Dashticz can't access Domoticz on latest beta

Please use template to report bugs and problems. Post here your questions when not sure where else to post
Only for bugs in the Domoticz application! other problems go in different subforums!

Moderators: leecollings, remb0

Forum rules
Before posting here, make sure you are on the latest Beta or Stable version.
If you have problems related to the web gui, clear your browser cache + appcache first.

Use the following template when posting here:

Version: xxxx
Platform: xxxx
Plugin/Hardware: xxxx
Description:
.....

If you are having problems with scripts/blockly, always post the script (in a spoiler or code tag) or screenshots of your blockly

If you are replying, please do not quote images/code from the first post

Please mark your topic as Solved when the problem is solved.
epik77
Posts: 17
Joined: Thursday 26 March 2026 10:40
Target OS: Raspberry Pi / ODroid
Domoticz version:
Contact:

Re: Dashticz can't access Domoticz on latest beta

Post by epik77 »

I hadn't actually thought of this, but I had a lighttpd instance for updating the Let's Encrypt SSL certificate.
I used that to bypass CORS.
I'm pasting the code and the configuration I used works:

100-domoticz.conf

Code: Select all

server.modules += ( "mod_proxy" )

$HTTP["remoteip"] !~ "192.168.2.|10.10.0." {
   $HTTP["url"] =~ "/json.htm" {
      url.access-deny = ( "" )
    }
  }


proxy.header = (
    "map-urlpath" => (
        "/json.htm" => "/json.htm"
    )
)

$HTTP["url"] =~ "^/json\.htm($|\?)" {
    proxy.server = (
        "" => (
            (
                "host" => "192.168.2.1",
                "port" => 8080
            )
        )
    )
setenv.add-response-header = (
        "Access-Control-Allow-Origin" => "*",
        "Access-Control-Allow-Methods" => "GET, POST, OPTIONS",
        "Access-Control-Allow-Headers" => "Content-Type, Authorization"
    )

}

Regarding Dynamic Dashboards, I'm starting to use it, but to adapt it to my tablet, a few important elements are still missing:
1) security panel widget
2) dashboard switch button (the swipe left/right to switch dashboards on older tablets isn't very responsive).
3) block device hide_data customization (on a 10-inch tablet, with all that information, the dashboard fills the entire screen).

In any case, you're on the right track. Keep up the development! :-)
User avatar
gizmocuz
Posts: 3026
Joined: Thursday 11 July 2013 18:59
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Location: Top of the world
Contact:

Re: Dashticz can't access Domoticz on latest beta

Post by gizmocuz »

The new beta adds CORS settings so tools like Dashticz can work again without weakening security for everyone else.

First, some background on what happened. This was not a bug: 2026.3 contains an important security hardening of the web server.
Before that, Domoticz answered every API request with Access-Control-Allow-Origin: *. Combined with the "Local Networks (no username/password)" setting, this meant that ANY website you visited in a browser on your LAN could silently read and control your complete Domoticz system.
That had to go, and it will not come back as a default.

What the next beta brings, under Settings > Security > "Allowed CORS Origins":

- A list of exact origins that may use the API cross-origin, for example http://192.168.1.5:8082 if that is where Dashticz is served from (separate multiple entries with a semicolon)
- A checkbox "Also allow origins from local networks": easiest for Dashticz, it allows any origin served from an IP inside your Local Networks ranges, while everything else stays blocked
- Entering * restores the old allow-everything behaviour. You will get a warning, and I really recommend one of the two options above instead

The settings apply immediately after saving, no restart needed.

The reverse proxy setup Renber posted above is a good workaround, since it makes Dashticz same-origin.

