# Websocket Authentication

**URL:** <https://discourse.nodered.org/t/websocket-authentication/12797>\
**Category:** General\
**Created:** [2 July 2019 00:23 UTC](https://discourse.nodered.org/t/websocket-authentication/12797 "2019-07-02T00:23:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![stbluesrul](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@stbluesrul](https://discourse.nodered.org/u/stbluesrul)\
**Post date:** [2 July 2019 00:23 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/1 "2019-07-02T00:23:25Z")

</div>

What is the best way going to go about doing this? I have https/wss setup so the communication is at least encrypted while in-transit but I'd like to add authentication now. I've done some reading and googling around and I'm a bit confused on the best way to accomplish authentication on a websocket.

I found the following:

> **[node-red-contrib-websocket-auth0](https://flows.nodered.org/node/node-red-contrib-websocket-auth0)**
>
> A web-socket with Auth0 authentication support.

  
But I'm not sure it's the best way to go.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [2 July 2019 00:28 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/2 "2019-07-02T00:28:11Z")

</div>

I've never actually got that far though I'm certainly interested in any viable approaches.

Using [Socket.IO](http://Socket.IO), I know that you can use middleware in a similar way to ExpressJS - except that it is only called when a new connection is made and so it isn't suitable for ongoing validation of connections. There is no realistic way, for example, of using the middleware to time out an authentication session like there is with Express middleware (which is called on every request).

That means that you need to build something into each client-server exchange of information manually.

---

<div class="post-metadata">

**Author:** ![stbluesrul](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@stbluesrul](https://discourse.nodered.org/u/stbluesrul)\
**Post date:** [2 July 2019 00:33 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/3 "2019-07-02T00:33:14Z")

</div>

To start I'm just looking for authentication on the new connection. Trying to setup two instances of Node-RED in a client-server type model.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [2 July 2019 00:34 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/4 "2019-07-02T00:34:51Z")

</div>

I don't think that Node-RED's websocket nodes use [Socket.IO](http://Socket.IO) so I'm not sure you can do anything with them. However, I might be wrong. I'm afraid you may need to check through the source code.

Perhaps Dave can chip in tomorrow.

---

<div class="post-metadata">

**Author:** ![stbluesrul](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@stbluesrul](https://discourse.nodered.org/u/stbluesrul)\
**Post date:** [2 July 2019 03:30 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/5 "2019-07-02T03:30:18Z")

</div>

I think have a solution. I setup nginx as a reverse proxy and enabled basic authentication over TLS. My WebSocket node is able to make a connection like this:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/d/dc1bc8228950d237dbba85f9fecf9dbebcb5ca28.png)  
Not ideal, but it will work for now.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [2 July 2019 20:44 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/6 "2019-07-02T20:44:14Z")

</div>

I'd always recommend doing security via a proxy actually. It will nearly always be more secure and easier to manage.

You might want to change your server IPTABLES firewall to ensure that it only accepts traffic to NGINX and blocks direct access to Node-RED.

---

<div class="post-metadata">

**Author:** ![DrZeta360](https://avatars.discourse-cdn.com/v4/letter/d/ea5d25/32.png) [@DrZeta360](https://discourse.nodered.org/u/DrZeta360)\
**Post date:** [16 August 2019 22:01 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/7 "2019-08-16T22:01:32Z")

</div>

That looks like a good solution! Could you share the nginx configuration?  
I'd like to use something like that and I'm not sure where to start.  
Thanks!

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [17 August 2019 10:50 UTC](https://discourse.nodered.org/t/websocket-authentication/12797/8 "2019-08-17T10:50:21Z")

</div>

> [@stbluesrul](#):
>
> node-red-contrib-websocket-auth0

Just to note that I've scored this with 1 star on Flows and raised 2 critical issues on GitHub.

There is an issue from 2017 that has no response.

It hasn't been updated in years and so the dependencies are MASSIVELY out of date.

It also looks as though this does not provide meaningful security as the token is only checked at socket connection and doesn't provide the token thereafter (because websockets don't support custom headers once the connection has been made). I'm not a code security expert though by any means so please correct me if I'm wrong.

My current recommendation is not to use this node.

I've also given 1 starts to two other related nodes,

- node-red-contrib-websocket which is a duplicate
- node-red-contrib-websocket-gabo which appears to be a fork, also not updated recently

I wouldn't recommend any of them I'm afraid.
