Activate the VRED Professional internal Web Server and turn on debug mode, if necessary. Activating the Web Server allows the execution of remote Python commands. A local firewall is recommended.
In the Menu Bar, click Edit > Preferences, then on the left side of the dialog box, select General Settings > Web Interface. After making any changes, press Apply and Save to save them.
Base
Encrypted HTTPS Only - Enables (rejects) or disables (allows) unencrypted connection requests.
Existing configurations (created before version 2024) will not be changed; however, new ones will only accept https, unless this option is disabled.
Certificate File - Generates a self-signed certificate. You will need to define the certificate to use, then define which certificates your browser trusts. This is done using a self-signed certificate. Install this certificate in the Windows Certificate Trust Store, to avoid browser warnings about invalid untrusted certificates.
Select Certificate File - Defines the certificate used.
Create Self-signed Certificate - Opens the Create Self-signed Certificate dialog to create a self-signed VRED certificate to use to sign individual VRED webserver instances.
Certificate Information - Opens the Certificate Information dialog and provides information about the certificate, like version, serial number, and validity.
Custom Web Root Directory
These options are for enabling and setting a custom web root directory. If you write your own web applications with an embedded VRED Stream, like our VREDStreamApp that can be accessed via web browser from any device, store the custom webpages in a local file location. Define this in Directory, so the VRED WebServer can execute the webpage.
Custom HTML should not be called index.html, as this is already in use for our VRED Hub page. After the directory is set to your custom page in the preferences, for example, MyIndex.html, access the page from any device using the following URL: http://hostname:8888/MyIndex.html.
We have also added new URL properties for the VRED Stream and it is now possible to set fullscreen, disable keyboard input, and disable navigation directly in the URL.
Directory - Only available when Enable File Access is enabled. Specifies the web root directory for accessing files.
Select Web Root Directory - Defines the web root directory used.
Host Access
These options set which sources the web browser will trust.
Restriction - Determines whether there are restrictions as to which sources your web browser will trust.
Authentication
Adds an extra layer of security, but requiring a user to log in and enter a password.
How to Generate a Self-signed Certificate
VRED has added a self-signed VRED certificate authority. Use this certificate to sign individual VRED webserver instances. You will need to create a certificate, define access, and if needed, set authentication.
Select Edit > Preferences > General Settings > Web Interface.
Next to Certificate File, click
to define the certificate to use.
Click
(the Create self signed certificate button) to create a certificate, enter a unique name for the certificate, and click Save.
In the Host Access section, in Restriction, set which source the web browser will trust.
In the Authentication section, change Authentication Mode to Log in with username and password.
Click the Add button, then add a username and password.
Click Apply and Save. The new user will appear in the User section.

Cross-Origin Resource Sharing (CORS)
This features provides a way for a web application running on VRED to access content from another website, to do something such as play a YouTube video.

Cross-Origin Resource Sharing (CORS) for the VREDServer
Cross-Origin Resource Sharing (CORS) was also implemented for the VREDServer in some requests.
Access-Control-Allow-Origin: *
Access Control Allow methods: GET,HEAD,PUT,PATCH,POST,DELETE
Access Control Allow Headers: content-type
Access-Control-Allow-Origin: *
If the HOST or PORT is different from the one running the current website/web application and the web application tries to send a request to this other host via Javascript, the HOST will agree to the request. Otherwise, the browser will not send the request.
The browser asks the different HOST or PORT in a preflight request with the HTTP method "OPTIONS", if the HOST agrees. If it responds with the HTTP headers as in Preflight above, then it looks to the actual request.
The browser sends the actual request. Here, too, an HTTP header must be included as above in Actual request This must be set; otherwise, the browser will not process the response.
For additional information on the headers and how they work, visit Access-Control-Allow-Origin and Cross-Origin Resource Sharing (CORS).