@dzdm: username/password in GET parameters will not return, credentials in URLs end up in logs and browser history, that part needs to be solved on the Dashticz side.
And of course, do also have a look at the built-in Dynamic Dashboard, it is same-origin so none of this applies to it.
Quality outlives Quantity!
User avatar
capman
Posts: 166
Joined: Friday 12 July 2013 20:48
Target OS: Raspberry Pi / ODroid
Domoticz version: Beta
Location: Belgium
Contact:

Re: Dashticz can't access Domoticz on latest beta

Post by capman »

Working like charme :D . Thanks 4 integrate it in domoticz !
User avatar
Bospieper
Posts: 177
Joined: Thursday 07 November 2019 10:26
Target OS: Raspberry Pi / ODroid
Domoticz version: 2026.3
Location: NL
Contact:

Re: Dashticz can't access Domoticz on latest beta

Post by Bospieper »

Hello,
Where in Domoticz or Dashticz can I find:
Setup:

Dashticz: /var/www/html/dashticz
Apache: port 80
Domoticz: port 8080
Enable Apache modules:
sudo a2enmod proxy
sudo a2enmod proxy_http

Thanxs Piet
Renber
Posts: 57
Joined: Thursday 04 February 2021 8:10
Target OS: Linux
Domoticz version: Beta
Location: Belgium
Contact:

Re: Dashticz can't access Domoticz on latest beta

Post by Renber »

Here is a corrected version of the previous one (WebSockets working) if you want to set up a reverse proxy with Apache.

Use a reverse proxy to serve Domoticz through the same origin as Dashticz. This avoids CORS issues.

This only applies when Dashticz is served by Apache.

In principle, your configuration is as follows: 1. Enable the required Apache modules:

Code: Select all

sudo a2enmod proxy
sudo a2enmod proxy_http
2. Edit the Apache configuration:

Code: Select all

sudo nano /etc/apache2/sites-available/000-default.conf
3. Add the following inside the <VirtualHost *:80> section:

Code: Select all

ProxyPreserveHost On

ProxyPass /domoticz/json ws://DOMOTICZ_IP:8080/json
ProxyPassReverse /domoticz/json ws://DOMOTICZ_IP:8080/json

ProxyPass /domoticz/ http://DOMOTICZ_IP:8080/
ProxyPassReverse /domoticz/ http://DOMOTICZ_IP:8080/
4. Restart Apache:

Code: Select all

sudo systemctl restart apache2
5. Update your Dashticz configuration (custom/CONFIG.js):

Replace:

Code: Select all

config["domoticz_ip"] = "http://DOMOTICZ_IP:8080"
with:

Code: Select all

config["domoticz_ip"] = "http://DOMOTICZ_IP/domoticz/"
Warning: This exposes Domoticz through your web server on port 80.
Linux Debian 12 Server: Domoticz beta + Dashticz beta + Node-Red + Homebridge
User avatar
Bospieper
Posts: 177
Joined: Thursday 07 November 2019 10:26
Target OS: Raspberry Pi / ODroid
Domoticz version: 2026.3
Location: NL
Contact:

Re: Dashticz can't access Domoticz on latest beta

Post by Bospieper »

Hi Renber,
Thanx for your replay on my question. I did the changes but unfortunately I'am getting the following failure:

Can't access Domoticz via http://192.168.1.27/domoticz/
Check domoticz_ip in config.js

This is in my config.js
var config = {}
config['domoticz_ip'] = 'http://192.168.1.27/domoticz/';

Grz. Piet
User avatar
Antoinne
Posts: 15
Joined: Monday 30 March 2020 17:39
Target OS: Raspberry Pi / ODroid
Domoticz version:
Contact:

Re: Dashticz can't access Domoticz on latest beta

Post by Antoinne »

Hi Gizmocuz,
gizmocuz wrote: Tuesday 04 August 2026 13:39 And of course, do also have a look at the built-in Dynamic Dashboard, it is same-origin so none of this applies to it.
Thanks for this nudge. Forgot all about this new feature. But tonight I've already started rebuilding my new dashboards. This will save me a lot of time because I won't have to maintain the building blocks in the extra dashticz environment any longer. Thanks for your continued development work, and for reminding us to keep updating the versions and staying up to date with the latest developments :D

Antoinne
Post Reply