
An ESP32 can be controlled beyond the local network, but internet-facing actuation requires a security design before a dashboard is built. A sound architecture separates the user interface, backend service, and device, and treats every command as an authenticated, time-bounded event.
Recommended architecture
Use an HTTPS API rather than clear-text HTTP requests. The dashboard authenticates the user, the backend checks authorisation before accepting a command, and the ESP32 connects through TLS or a secure MQTT broker to retrieve only commands assigned to that device.
Essential controls
- Hash passwords securely and keep secrets out of source code.
- Use prepared statements, request rate limits, input validation, and audit logs.
- Give commands a sequence number or expiry time to prevent replay of stale actions.
- Define fail-safe output states for loss of connectivity and reboot.
- Protect browser actions against CSRF where cookies are used.
Internet exposure
Do not forward a public port directly to an ESP32. Prefer a VPN, reverse tunnel, or managed MQTT/IoT service. Owning a domain does not remove dependencies on hosting, DNS, certificates, or service availability, and it does not provide security by itself.
Prototype on an isolated network, then test authentication, connection failure, and logging before external deployment.
اترك تعليقا