# What are the available node-RED permissions

**URL:** <https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020>\
**Category:** General\
**Created:** [16 May 2024 13:42 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020 "2024-05-16T13:42:31Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![malee](https://avatars.discourse-cdn.com/v4/letter/m/ac8455/32.png) [@malee](https://discourse.nodered.org/u/malee)\
**Post date:** [16 May 2024 13:42 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/1 "2024-05-16T13:42:31Z")

</div>

Are \* and read the only available permissions when setting [scope.](https://nodered.org/docs/api/admin/oauth)?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 May 2024 14:05 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/2 "2024-05-16T14:05:13Z")

</div>

Yes - we have the groundwork for supporting finer-grained permissions, but it isn't something we've formally supported.

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [16 May 2024 14:13 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/3 "2024-05-16T14:13:22Z")

</div>

Will Node-RED in the future allow to have an editor configurations for each user?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 May 2024 14:14 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/4 "2024-05-16T14:14:55Z")

</div>

> [@GogoVega](#):
>
> allow to have an editor configurations for each user?

Some settings are already remembered per-user. Anything you set in the settings dialog in the editor will be saved for the user.

Are there particular additional settings you have in mind?

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [16 May 2024 14:19 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/5 "2024-05-16T14:19:05Z")

</div>

Well, one user is the administrator and has access to everything. Another user only has the right to modify the flows (no palette manager).

I admit that I have no further idea on this subject.  
I try to see it as a team, one of the members is in charge and the others have more or less restrictions.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 May 2024 14:24 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/6 "2024-05-16T14:24:49Z")

</div>

Ah, I understand what you mean.

To expand on my original reply, we do have finer grained permissions in runtime API - so it is theoretically possible to give a user write access to the flows, but not write access to the nodes. But not sure it's fully validated.

But more importantly, the editor doesn't reflect those permissions well - it lets you _try_ to do anything and reports back if it fails. Whereas it would be better to stop you trying to do something you aren't allowed to do.

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [16 May 2024 14:27 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/7 "2024-05-16T14:27:09Z")

</div>

Thanks, can be a topic of discussion for FlowFuse.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 May 2024 15:51 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/8 "2024-05-16T15:51:31Z")

</div>

That would be sad. It would be helpful to many Node-RED users, not just FlowFuse users.

I know that I tried to add some finer control to the uibuilder Editor features in earlier days and it didn't work at the time, certainly would be nice to have some more authorisation control.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 May 2024 16:02 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/9 "2024-05-16T16:02:12Z")

</div>

> [@TotallyInformation](#):
>
> That would be sad. It would be helpful to many Node-RED users, not just FlowFuse users.

And it isn't at all suggested that anything in this area would be FF specific.

It may be that FF is able to provide a simple way to make use of any Node-RED capability, but any ability to have finer-grained permissions would be an entirely core Node-RED feature available to all.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [14 August 2024 16:02 UTC](https://discourse.nodered.org/t/what-are-the-available-node-red-permissions/88020/10 "2024-08-14T16:02:23Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
