# User context in httpAdminMiddleware?

**URL:** <https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542>\
**Category:** General\
**Tags:** security\
**Created:** [31 January 2022 09:34 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542 "2022-01-31T09:34:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mw75](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mw75/32/52490_2.png) [@mw75](https://discourse.nodered.org/u/mw75)\
**Post date:** [31 January 2022 09:34 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542/1 "2022-01-31T09:34:44Z")

</div>

Hi all,  
i'm currently integrating node-red in an OpenID-connect context using keycloak as provider - see [OAuth/OpenID logout with Keycloak](https://discourse.nodered.org/t/oauth-openid-logout-with-keycloak/57492) . In this context i found the httpAdminMiddleware settings and tried it out.

I documented in the PR regarding the topic above:  
If the httpAdminMiddleware had access to the profile information provided by the authentication layer, it would be an option to set the username to a keyword like "no\_node\_red\_permission" and redirect from the middleware in that case. Unfortunately this middleware seems to run in an independent middleware chain and i can't get a user context before or after the next() call.

Is my assumption with different chains correct or am i missing something?

Thanks for clearing that up for my!

Regards,  
Mario

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [31 January 2022 10:50 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542/2 "2022-01-31T10:50:08Z")

</div>

> [@mw75](#):
>
> Is my assumption with different chains correct or am i missing something?

I don't think it has been properly considered, so would be happy to discuss any proposed changes to make it more useful (as long as they are backwards compatible of course).

One challenge is identifying where the middleware should be inserted in the chain - whether it comes before or after the authentication layer. I can see uses for both.

---

<div class="post-metadata">

**Author:** ![mw75](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mw75/32/52490_2.png) [@mw75](https://discourse.nodered.org/u/mw75)\
**Post date:** [1 February 2022 13:30 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542/3 "2022-02-01T13:30:31Z")

</div>

> [@knolleary](#):
>
> whether it comes before or after the authentication layer. I can see uses for both.

Why not both?  
@node-red/editor-api/lib/index.js : 61

```javascript
        if (settings.httpAdminMiddleware) {
            if (typeof settings.httpAdminMiddleware === "function" || Array.isArray(settings.httpAdminMiddleware)) {
                adminApp.use(settings.httpAdminMiddleware);
            } 
> if (typeof settings.httpAdminMiddleware.early === "function" || Array.isArray(settings.httpAdminMiddleware.early)) {
> adminApp.use(settings.httpAdminMiddleware.early);
> } 
        }
...
...
... - 106 
        if (settings.httpAdminCors) {
            var corsHandler = cors(settings.httpAdminCors);
            adminApp.use(corsHandler);
        }   

> if (settings.httpAdminMiddleware) {
> if (typeof settings.httpAdminMiddleware.late === "function" || Array.isArray(settings.httpAdminMiddleware.late)) {
> adminApp.use(settings.httpAdminMiddleware.late);
> } 
> }

        var adminApiApp = require("./admin").init(settings, runtimeAPI);
        adminApp.use(adminApiApp);

```

The default-early behavior is just to keep the current implementation stable.

PR on request.

---

<div class="post-metadata">

**Author:** ![mw75](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/mw75/32/52490_2.png) [@mw75](https://discourse.nodered.org/u/mw75)\
**Post date:** [5 February 2022 07:47 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542/4 "2022-02-05T07:47:59Z")

</div>

Any feedback would be appreciated @knolleary and @all!

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [5 February 2022 09:30 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542/5 "2022-02-05T09:30:38Z")

</div>

Happy to discuss in the context of a PR against the `dev` branch.

I'm not sure `early` and `late` is the right naming. Maybe `preAuth` and `postAuth` would be clearer and give scope for having other well-defined points a middleware could be inserted.

---

<div class="post-metadata">

**Author:** ![bubus](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bubus/32/44356_2.png) [@bubus](https://discourse.nodered.org/u/bubus)\
**Post date:** [14 March 2022 15:00 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542/6 "2022-03-14T15:00:30Z")

</div>

@mw75 @knolleary

Is there some estimation when such feature could be avalible?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [13 May 2022 15:00 UTC](https://discourse.nodered.org/t/user-context-in-httpadminmiddleware/57542/7 "2022-05-13T15:00:58Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
