Moderators: grovkillen, Stuntteam, TD-er
-
ili
- New user
- Posts: 5
- Joined: 01 Dec 2021, 15:44
#1
Post
by ili » 01 Dec 2021, 15:54
Hello, sorry for newbie question, but I am the newbie. And I've failed to find the answer for obvious question: How can I secure
HTTP command protocol
I do mean everybody can send
Code: Select all
http://<espeasyip>/control?cmd=<command>
and there are should be a possibility to use password to protect requests, but how? Maybe basic auth or some secure parameters...
-
ili
- New user
- Posts: 5
- Joined: 01 Dec 2021, 15:44
#3
Post
by ili » 02 Dec 2021, 07:02
Thanks, but the same, i do see some examples, but can't find how to secure call to http://<espeasyip>/control?cmd=<command>
(
-
Ath
- Normal user
- Posts: 3419
- Joined: 10 Jun 2018, 12:06
- Location: NL
#4
Post
by Ath » 02 Dec 2021, 07:58
You can set an admin password on the unit, that will limit access to parts of the UI, but you can't lock it completely.
AFAIK, you can use basic authentication to get access to passworded sections, but I do not use that myself, currently, so I'm not up to speed on that part.
This is something that is planned for 'future improvement', but not completed.
-
TD-er
- Core team member
- Posts: 8644
- Joined: 01 Sep 2017, 22:13
- Location: the Netherlands
-
Contact:
#5
Post
by TD-er » 02 Dec 2021, 10:27
You can also add an IP-filter on the "Config" tab.
-
ili
- New user
- Posts: 5
- Joined: 01 Dec 2021, 15:44
#6
Post
by ili » 06 Dec 2021, 09:39
Ath wrote: ↑02 Dec 2021, 07:58
You can set an admin password on the unit, that will limit access to parts of the UI, but you can't lock it completely.
AFAIK, you can use basic authentication to get access to passworded sections, but I do not use that myself, currently, so I'm not up to speed on that part.
This is something that is planned for 'future improvement', but not completed.
I'v tried to set the password, but http://<espeasyip>/control?cmd=<command> works without auth... i'ts really the bit of pain... should i post or vote feature request on GitHub?...
-
ili
- New user
- Posts: 5
- Joined: 01 Dec 2021, 15:44
#7
Post
by ili » 06 Dec 2021, 09:40
TD-er wrote: ↑02 Dec 2021, 10:27
You can also add an IP-filter on the "Config" tab.
Yep, IP/MAC/etc filter is not my case
-
Ath
- Normal user
- Posts: 3419
- Joined: 10 Jun 2018, 12:06
- Location: NL
#8
Post
by Ath » 06 Dec 2021, 09:51
ili wrote: ↑06 Dec 2021, 09:39
should i post or vote feature request on GitHub?...
There is already a Github issue for that,
over here
You could add a comment to push attention up a little.
-
ili
- New user
- Posts: 5
- Joined: 01 Dec 2021, 15:44
#9
Post
by ili » 06 Dec 2021, 10:29
Ath wrote: ↑06 Dec 2021, 09:51
There is already a Github issue for that,
over here
You could add a comment to push attention up a little.
Thanks, done!
Who is online
Users browsing this forum: Bing [Bot], Google [Bot] and 34 guests