Sorry for cross posting, but maybe it's okay because my original post is a reply to the release, and it won't be seen quickly enough.
Version: 2026.3
Platform: Linux binary
Plugin/Hardware: core webserver
Description:
- New libwebem ignores proxy headers by default. Forwarded headers are now ignored unless the new trusted_proxy_header_family setting is explicitly configured. Its new default is None.
- Domoticz does not configure this new header-family setting.
- Domoticz sees trusted proxy IP, and grants all clients admin access without login.
This applies to: setups with trusted reverse proxy in front of Domoticz with X-Forwarded-For to forward real client IPs.
Fix: Add headers explicitly to the libwebem config:
https://github.com/domoticz/domoticz/pull/6937
We probably want to do a quick patch release here.
2026.3 libwebem change results in unauthenticated admin access Topic is solved
Moderators: leecollings, remb0
Forum rules
Before posting here, make sure you are on the latest Beta or Stable version.
If you have problems related to the web gui, clear your browser cache + appcache first.
Use the following template when posting here:
Version: xxxx
Platform: xxxx
Plugin/Hardware: xxxx
Description:
.....
If you are having problems with scripts/blockly, always post the script (in a spoiler or code tag) or screenshots of your blockly
If you are replying, please do not quote images/code from the first post
Please mark your topic as Solved when the problem is solved.
Before posting here, make sure you are on the latest Beta or Stable version.
If you have problems related to the web gui, clear your browser cache + appcache first.
Use the following template when posting here:
Version: xxxx
Platform: xxxx
Plugin/Hardware: xxxx
Description:
.....
If you are having problems with scripts/blockly, always post the script (in a spoiler or code tag) or screenshots of your blockly
If you are replying, please do not quote images/code from the first post
Please mark your topic as Solved when the problem is solved.
-
domovincent
- Posts: 30
- Joined: Friday 18 March 2022 13:55
- Target OS: Raspberry Pi / ODroid
- Domoticz version: 2026.2
- Contact:
2026.3 libwebem change results in unauthenticated admin access
Domoticz (RPI 5), Z-Wave, 433, MQTT, ANWB-energy. Happy user since 2017
-
rugspin
- Posts: 20
- Joined: Tuesday 04 February 2020 23:59
- Target OS: Raspberry Pi / ODroid
- Domoticz version:
- Contact:
Re: 2026.3 libwebem change results in unauthenticated admin access
Just a question on the above.
In my local network, I use nginx as a revers proxy on the same host as domoticz is running, just to have a decent url and not always have to put the port number. It looks like that and was working fine so far:
Now when I do the
I get error: "403 Forbidden"
But with
everything is fine.
I'm not much of an expert in reverse proxies, but is that related to the above problem with revers proxies?
Would be glad about some help.
In my local network, I use nginx as a revers proxy on the same host as domoticz is running, just to have a decent url and not always have to put the port number. It looks like that and was working fine so far:
Code: Select all
########################################
# domoticz
########################################
# domoticz
location = /domoticz {
return 301 /domoticz/;
}
location ^~ /domoticz/ {
auth_basic off;
proxy_pass http://127.0.0.1:8085/;
proxy_ssl_trusted_certificate /opt/domoticz-docker/domoticz-com.pem;
proxy_ssl_verify on;
proxy_ssl_verify_depth 2;
proxy_redirect off;
}Code: Select all
https://<hostnname>/domoticz/But with
Code: Select all
http://127.0.0.1:8085/I'm not much of an expert in reverse proxies, but is that related to the above problem with revers proxies?
Would be glad about some help.
-
domovincent
- Posts: 30
- Joined: Friday 18 March 2022 13:55
- Target OS: Raspberry Pi / ODroid
- Domoticz version: 2026.2
- Contact:
Re: 2026.3 libwebem change results in unauthenticated admin access
@rugspin that is a different issue. There's some nice reverse proxy examples on the wiki. The logs of your proxy are usually very helpful as well.
On the main topic: the latest beta fixes the issue (About page states Compile Date 2026-08-02 18:55:45). Just installed and tested. X-Forwarded-For works as expected.
On the main topic: the latest beta fixes the issue (About page states Compile Date 2026-08-02 18:55:45). Just installed and tested. X-Forwarded-For works as expected.
Domoticz (RPI 5), Z-Wave, 433, MQTT, ANWB-energy. Happy user since 2017
-
rugspin
- Posts: 20
- Joined: Tuesday 04 February 2020 23:59
- Target OS: Raspberry Pi / ODroid
- Domoticz version:
- Contact:
Re: 2026.3 libwebem change results in unauthenticated admin access
Somehow, my reverse proxy was affected. The 2026-08-02 18:55:45 version showed that strange behavior.domovincent wrote: Monday 03 August 2026 9:23 @rugspin that is a different issue. There's some nice reverse proxy examples on the wiki. The logs of your proxy are usually very helpful as well.
On the main topic: the latest beta fixes the issue (About page states Compile Date 2026-08-02 18:55:45). Just installed and tested. X-Forwarded-For works as expected.
Now, I have 2026-08-03 16:43:35 and it works as before.
Thanks for the help.
-
domovincent
- Posts: 30
- Joined: Friday 18 March 2022 13:55
- Target OS: Raspberry Pi / ODroid
- Domoticz version: 2026.2
- Contact:
Re: 2026.3 libwebem change results in unauthenticated admin access
Oh, well, that's unexpected. But good news nonetheless. 
Domoticz (RPI 5), Z-Wave, 433, MQTT, ANWB-energy. Happy user since 2017
- gizmocuz
- Posts: 3026
- Joined: Thursday 11 July 2013 18:59
- Target OS: Raspberry Pi / ODroid
- Domoticz version: beta
- Location: Top of the world
- Contact:
Re: 2026.3 libwebem change results in unauthenticated admin access
You need to proxy to HTTP, NPM is doing the certificates
Quality outlives Quantity!