Honest question, because I know multiple people who are not looking to jump ship since they already have the Plex Pass.

  • zuch0698o@lemmy.world
    link
    fedilink
    English
    arrow-up
    81
    arrow-down
    2
    ·
    2 months ago

    Ease of use for my users across multiple platforms with minimal tech knowledge on their end. I’m sharing my library with ranges from 12yo to 70. I need it to “just work” and it does that perfectly.

    • akilou@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      19
      arrow-down
      1
      ·
      2 months ago

      Couldn’t upvote this harder. Tried Jellyfin for 5 mins and was super confused why I couldn’t find sharing options. After googling and reading about reverse proxies and buying domains and shit I said fuck it and uninstalled

      • Rijunox@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        2 months ago

        Totally understandable, however basic tailscale version is free and you can just have that installed on all of the connected devices as a “reverse proxy”. You then use the ip adress from the server or main computer with the files and connect to its tailscale provided ip adress after turning it on and as long as you have port 8096 open on the server computer (http:/with your adress here:8096) you can connect to the server through the jellyfin app on the device you’ve installed it on.

        • SavinDWhales@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 months ago

          Yeah, I think you lost them after the first paragraph. 😉

          I am tinkering constantly with my home setup, but I am lacking the time to set up everything to my liking.

          So I am using neither Plex or Jellyfin, I am using Kodi and have a Webdav share available for when I am away on holiday. 😬😁

          But then I am only sharing with my closest family in my home network. Somehow it seems everyone is providing a streaming service for half the neighborhood and the remote family (or possibly a polycule with the drama associated, IIRC).

        • Rijunox@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          I found that the most simplicity way of doing it if you want remote acess otherwise you can connect locally without tailscale

      • Reaper948@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        6
        ·
        2 months ago

        I never fully understood this argument as you would have to do that anyways with plex unless you’re using their proxy which would just artificially rate limit all of your users. But I do realize that jellyfin doesn’t have an email invite system in place which really is my biggest issue

        • akilou@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          8
          ·
          2 months ago

          What’s the “that” that you’d have to do anyway with Plex? I had to do nothing of the sort. I asky friends and family to make a Plex account and ask what email address they used. Then I give that email access to my library

    • kiol@discuss.onlineOP
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      14
      ·
      2 months ago

      Did you try Jellyfin? I’ve had success with Jellyfin once I’ve been the one setting up the TV app, etc. It did just work, because users found it very simple in comparison to Plex. If anything, they like how Plex shows more things beyond the collection.

      • Technoguyfication@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        27
        ·
        2 months ago

        I’ve been the one setting up the TV app, etc.

        That is exactly the issue. I can’t personally set up the app for all my users. Most of them are not in my household.

        • kiol@discuss.onlineOP
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          11
          ·
          2 months ago

          Me either, but I don’t expect them to setup any sort of app themself (including Plex).

          • Khanzarate@lemmy.world
            link
            fedilink
            English
            arrow-up
            27
            ·
            2 months ago

            That’s his point though, he does expect them to be able to set up themselves, and apparently Plex is good for that.

            • kiol@discuss.onlineOP
              link
              fedilink
              English
              arrow-up
              4
              arrow-down
              6
              ·
              2 months ago

              Yes, in my case I personally had to setup both clients (Plex and Jellyfin) for the family members myself.

        • gdbjr@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          2 months ago

          Thanks do letting me kno about this. I tried it and it does look good. Sadly for me at least it does perform well. Moves slow between options and libraries. And the Live TV Guide isn’t working at all. That could be a me issue, but the slowness is unacceptable. Once I have more time I will play it more and probably reach out to the Dev.

      • keyez@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 months ago

        I use both at home, mostly plex though and I have about a dozen people who watch remotely and keeping the remote access private and secure I’m not putting jellyfin behind a public reverse proxy. Not feasible to setup wire guard for a dozen people across 4 states and troubleshooting those tunnels when Plex does all that for me. Plus Plex allows them to manage and reset their password without my intervention

  • gdbjr@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    arrow-down
    1
    ·
    2 months ago

    The client apps on Apple TV are just not good. I have tried swiftfin which is slow and I find it not very visually appealing. There there is infuse which does look better, but is missing features and requires a subscription for full functionality. If there is a app I’m missing I would be happy to try it.

    I keep Jellyfin up to date and check in or it from time to time. Even have watchstate so my watched history stays updated. Hoping one day there will be a good Apple TV app and I could fully switch.

