From 43102c617d0ea2824e60e56766cad004d4a635b3 Mon Sep 17 00:00:00 2001 From: bonamin Date: Wed, 30 Sep 2026 00:58:59 +0300 Subject: [PATCH] docs(mqtt-auth): note VPS broker has allow_anonymous false but no TLS listener yet The full mosquitto.conf (2026-09-30) has a single plain listener on 1883, used by the boards. The phone app sends a Firebase ID token as its MQTT password, so a TLS listener must be added before app users go live. Co-Authored-By: Claude Opus 5.5 --- docs/mqtt-app-user-auth.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/docs/mqtt-app-user-auth.md b/docs/mqtt-app-user-auth.md index 6455fe2..2577fa9 100644 --- a/docs/mqtt-app-user-auth.md +++ b/docs/mqtt-app-user-auth.md @@ -137,6 +137,9 @@ When those lines stop appearing, set `MQTT_ALLOW_LEGACY_PASSWORD=false`. - Already set correctly: `backends files,http`, `http_host 172.20.0.1` (Docker bridge), `http_port 8000`, both URIs, `http_method post`, `params_mode form`, `response_mode status`, `cache true`, `cache_reset true`. +- `allow_anonymous false` ✓. Only listener: `listener 1883 0.0.0.0` (plain TCP, used by + the boards). **No TLS listener yet.** One must be added for the app (a second + listener, e.g. 8883 with `certfile`/`keyfile`) while keeping 1883 for the boards. - Still to change: `auth_cache_seconds` and `acl_cache_seconds` are **300**. Lower both to 60 before app users go live, or a block/unassign can take up to 5 minutes to apply.