# Using express-openid-connect in httpNodeMiddleware for authenticating through Auth0 leaves req.oidc empty

**URL:** <https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305>\
**Category:** General\
**Created:** [19 June 2023 16:06 UTC](https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305 "2023-06-19T16:06:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mpolling](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@mpolling](https://discourse.nodered.org/u/mpolling)\
**Post date:** [19 June 2023 16:06 UTC](https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305/1 "2023-06-19T16:06:59Z")

</div>

I am trying to use Auth0 for authentication of endpoints in my flow. As far as I can see, this requires httpNodeMiddleware. [Passport-auth0](https://www.passportjs.org/packages/passport-auth0/) refers to [express-openid-connect](https://github.com/auth0/express-openid-connect), so I am trying to use that.

I have managed to get the basics working, and also to require authentication for only specific endpoints. The express-openid-connect examples (link to follow) suggest that I should have a non-empty object `req.oidc` when authentication is successful, but in my case this object is empty.

What strikes me, is that I need to have an _http in_ node in my flow with the callback endpoint for Auth0, but that node never gets activated; most likely because the middleware is taking care of responding to the callback (which is fine). I found a Github ticket for express-openid-connect (link to follow) where someone had a similar issue, and it seems that their issue was caused by the callback being overridden (link to follow).

Could Node-RED be overriding my callback in some way? Is there a way to define a route at the middleware level in `settings.js`?  
Or perhaps someone has experience with using express-openid-connect and Auth0 in combination with Node-RED?

At the top of my `settings.js` I have this:

```auto
const { auth, requiresAuth } = require('express-openid-connect');

```

And my httpNodeMiddleware in `settings.js` looks like this:

```auto
	httpNodeMiddleware: [
		auth({
			authRequired: false,
			issuerBaseURL: 'https://dev-some_unique_id.eu.auth0.com',
			baseURL: 'https://localhost/',
			clientID: 'some id that I prefer not to share',
			secret: 'some secret that I prefer not to share',
			idpLogout: true,
			routes: {
				callback: '/mycallback'
			},
		}),
		function (req, res, next) {
			var url = require("url");
			if (url.parse(req.url).pathname == '/test2') {
				requiresAuth()(req, res, next);
			} else {
				next();
			}
		}
	],

```

I'll try to add more links in a follow-up comment, because I am not allowed more than two links.

---

<div class="post-metadata">

**Author:** ![mpolling](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@mpolling](https://discourse.nodered.org/u/mpolling)\
**Post date:** [19 June 2023 16:08 UTC](https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305/2 "2023-06-19T16:08:02Z")

</div>

The [express-openid-connect examples](https://github.com/auth0/express-openid-connect/blob/master/EXAMPLES.md).

---

<div class="post-metadata">

**Author:** ![mpolling](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@mpolling](https://discourse.nodered.org/u/mpolling)\
**Post date:** [19 June 2023 16:09 UTC](https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305/3 "2023-06-19T16:09:12Z")

</div>

The [Github ticket for express-openid-connect](https://github.com/auth0/express-openid-connect/issues/235) and the comment about it being [caused by the callback being overridden](https://github.com/auth0/express-openid-connect/issues/235#issuecomment-842602124).

---

<div class="post-metadata">

**Author:** ![mpolling](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@mpolling](https://discourse.nodered.org/u/mpolling)\
**Post date:** [20 June 2023 07:46 UTC](https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305/4 "2023-06-20T07:46:43Z")

</div>

(Feeling slightly silly to keep replying to my own post)

I found out that the `req.oidc` object only _looks_ empty, but actually does have properties that can be used. I was not familiar with this possibility, and I did not see it mentioned in documentation. But someone else did have the [same issue](https://github.com/auth0/express-openid-connect/issues/302).

So the whole thing is unrelated to Node-RED, and my issue seems solved.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [20 June 2023 09:49 UTC](https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305/5 "2023-06-20T09:49:27Z")

</div>

> [@mpolling](#):
>
> Feeling slightly silly to keep replying to my own post

Not at all. It's very useful for the community and future readers. I wish more would. .

> [@mpolling](#):
>
> I found out that the `req.oidc` object only _looks_ empty, but actually does have properties that can be used. I was not familiar with this possibility,

Possibly a proxy object.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [4 July 2023 09:49 UTC](https://discourse.nodered.org/t/using-express-openid-connect-in-httpnodemiddleware-for-authenticating-through-auth0-leaves-req-oidc-empty/79305/6 "2023-07-04T09:49:37Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