    • violentfart@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 months ago

      Same boat on Swiftfin and Infuse.

      There’s one I recently found called Moonfin that does many things well. It’s my current go-to until official apps catch up.

      • thehatfox@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        I hadn’t heard of Moonfin before, it looks promising as an Apple TV client. Any pitfalls with it?

        • violentfart@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          2 months ago

          I use it on my tablet and it direct plays all of my (limited) media, and also handles and organizes downloads to the device with reencoding options. Playback is more reliable and efficient compared to Swiftfin. UI seems modeled after existing streaming services.

          They also have a plugin that “updates” your existing Jellyfin install so the features show up on the official client, but uses code injection which I didn’t like and so did not partake. The sense I get is that they push for features and implementation while official Jellyfin development takes a much more conservative approach. I hope they can work together some day.

    • kiol@discuss.onlineOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      Absolutely, my other friends are doing the same. They keep their state synced between services and keep checking in on the AppleTV client improvements for Swiftfin.

    • Reannlegge@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      2 months ago

      I use Jellyfin on my phone and just do the screen share to my AppleTV.

  • fartographer@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    2 months ago

    I absolutely love jellyfin and frequently take advantage of its features. But the client absolutely suck butt. When I can hardly get my mom to remember which app on her TV lets her watch what, I can’t also have her fucking around with play buttons that don’t do what they say, a “continue watching” list that’s often haunted by episodes that have been marked as watched, or inscrutable menu icons mashed into the top-right corner of a media browser.

    And don’t get me started on getting people logged in on the client.

  • douglasg14b@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    3
    ·
    edit-2
    2 months ago

    Problem is access outside your home for family and friends.

    There are serious security gaps that make it a non starter to expose to the internet.

    I’ve been using Jellyfin ever since they forked out of Emby, and honestly, it’s the biggest complaint that I have. It is incredibly difficult to make it available to friends and family who are on various devices, networks, so on and so forth.

    Whereas Plex “just works.”

    • uthredii@programming.dev
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      3
      ·
      2 months ago

      Why not use a zero trust VPN like netbird? It is fully open source.

      You can create a reverse proxy that requires a password to get through to jellyfin. I think there is a limit of like 5 for this though (unless you pay or self host).

      • Nibodhika@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 months ago

        Because clients would probably fail if there’s an authentication layer on front that they’re not expecting.

    • hexabs@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 months ago

      Wait what? I have been sharing my jellyfin using a cloudflare tunnel to the endpoint.

      Could you elaborate on the security gaps? How can I pen-test myself to see if I’m vulnerable

    • karlhungus@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 months ago

      What security gaps in particular? I did have to reverse proxy to get it to https, are there additional security issues?

        • karlhungus@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          thanks; for anyone looking, the issues have been split out at the bottom, none of them are addressed as of this writing. I don’t know that I feel like they are that serious (most of them allow you to play things if you know an ID), but they are the kind of thing you’d see in a project where there are bigger security issues.

  • blitzen@lemmy.ca
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    2 months ago

    Agree with most of the other comments here, but number one for me is PlexAmp.

    • kiol@discuss.onlineOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      Dedicated music on Jellyfin is something I’ve never been able to wrap my head around. Would be curious if others have figured something out that works really well within the same ecosystem.

    • Geologist@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      100% this. I couldn’t find any other good carplay music player that wasn’t a subscription like Spotify.

  • emmy67@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 months ago

    This is all a fascinating thread because everyone says Plex “just works”

    I started using jellyfin about 6 months ago. I don’t really know anything about plex use. However, jellyfin worked out of the box for me. Set up with a docker container and have never had any problems with it.

    Its never failed to load media, or loaded duplicates or any of the other random things others have mentioned here.

    For the most part it feels like people in the thread have just used Plex for a long time and had their first impression of jellyfin years ago and probably haven’t checked it out since.

    Which, fair play to them, life gets busy and setting up and migrating a media library is something that takes at least a couple hours which could be spent doing anything else.

    If people are new, I’m sure they won’t even bother with Plex and their ridiculously high fees. I cannot see Plex maintaining their userbase at this rate.

    With them unable to maintain their userbase, I give it a year before they cancel lifetime passes and 2 years or so before it’s completely enshitified and unusable.

    • Final Remix@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      2
      ·
      2 months ago

      I’m at the user level of “people keep saying docker… what the fuck is a docker?” -looks it up- “this explains nothing.”

