Api security

On various Hardware and OS systems: pi / windows / routers / nas, etc

Moderator: leecollings

Post Reply
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Api security

Post by janpep »

I found out that there is no logging of failed api connections?

When an API command is issued with the correct authentication, it appears in the log.

Code: Select all

Status: User: XXX initiated a SetPoint command
But if there is an invalid login, I see no record of it in the log.
This In contrast to the UI, where an incorrect login attempt is (rightfully) logged.
Am I overlooking something?
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
User avatar
gizmocuz
Posts: 3026
Joined: Thursday 11 July 2013 18:59
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Location: Top of the world
Contact:

Re: Api security

Post by gizmocuz »

Probably. When you login with a failed username/password, you will see this in the log (just checked)

Regarding API calls, It is up to developers to check the return response from the backend.
Quality outlives Quantity!
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

gizmocuz wrote: Friday 24 April 2026 7:24 Probably. When you login with a failed username/password, you will see this in the log (just checked)
What do you mean with 'this''?
I see nothing, so that is the same on my side. :-)
And expected the same behaviour as from the UI.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

Found out that I have to enable debug level for authentication in Setup --> Settings --> Log
I would expect that an invalid login is always marked as an error.

Code: Select all

2026-04-24 13:44:57.068  Debug: [Basic] Found a Basic Auth Header ('username')
2026-04-24 13:44:57.068  Debug: [Auth Check] Invalid Basic Authorization for API call!
2026-04-24 13:44:57.069  Debug: [web:443] isPage 1 isAction 0 isUpgrade 0 needsAuthentication 1 isAuthenticated 0 () isNew 0
Unfortunately: The IP address is not displayed.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

I think it would be much better if an incorrect authentication with mentioning of the IP address were recorded as an ERROR in the log.
That would at least provide the option to respond to this with Fail2ban.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
jannl
Posts: 870
Joined: Thursday 02 October 2014 6:36
Target OS: Raspberry Pi / ODroid
Domoticz version: 2026.1.x
Location: Geleen
Contact:

Re: Api security

Post by jannl »

I would expect that no ip could reach the API from outside your (v)lan.
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

jannl wrote: Monday 27 April 2026 9:51 I would expect that no ip could reach the API from outside your (v)lan.
Then it turns out that we both have an expectation that turns out to be incorrect.
That does not take away the possibility and the desire to approach it from the outside and to do so in the safe way and restrict invalid access.
And no, I do not want to do this over VPN. With various endpoints this becomes too complicated.

Apart from that, it is always good to log incorrect login attempts as errors. Where can this request be submitted?
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
jannl
Posts: 870
Joined: Thursday 02 October 2014 6:36
Target OS: Raspberry Pi / ODroid
Domoticz version: 2026.1.x
Location: Geleen
Contact:

Re: Api security

Post by jannl »

General security rule of thumb is never to have you system reachable from the internet if it is not absolutely necessary.

Are you sure the api us robust enough? Every open port to the internet is under attack. Using different ports compared to the standards help a bit.

That being said, as Gizmocuz indicates, the caller of the api should also take care of error handling like invalid credentials. Login in to the gui does this.
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

jannl wrote: Monday 27 April 2026 10:44 General security rule of thumb is never to have you system reachable from the internet if it is not absolutely necessary.
I can not do much with this. The safest house is, of course, a house without windows and doors. In my case, I want a better lock on the door. Not to remove the entire door.
The wish is to have it accessible from the outside, and to do so in the most secure way possible. Before you mention VPN: that is also difficult if you have various goals, and it becomes complicated to constantly switch VPNs for automated access to serveral systems.

So, I end up with a connection over SSL, with the necessary login credentials for a separate user with limited privileges, and a firewall that limits access with GeoIP and blocks frequent connections on that (not standard) port. Then finally, I would like to round this off with Fail2ban, to block the IP entirely after a few invalid attempts.

And then what remains is that I expect any program with authentication to log an invalid login attempt with the origin IP as an ERROR. That appears not to be the case. Therefore, a small request for improvement. To handle this in the same way the gui does.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
User avatar
gizmocuz
Posts: 3026
Joined: Thursday 11 July 2013 18:59
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Location: Top of the world
Contact:

Re: Api security

Post by gizmocuz »

I will have a look at the warning/error message.

Regarding VPN, this is extremely easy these days but might depend on the VPN system you are using.

I am using Wireguard. In the wireguard client on your mobile/tablet/desktop you can very quickly change to another tunnel (read, another location)
Once you are connected you can use your entire subnet, which is great.

Using this for years and it is the safest thing to do. Opening ports on firewalls just to access applications is not from today. (still possible, but not recommended)
Quality outlives Quantity!
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

gizmocuz wrote: Tuesday 28 April 2026 8:54 I will have a look at the warning/error message.
Thank you very much.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
User avatar
gizmocuz
Posts: 3026
Joined: Thursday 11 July 2013 18:59
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Location: Top of the world
Contact:

Re: Api security

Post by gizmocuz »

Implemented in beta 17832
Quality outlives Quantity!
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

gizmocuz wrote: Tuesday 28 April 2026 11:10 Implemented in beta 17832
That is great. And very fast, too. Thank you very much. I will take a look at it in my test environment tonight.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
lost
Posts: 716
Joined: Thursday 10 November 2016 9:30
Target OS: Raspberry Pi / ODroid
Domoticz version:
Contact:

Re: Api security

Post by lost »

Agree, as this may have been a way to bypass fail2ban, being based on log analysis, to prevent bruteforce login attempts: No log, no ban!
Don't know if this was at least bringing you to the 'end of the internet' page, as after several webUI unsuccessful login attempts :lol:
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

It wasn't very smart on my part to test this with the GUI, and assume, without testing, that the API (from the same system) would log an invalid login in the same way.
Now on my test environment with new beta tested and confirmed.
Valid login to API

Code: Select all

2026-04-29 09:12:59.988  Status: User: xxxx (IP: 111.222.333.444) initiated a switch command (139/'aSwitch'/Off)
Failed login to API ( in this case from Macrodroid 10 times) gives 10 times.....

Code: Select all

2026-04-29 09:11:13.063 Error: Failed login attempt from 111.222.333.4444 for user 'xxxx' (API)
Nice that API is mentioned aswell. I am very happy with it. Thank you gizmocuz!
Normaly api is not called from a browser, so I did not notice an 'end of the internet' page.
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
janpep
Posts: 321
Joined: Thursday 14 March 2024 10:11
Target OS: Linux
Domoticz version: v2026.3
Location: Netherlands
Contact:

Re: Api security

Post by janpep »

Tested with Fail2ban and working!
Dz on Ubuntu VM on Proxmox behind FRITZ!Box.
EvoHome; MELCloud; P1 meter; Z-Stick GEN5; Z-Wave-js-ui; Sonoff USB-Dongle Plus-E; Zigbee2Mqtt; MQTT; Greenwave powernodes 1+6; Fibaro switch, plugs, smoke; FRITZ!DECT 200. Scripts listed in profile interests.
jannl
Posts: 870
Joined: Thursday 02 October 2014 6:36
Target OS: Raspberry Pi / ODroid
Domoticz version: 2026.1.x
Location: Geleen
Contact:

Re: Api security

Post by jannl »

Still remember the vpn....

A vulnerability in the api access code will enable an advisory to access your system bypassing the authorization and thus fail2ban. Just something to keep in mind.
Post Reply