node-red-contrib-protocol-inspector
v0.1.0
Published
Node-RED editor sidebar plugin that shows a live DevTools-style feed of HTTP, MQTT, and WebSocket traffic
Maintainers
Readme
node-red-contrib-protocol-inspector
Node-RED editor plugin (not a flow node) that adds a sidebar tab with a live, DevTools-Network-style feed of HTTP, MQTT, and WebSocket traffic flowing through a running Node-RED instance.
Requires Node-RED 5.x and Node.js >= 22.9.
Install
cd ~/.node-red
npm install node-red-contrib-protocol-inspectorRestart Node-RED, open the editor, and find the Inspector sidebar tab.
Capture defaults to OFF — press the sidebar play button to start (or POST /protocol-inspector/toggle with {"enabled":true}). Press stop to turn capture off again.
Click an event’s object tree to expand nested keys, arrays, and sub-objects (same Debug-sidebar widget).
Optional settings.js
module.exports = {
// ...
protocolInspector: {
enabled: false, // capture on start (default false)
redact: true, // redact secrets (default true)
bufferSize: 500 // circular buffer capacity
}
}Security & Privacy
- Redaction is ON by default.
Authorization,Cookie/Set-Cookie, and keys matching/api[-_]?key/i,/token/i,/secret/i,/password/iare replaced with[REDACTED]in headers and top-level payload keys. - You can disable redaction from the sidebar or settings — only do this on trusted networks.
- Capture is OFF by default so idle installs do not record traffic.
- Events live in an in-memory circular buffer only. Nothing is written to disk unless you click Export.
- Admin HTTP endpoints (
/protocol-inspector/*) are intentionally unauthenticated in this package. Do not expose the Node-RED admin port to untrusted networks. - Node correlation is best-effort. The runtime walks
Error().stacklooking for node module paths. Many calls cannot be attributed to a specific node id — treatnodeIdas a hint, not ground truth.
Manual test (bare metal)
- Install the package into
~/.node-redand restart Node-RED. - Open the Inspector sidebar and turn Capture ON.
- Deploy a flow: inject → http request (any URL) → confirm an
httpevent appears with status/duration. - Optionally add MQTT in/out against a local broker and confirm
mqttevents.
Docker Test Environment
See the repository root README.md for docker compose instructions (editor on http://localhost:1890).