      Plus, I got lifetime Plex a while back, and can use it to stream videos to my remote classroom for examples in class.

      • emmy67@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        2 months ago

        Yeah I understand that. I was also at that level when I started. It did take me a while to understand the docker compose syntax. But was pretty simple once I got into it. I understand not wanting to dive that deep though.

    • PmMeFrogMemes@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      yeah as a former plex user I can confirm the setup is way more annoying. for me “just works” means I spin up the container, point it at my media library, and I’m done. never had to make an online account or pay for anything with jellyfin. I agree with ppl that say the plex web UI and native apps are more polished but that’s about the only positive

      • beeb@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        2 months ago

        Not it’s mostly about remote access anywhere without VPN. Forcing your friends and family to use a VPN to access a jellyfin instance securely is not something everyone is willing to do (and might be impossible on some devices).

    • ripcord@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      2 months ago

      Did you read what they are saying Plex “just works” a[ that Jellyfin doesn’t?

    • 1371113@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      3
      ·
      2 months ago

      I tried jellyfin/emby for the third time about 6 months back. I had heaps of encoding issues (not playing) with x265 and lots of issues with dolby encodes (running it through my home theatre from a 2017 nVidia shield using the official client). I even went so far as to run a separate ffmpeg instance but no dice. Until it’s not a hobby project and ‘just works’ I’m not interested.

  • cmeu@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    2
    ·
    2 months ago

    I like Plex.

    When I bought my Plex lifetime pass I saw it as an investment. So far, it’s paid off handsomely.

    I’m still getting great experiences, able to access it from anywhere in the world, on basically any device, seamlessly and simply.

    I get it that the jellyfin community is really excited about their thing - I just am not.

    I’ve run jellyfin, it was kind of cool I guess, but there was nothing compelling about it. So I uninstalled it. What is jellyfin’s “must have” feature, anyway?

    I wouldn’t go out and build a new car when I’m perfectly happy with my 10-year old sedan. If you’re expecting me to go through that just because the new ones cost more than I spent years ago, you’re insane. I wouldn’t go and re paint my house just because the old company now charges new customers more for their paint.

    I paid for it, it works well. There’s no reason (except all the FUD I keep seeing on lemmy,) to even think about dismantling and recreating it with something new.

    Keep building your dream tool Jellyfin people - Godspeed, but your community should target acquiring net-new users instead of trying to scare and poach happy users away from what they already have.

    • Billegh@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 months ago

      Same here, but I am also maintaining jellyfin alongside it. In case Plex decides that “lifetime” means something other than what I expected it to mean. I’ve long ago gotten my $80 of usage out of it.

      Jellyfin is… ok. It works, it works consistently, and it is consistently almost great. But I provide “cable replacement” and “streaming supplement” services to family that doesn’t live in the same house, and will all likely break a box that managed a VPN.

      Given the above, we’ll ride out Plex until they go nuts. Hopefully jellyfin will be polished enough for child use by then.

  • chronicledmonocle@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 months ago

    Jellyfin is great and I run both. However, sharing access with family is a PITA compared to Plex. I paid for Plex Pass lifetime at the $75 and have no reason to fully move. Keeping Jellyfin around in case Plex tries to rug pull lifetime passes, though.

    • Mr_Dr_Oink@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 months ago

      I set up tailscale on my jellyfin box and my family can use their phone to access the server by turning on tailscale (just open the app and toggle it on then open jellyfin) and cast to their Tv. Not as smooth as plex but works for us and the tailscale means its all encrypted.

      • chronicledmonocle@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        I use GeoIP restrictions on WAN and use a TLS offload on a load balancer in front. Problem is the older members in my family look at me weird when I give them a URL, username, and password. They just ask if they can use their Apple or Google account “like we do with Plex”. So…for now Plex stays.

  • youmaynotknow@lemmy.zip
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    3
    ·
    2 months ago

    I see so many here with the argument of 'I already have a life time pass, so this increase doesn’t affect me". And in all honesty, that’s a mostly logical take on this if you already have it.

    However, the signs are clear. This is a first step. I don’t believe (and I’m very aware I could be wrong) for a second that the executives are actually expecting people to grab a pass for 750 dollars, but they expect a minimum amount of people to go ahead and do it anyway. Once they see this conversation is dying down, and that no money is coming in on that end, they will switch to another method of getting money (the investors need their money, right?).

    From there, the sky’s the limit. Charge extra if your instance has more than 3 users, or charge the users that are not you. Cap your quality at 720p unless you fork over 2 dollars per month. Pay for this new AI feature that is not included in your pass. Pay to disable this AI feature that was forced into your pass.

