# Using async function for managing http authentication

**URL:** <https://discourse.nodered.org/t/using-async-function-for-managing-http-authentication/75404>\
**Category:** General\
**Created:** [18 February 2023 21:14 UTC](https://discourse.nodered.org/t/using-async-function-for-managing-http-authentication/75404 "2023-02-18T21:14:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lizzardguki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lizzardguki/32/103637_2.png) [@lizzardguki](https://discourse.nodered.org/u/lizzardguki)\
**Post date:** [18 February 2023 21:14 UTC](https://discourse.nodered.org/t/using-async-function-for-managing-http-authentication/75404/1 "2023-02-18T21:14:18Z")

</div>

A strange idea came to mind today. I am heavily using bitwarden for my personal info, and i am running several node-red instances where they share same username and password combination for accessing the editor.

Could i define `adminAuth` property as a async function to utilize the Bitwarden api (which would store username and password ) to be able to have easier access and more security?

I will also utilize the Bw API to store 3rd party credentials for my integrations, because why keep them encrypted in github repository.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 February 2023 22:07 UTC](https://discourse.nodered.org/t/using-async-function-for-managing-http-authentication/75404/2 "2023-02-18T22:07:35Z")

</div>

> [@lizzardguki](#):
>
> Could i define `adminAuth` property as a async function to utilize the Bitwarden api (which would store username and password ) to be able to have easier access and more security?

Maybe you could - I think you might be able to but I've not really looked into that api.

However, I'm not entirely convinced it would be more secure. I suspect it would be less secure but would need to give it more thought than a Sat. evening warrants I'm afraid. 🙂 My reasoning being that you have collapsed the security decision making and action into your application. Ideally, the two should generally be separate, especially for administrative actions.

Where it might make more sense is your other use-case which would effectively use Bitwarden as a keystore for your application. Now that would be an interesting flow to see and I hope that you will be able to share something.

---

<div class="post-metadata">

**Author:** ![ralphwetzel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ralphwetzel/32/53713_2.png) [@ralphwetzel](https://discourse.nodered.org/u/ralphwetzel)\
**Post date:** [18 February 2023 22:11 UTC](https://discourse.nodered.org/t/using-async-function-for-managing-http-authentication/75404/3 "2023-02-18T22:11:29Z")

</div>

> [@lizzardguki](#):
>
> Could i define `adminAuth` property as a async function [...]

Yes, `adminAuth` may return a Promise.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [19 April 2023 22:11 UTC](https://discourse.nodered.org/t/using-async-function-for-managing-http-authentication/75404/4 "2023-04-19T22:11:45Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
