Node-RED Admin API /flows Endpoint Permission Check Missing When adminAuth Disabled
26.5K reputation · 01 Jul 2023, 11:30 UTC
Node-RED Admin API /flows Endpoint Permission Check
When the adminAuth setting is disabled, the /flows endpoint does not perform an explicit permission verification, allowing unauthenticated requests to read or modify flows. Deployments triggered through this endpoint may fail silently, and the log only shows a generic “Error: Failed to deploy flow” message without indicating whether the cause is missing authentication, a syntax error, or a runtime exception.
The unresolved decision is whether Node-RED should enforce an authorization check and log a distinct authentication‑failure signal even when adminAuth is turned off, or rely on external middleware to provide that visibility.
Should the admin API return a clear 401 Unauthorized response when adminAuth is disabled but no credentials are supplied? Should Node-RED log an authorization‑specific error that separates it from other deployment failures? Should administrators be required to enable adminAuth or configure additional middleware to obtain reliable deployment diagnostics?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 01 Jul 2023, 23:20 UTC
Clarifying the Intent
When adminAuth is set to null or omitted in settings.js, Node‑RED intentionally removes the built‑in authentication middleware from all admin routes, including /flows. The route stays registered, so any client that can reach the HTTP port can GET, POST, PUT or DELETE flows without credentials. This is a documented feature, not a bug, and is why the API returns 200 OK and logs only a generic “Error: Failed to deploy flow” on deployment failures.
// settings.js example
module.exports = {
// adminAuth: null, // or comment out entirely
// ... other settings
};
How to Verify
- Start Node‑RED with
adminAuthdisabled. - Run
curl -v http://localhost:1880/flows– you should receive a200 OKand the flow JSON. - Re‑enable
adminAuth(e.g.,adminAuth: { type:'credentials', users:[{username:'admin',password:'pass'}] }) and restart. - Repeat the curl; the response should now be
401 Unauthorized.
Consequently, administrators should enable adminAuth or place Node‑RED behind a reverse‑proxy that enforces authentication if the admin API must be protected.