    For pass holders there is no problem with this increase, it’s what invariably happens when companies start moving towards the money grab path.

    We’ll just watch from the sidelines and will be here to help you migrate once (not if) these things happen.

    • amorpheus@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      5
      ·
      2 months ago

      We’ll just watch from the sidelines and will be here to help you migrate once (not if) these things happen.

      Would be nice if you guys could do that quietly. Not every change in how Plex does business needs to echo through social media. We’ll let you know when the time comes.

      • jumjummy@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        2 months ago

        It’s like the standard ”I use Arch btw” meme, but maybe there are too many Linux users on Lemmy so these people need to find a new way to feel special.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        2 months ago

        Would be nice if you guys could do that quietly. Not every change in how Plex does business needs to echo through social media.

        1000003962

        I’ve never seen a bunch of pretentious assholes react so hard to a product they don’t use so loudly. not even Linux vs Windows users are this insufferable.

        then you have an actual JF developer stirring the shitpot up with posts like this.

        • amorpheus@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          2 months ago

          I really don’t mind them capitalizing on this, the echo chamber just makes it super annoying.

          I’ve never seen a bunch of pretentious assholes react so hard to a product they don’t use so loudly.

          Very apt way of putting it.

          Here’s another meme that came to mind:

          • dustyData@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 months ago

            Always remember that the point of this scene is that the guy saying “I don’t think about you at all” is an insecure prick who is constantly anxious of losing his power and status. He thinks about it all the time, this scene is just bravado to keep up a façade of suave indifference, but inside he is spiraling out of control because the other dude took a project away from him. So, this meme doesn’t say what you think it says.

      • Noggog@programming.dev
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        I think the thing is, every news cycle there IS a few people who’s time has come. And so jellyfin is brought up

        I say this as someone who has a plex lifetime and is still using plex. I appreciate everyone getting riled up and passionate, because that means the fallback will be that much more polished when my time comes.

        You sound like someone pulling up the ladder and yelling at the people below to shut up. Anyone new to the space is dealing with this absurd $750 lifetime price. Of course they’re yelling

      • youmaynotknow@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        Wy do it quietly when we can help others know about the alternatives, how to get them, how they work and what would be the cons and pros?

        That’s one of the utilities of social media, no?

  • csm10495@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 months ago

    Have lifetime already. No reason to jump. Generally it just works.

    No need to have another project while Plex still works fine.

    • JustAnotherPodunk@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 months ago

      Same. Got it cheap. Untill they break lifetime. Why bail? I’m not compromising my own experience because someone else was too cheap, lazy or slow.

      Is it messed up what they are doing? Yeah. But that’s not my fault. Nor is someone missing out on the very clear signposts about what was going to happen. I’m not sacrificing my user experience and investment to justify someone else’s missed opportunity or vendetta.

  • melsaskca@lemmy.ca
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    1
    ·
    2 months ago

    I use Plex to save money on plumbers because I cannot solder. Plex gives me the ability to exact repairs myself.

  • FauxLiving@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    2
    ·
    2 months ago

    I run both, I got the lifetime license for under $100 and it is much easier to have my various family members install the Plex app and then login than to get them on my VPN to access Jellyfin.

    Grandma ain’t installing Tailscale

  • SethranKada@lemmy.ca
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 months ago

    I got a lifetime pass for cheap ages ago and while the company isn’t doing so well, Plex itself isn’t getting any worse. Its just not getting better.

    As long as that continues, then I’m fine with staying. I only really use it for Plexamp anyway.

  • Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    2 months ago

    I’m not using Plex, but I feel like I can answer my complaints about using jellyfin.

    My biggest complaint is the lack of clients. It is such a pain in the butt to install jellyFin on all of my products.

    My second complaint is the security design. They’ve had open issues about unauthenticated endpoints for three or four years now. And whenever the issue gets so old that it starts to look bad, they refactor the issue into a newer issue abd bury it in the sand.

    For a while this was done under the guise of maintaining legacy client support, but just recently it looks like they’re starting to focus on more security, and I’ve noticed some of those security holes are being closed finally, but it’s a major concern for me that they’ve been open for as long as they have.

    • ShortN0te@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 months ago

      My second complaint is the security design. They’ve had open issues about unauthenticated endpoints for three or four years now. And whenever the issue gets so old that it starts to look bad, they refactor the issue into a newer issue abd bury it in the sand.

