I have just been going through a HELL of a time building a web-based app ("PWA" in progressive lingo) that needs to auto-discover certain devices on the user's LAN. This is a rebuild of an existing AIR-based app that's been in use in a corporate setting for 10 years and needs to be replaced because "death of flash". The AIR app I wrote back then handled discovering the local devices fantastically well. The problem now? Mixed-origin blockades. I can't get into all those devices and routers in each location to set up local DNS servers and maintain certificates. So the connection from the ultimate app to the local node has to be unencrypted. But this means the only answer to a web-based discovery app is to have it be served over HTTP as well.
Interesting thing google missed when trying to prevent people from doing this exact thing with PWAs: If you have a valid manifest and service worker, Chrome won't run the service worker if it's not served over SSL, but it WILL include the app name and icons and let you save it to the home screen on Android; it will even cache a good deal of what you intended.
For auto-discovery, I used a fuckton of hidden iframes loading asynchronously and waiting for any window.postMessage that matches what I want from a local device.
Seriously, Google has made my life fucking miserable as a solo dev. They don't want anyone to be able to write an IoT app without going through them.