86
Sharing Jellyfin (poptalk.scrubbles.tech)

Hi folks. So, I know due to a myriad of reasons I should not allow Jellyfin access to the open internet. However, in trying to switch family over from Plex, I'll need something that "just works".

How are people solving this problem? I've thought about a few solutions, like whitelisting ips (which can change of course), or setting up VPN or tail scale (but then that is more work than they will be willing to do on their side). I can even add some level of auth into my reverse proxy, but that would break Jellyfin clients.

Wondering what others have thought about for this problem

you are viewing a single comment's thread
view the rest of the comments
[-] MaggiWuerze@feddit.org 10 points 1 year ago

It's not impossible, Far from it. The ids are not random uuids but hashes derived from the path. Since most people have a similar setup to organize their media, this gets trivial very fast

[-] synestine@sh.itjust.works 2 points 1 year ago

If you're worried about it, make sure to not use a default path. Then legit clients are fine but these theoretical attackers get stymied.

[-] MaggiWuerze@feddit.org 1 points 1 year ago

What? Why would I have to make my library harder to manage just because Jellyfin devs can't get their act together? They should just start a api/v2 and secure it properly while allowing to disable the old one

[-] blitzen@lemmy.ca 2 points 1 year ago

I’m with you that you shouldn’t have to, but putting your media directory one level up in a randomly generated directory name isn’t too bad. ~/[random uuid]/media/… may not be a terrible idea in any case.

[-] synestine@sh.itjust.works 0 points 1 year ago

Ah, so you're the kind who loves bitching about things online, but won't lift a finger to defend themself, gotcha.

What I mentioned prior doesn't change anything about library management in the slightest, you just wanted an excuse.

[-] MaggiWuerze@feddit.org 2 points 1 year ago

No, I'm the kind who thinks security by obscurity is bullshit. But you do you

this post was submitted on 25 Apr 2025
86 points (97.8% liked)

Selfhosted

62781 readers
1050 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS