# Insecure favicon?

**URL:** <https://discourse.nodered.org/t/insecure-favicon/94192>\
**Category:** Dashboard\
**Tags:** dashboard-2\
**Created:** [26 December 2024 21:36 UTC](https://discourse.nodered.org/t/insecure-favicon/94192 "2024-12-26T21:36:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [26 December 2024 21:36 UTC](https://discourse.nodered.org/t/insecure-favicon/94192/1 "2024-12-26T21:36:02Z")

</div>

Trying to change my dashboard icon for use in a PWA, but hitting a 'Mixed Content' issue because the icon is not served over https, but is served on a local IP address (same raspberry where node-RED is running).

I can see the image if I navigate my browser to [http://192.168.0.8:1880/images/tail.png](http://192.168.0.8:1880/images/tail.png)

If I check the browser console I see the following;

> Mixed Content: The page at '[https://myserver/dashboard/page1](https://myserver/dashboard/page1)' was loaded over HTTPS, but requested an insecure favicon '[http://192.168.0.8:1880/images/tail.png](http://192.168.0.8:1880/images/tail.png)'. This request has been blocked; the content must be served over HTTPS.

I'm guessing this is a browser restriction, and not node-RED's fault.  
If there isn't a workaround, I have a plan B 😉

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [26 December 2024 22:11 UTC](https://discourse.nodered.org/t/insecure-favicon/94192/2 "2024-12-26T22:11:52Z")

</div>

Hi @Paul-Reed

Actually - I wonder if this is D2 not honouring the host name and/or protocol.

You can try adding the favi meta directly in a template node (set in the head)

```auto

<link rel="icon" type="image/x-icon" href="https://…">

```

You might need to change type to image/png

Note: I know very little on D1 or D2 - so this really is a guess

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [27 December 2024 15:25 UTC](https://discourse.nodered.org/t/insecure-favicon/94192/3 "2024-12-27T15:25:28Z")

</div>

Thanks for the suggestion @marcus-j-davies, but after checking [Bart's excellent Tailscale guide](https://github.com/bartbutenaers/Node-RED-Tailscale-Tutorial/blob/main/docs/extend_reverse_proxy.md), it was very easy to tell Tailserve to serve the icon file via https, which worked great.

Now, on my phone, my dashboard PWA icon is my own, so I don't get it confused with the Node-RED forum icon etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [10 January 2025 15:25 UTC](https://discourse.nodered.org/t/insecure-favicon/94192/4 "2025-01-10T15:25:41Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
