication** :

2. Afterwards we arrive in the Bearer authentication strategy function. For all Node-RED standard admin endpoint ajax calls (nodes, flows, settings, ...) this works fine, because those http requests all contain an "_ **Authorization** _" http header (which will be used as Bearer token):

3. However my custom xterm ajax call contains _ **no** _ such http Authorization header, so no token (so the Bearer authentication will fail):

But I don't know why my ajax call doesn't have that http header. Thought it would be added automatically, when the first request failed (i.e. status 401)?

Does anybody can give me a tip of what I could try?

Thanks a lot !!  
Bart

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [11 January 2020 22:23 UTC](https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201/2 "2020-01-11T22:23:14Z")

</div>

1. How have you defined the endpoint that serves that resource?
2. How are you trying to load it?

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [11 January 2020 22:42 UTC](https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201/3 "2020-01-11T22:42:33Z")

</div>

Hey Nick,  
I assume it must be something very stupid ...

- My endpoint is defined [here](https://github.com/bartbutenaers/node-red-contrib-xterm/blob/master/xterm_config.js#L235):

- That endpoint is called for example [here](https://github.com/bartbutenaers/node-red-contrib-xterm/blob/master/xterm_config.html#L13):

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [11 January 2020 22:50 UTC](https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201/4 "2020-01-11T22:50:02Z")

</div>

> [@BartButenaers](#):
>
> Although I think it must be a POST when I use permission _'xterm.write'_ , and a GET for permission _'xterm.read'_ ?

No, its `.read` if its something a user with read-only access should have access to and `.write` if its something that requires full read/write access.

Do not equate `read` and `write` with `get` and `post` - there may be things that only a user with full access is allowed to read.

Any endpoint that has `needsPermission` will require the auth header to be set to access. jQuery is setup by us to add that header for any request - so your `$.ajax` requests will work.

The `<script>` loading of `xterm.js` won't work because the browser doesn't know to add the auth header.

In general though, loading static javascript resources don't need to be behind an endpoint protected by `needsPermission`. So the fix would be to add a separate endpoint for serving these resources and don't use `needsPermission` on it.

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [11 January 2020 22:52 UTC](https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201/5 "2020-01-11T22:52:53Z")

</div>

Thanks a lot again Nick!  
That is very clear information. Will try it tomorrow and will get back here.  
Have a nice sunday !

---

<div class="post-metadata">

**Author:** ![BartButenaers](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bartbutenaers/32/10476_2.png) [@BartButenaers](https://discourse.nodered.org/u/BartButenaers)\
**Post date:** [12 January 2020 07:32 UTC](https://discourse.nodered.org/t/unauthorized-when-accessing-custom-admin-endpoint/20201/6 "2020-01-12T07:32:19Z")

</div>

The separate endpoint for static resources (without needsPermission), has solved the problem for both me and Paul!
