More security: Other passwords for JSON and Domoticz website

Use this forum to discuss possible implementation of a new feature before opening a ticket.
A developer shall edit the topic title with "[xxx]" where xxx is the id of the accompanying tracker id.
Duplicate posts about the same id. +1 posts are not allowed.

Moderators: leecollings, remb0

Post Reply
RMU
Posts: 17
Joined: Wednesday 19 February 2014 22:48
Target OS: Linux
Domoticz version:
Location: Netherlands
Contact:

More security: Other passwords for JSON and Domoticz website

Post by RMU »

Hello all,

I dont know if this is discussed before (cant find any with search) but i wonder the following:
If you want to switch things through a JSON request (like: http://<username:password@>domoticz-ip<:port>/json.htm?api-call) it works fine, and i understand that you need to use a password.
But would it be possible to use Form authentication as default for the website, and set a seperate password for JSON requests?

Because now i need to set authentication for all things (JSON and Website) to Basic auth. and use the username/password for both JSON request and login on the website. In my opinion that is not very safe.

And if the above can be created would it also be possible to use something like Google authenticator as Two factor authentication method to login at the website? So that it is safer to use from the Internet.
User avatar
gizmocuz
Posts: 2484
Joined: Thursday 11 July 2013 18:59
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Location: Top of the world
Contact:

Re: More security: Other passwords for JSON and Domoticz web

Post by gizmocuz »

if you call the json requests locally, why dont you add 127.0.0.1 to the local networks, or any other ip address that calls it ?

we are currently busy with other implementations, but 2way is on the todo list, bu when using https for now its pretty save
else change the password every now and then, same as you do on your system (linux/windows)
Quality outlives Quantity!
RMU
Posts: 17
Joined: Wednesday 19 February 2014 22:48
Target OS: Linux
Domoticz version:
Location: Netherlands
Contact:

Re: More security: Other passwords for JSON and Domoticz web

Post by RMU »

gizmocuz wrote:if you call the json requests locally, why dont you add 127.0.0.1 to the local networks, or any other ip address that calls it ?
The problem is that i dont only run it locally, i also plan to run them from my phone (NFC tags) with mobile network.
gizmocuz wrote:we are currently busy with other implementations, but 2way is on the todo list, bu when using https for now its pretty save
Ok thats nice. Waiting for that!

Speaking of HTTPS, when you run Domoticz and use the https port it gives back a *.domoticz.com certificate. will it also be possible to load your own certificate into Domoticz?
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest