Closed ajlennon closed 4 years ago
Fancy a go @MatthewCroughan ?
Are there any security implications? Is there a reason mosquitto doesn't enable it by default anyway @ajlennon ?
Good questions.
I think I'll look around and put that in the PR and discuss what I find regarding security, maybe enable it depending on env vars.
Response from Roger Light (Mosquitto creator)
"Security is much the same as for normal MQTT. Biggest difference is probably in keeping your credentials secret if you're using it as a web interface."
eg
https://blog.ithasu.org/2016/05/enabling-and-using-websockets-on-mosquitto/