# Use httpstatic to serve a image file

**URL:** <https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435>\
**Category:** General\
**Created:** [10 April 2023 20:12 UTC](https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435 "2023-04-10T20:12:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [10 April 2023 20:12 UTC](https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435/1 "2023-04-10T20:12:52Z")

</div>

My node-RED https server is exposed to the internet, but I've taken a number of precautions to keep it safe. However, I'd like to serve an image file via httpstatic, **without** password protecting the node-defined HTTP endpoints (httpNodeRoot).

I don't care if anyone accesses the image file (it's only a logo), but wondered if it would expose a way into Node-RED, and leave my system vulnerable?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [11 April 2023 00:59 UTC](https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435/2 "2023-04-11T00:59:34Z")

</div>

Nothing is perfect so there is always risk. As far as I know, there is no public security review of Node-RED so no certified way of assessing the risks without doing an independent review (which I know some companies have done).

My personal take would be this: If the data/processes you are protecting are relatively low value then Node-RED alone should be fine.

If they are of higher value, I would always recommend defence in depth and would use additional tools to provide separate layers of security using tools that have been very widely battle-tested.

But even the best of tools is vulnerable to mis-configuration. So ultimately, regular security testing including penetration tests are the ultimate method to assure security.

Since only you probably know the value of what you are doing, I'm afraid that only you can assess whether more is needed unless you want to pay for someone certified to do a professional review.

I would just bear in mind that Node-RED is a general-purpose tool and not one that specialises in security. Not that that makes it insecure but that there will be more opportunities to misconfigure than something more specialist.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [11 April 2023 08:10 UTC](https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435/3 "2023-04-11T08:10:50Z")

</div>

Thanks Julian, I understand the general risks to hosting valuable data/processing in Node-RED, but does serving an image file using httpstatic, **without** password protecting the http endpoints, create in itself a specific risk to Node-RED or the OS in general?

The image file itself has no value whatsoever.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [11 April 2023 08:27 UTC](https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435/4 "2023-04-11T08:27:21Z")

</div>

No, it doesn't add any material difference as long as nobody else can upload or change the image. If they did find a way then the answer would be yes.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [11 April 2023 09:42 UTC](https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435/5 "2023-04-11T09:42:05Z")

</div>

Of course you could serve the file from somewhere else like github pages.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [10 June 2023 09:42 UTC](https://discourse.nodered.org/t/use-httpstatic-to-serve-a-image-file/77435/6 "2023-06-10T09:42:42Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