      You mean that one issue that is still open and linked in the “security and quality” tab on github?

      • Pika@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        2 months ago

        i feel like one issue is a bit of a downplay here, considering that it’s 12 different issues being shown as one mega issue. but yes that has most of them

        But that’s also the most recent version of it. Some of those issues that they have listed there has had previous issues that were closed to be consolidated into that mega issue, which then was closed to be split into their own issues again.

        • ShortN0te@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          i feel like one issue is a bit of a downplay here,

          But how does it matter if the issue is closed or open? It is linked and stated early and tracked.

          That issues get merged and closed is quite normal when there arw duplicates.

          Also, i think the oppoaite. The issues get ‘upplayed’. Which one of these are you actually worried about? And how does they affrct you?

          • BakedCatboy@lemmy.ml
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 months ago

            Doesn’t it affect all of us in that we cannot safely run it exposed to the internet? I mean I still yolo it and run my jellyfin completely exposed because there’s no way I’m guiding anyone through setting up wire guard or configuring clients to do additional auth, but still. I would love to not worry about that.

            • ShortN0te@lemmy.ml
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 months ago

              The question is, are the vulnerabilities actually a risk for your setup?

              Should they be fixed? Absolutely.

              But do they affect you? For me its basically a no.

              A vulnability can be a nothing burger or critical issue that needa to be fixed. But it depends.

              • BakedCatboy@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 months ago

                If it’s a nothing burger then they should come out and say it’s fine to run your instance publicly then

                • ShortN0te@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 months ago

                  No, it is impossible to certify security, it’s only possible to certify insecurity.

                  They could only say something like “it’s designed to run exposed” or something like it.

                  You can pay for the audit if you like and still there would be no certainty.

                  I assume, before they say something like that they want a completely new API. But this would break every single client.

          • Pika@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 months ago

            I don’t think downplaying them is the way to go though, Some of these issues have been in existence since 2019.

            Like I mentioned though, it does seem like its starting to be worked on, a few of them are in progress the one I really don’t like is #13991 which is a combination of:

            • #13982 which allows for an alternative user to be able to interact with the client readonly as if they are another user as long as they have the user id and any valid auth token (which includes that current users auth token). original issue: #5210 2/10/2021; status: partially mitigated 5/11/24 with v10.9 which locked modifying data behind elevation but getting the data still is able to be done in select endpoints still
            • and #13990 Which gives any user with standard login access(like say the common family tv’s account) the ability to access the getUser endpoint and retrieve said previous user id. In progress since 12/2/25 reported via the megathread creation 3/8/2021

            For example I just made a user with no access period to any collection, just a login access and took the auth token for the user. I was able to grab every user on the servers ID including hidden and administrative users as well as users who don’t use jellyfin’s auth system, then couple that to see what the users login method was, when their last access was, what folders they were allowed to use[note these are represented as id’s the client can’t actually parse them so you need to traverse the api for it], how many max sessions they could have, etc. without actually having access or logging in as that user or even being an administrator. If you snag an admins userid it even gives you internal server data such as logging paths that the server uses on the dashboard, the transcode path, the metadata path, what networking settings the server is using such as trusted ip nets the port jellyfin is using by default your certificate file and password if configured[although password may be ommited/the field left blank i didn’t test internal certs]. From there you can even recurse through the folder UUID’s provided via “enabledfolders” and the other folder restrictions on the users endpoint and get the name of the folders which could leak personal information about the library or the user because the 403 request it returns leaks the name of the library as part of the error message. “username is not allowed to access Library name

            Thankfully it’s finally being worked on but, I do think it’s worth stating the timeframe on them and that those issues do still exist.

            Just like I think it’s worth stating that media endpoints are still fully unauthenticated as well, so as long as you can guess the full file path, you can md5 it and get unauthenticated media paths, but that’s in progress as well, its just super slow because that breaks third party clients.

            • ShortN0te@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 months ago

              I don’t think downplaying them is the way to go though, Some of these issues have been in existence since 2019.

              I am not downplaying them. And yes they should get fixed. But this attack needs access to an account on your server.

              so as long as you can guess the full file path,

              Yes, also should be fixed, probably by some sort of salt and authentication, but can be easily prevented by adding a random character in the base/root path to the media. Especially with docker or similar, thats an 1 min fix.

              And even if not? What then? Why would someone want to attack that?

              Those are not good, no. But no deal breakers and actually more blown up then downplayed imho.