Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Jellyfin
  3. Jellyfin and OIDC passwords

Jellyfin and OIDC passwords

Scheduled Pinned Locked Moved Jellyfin
10 Posts 4 Posters 74 Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • eyecreateE Offline
    eyecreateE Offline
    eyecreate
    App Dev
    wrote last edited by
    #1

    After the migration to OIDC, I've had issues due to a number of jellyfin clients not supporting OIDC. In addition, cloudron only supports app passwords for SFTP, so I can't make an app password for these clients to by pass OIDC. Is there a way to allow using app password with jellyfin for clients who need it?

    luckowL 1 Reply Last reply
    0
    • eyecreateE eyecreate

      After the migration to OIDC, I've had issues due to a number of jellyfin clients not supporting OIDC. In addition, cloudron only supports app passwords for SFTP, so I can't make an app password for these clients to by pass OIDC. Is there a way to allow using app password with jellyfin for clients who need it?

      luckowL Offline
      luckowL Offline
      luckow
      translator
      wrote last edited by
      #2

      @eyecreate IMHO it should be possible to add user accounts via an administrator account. Does that help/work?

      2040a3dc-2958-4e6e-b15a-250d2d5d66b4-image.png

      Pronouns: he/him | Primary language: German

      1 Reply Last reply
      2
      • eyecreateE Offline
        eyecreateE Offline
        eyecreate
        App Dev
        wrote last edited by
        #3

        Thanks, I didn't consider adding a new user, but that seems to have worked. Would be nice to be able to use the exiting user, but this will work.

        1 Reply Last reply
        1
        • RoundHouse1924R Offline
          RoundHouse1924R Offline
          RoundHouse1924
          wrote last edited by
          #4

          Surely, the idea is to create an account per user, not per client. In that case, each user should be able to login on multiple clients using OIDC or app passwords, as appropriate to the client. If not, then OIDC is not a lot of use and a retrograde move from LDAP.

          1 Reply Last reply
          1
          • J Offline
            J Offline
            joseph
            Staff
            wrote last edited by
            #5

            @eyecreate @roundhouse1924 I guess you have to treat the user that you "Add user" like an app password. Remember that with LDAP all those clients have access to your raw password, so while the whole thing seems a step back, it at least helps a bit in securing your Cloudron password!

            RoundHouse1924R 1 Reply Last reply
            0
            • J joseph

              @eyecreate @roundhouse1924 I guess you have to treat the user that you "Add user" like an app password. Remember that with LDAP all those clients have access to your raw password, so while the whole thing seems a step back, it at least helps a bit in securing your Cloudron password!

              RoundHouse1924R Offline
              RoundHouse1924R Offline
              RoundHouse1924
              wrote last edited by
              #6

              @joseph said in Jellyfin and OIDC passwords:

              with LDAP all those clients have access to your raw password

              Are you saying that LDAP app passwords have access to, for example, the Cloudron dashboard? Surely, an app password created for a specific app (mail, Syncthing, Jellyfin, etc) can access ONLY the expected app.

              1 Reply Last reply
              0
              • J Offline
                J Offline
                joseph
                Staff
                wrote last edited by
                #7

                @roundhouse1924 I meant if you use the main password. If you used app password feature to start with, the security issue I mentioned does not make sense.

                1 Reply Last reply
                0
                • RoundHouse1924R Offline
                  RoundHouse1924R Offline
                  RoundHouse1924
                  wrote last edited by
                  #8

                  I seem to have cracked the original problem as described by the OP.

                  Cloudron's Jellyfin implementation has Quick Connect disabled; whereas the Jellyfin default is for Quick Connect to be enabled.

                  https://jellyfin.org/docs/general/server/quick-connect/ describes the procedure nicely.

                  In a nutshell, a 6-digit PIN is produced on the new client; same is then entered into an already logged in client.

                  Voila! No app passwords required.

                  1 Reply Last reply
                  3
                  • eyecreateE Offline
                    eyecreateE Offline
                    eyecreate
                    App Dev
                    wrote last edited by
                    #9

                    quick connect would require the client to support quick connect, though. I don't think Home Assistant, for example, supports quick connect.

                    1 Reply Last reply
                    1
                    • RoundHouse1924R Offline
                      RoundHouse1924R Offline
                      RoundHouse1924
                      wrote last edited by
                      #10

                      Unfortunately, the Home Assistant Jellyfin integration seems to demand username/password. So, in that case, you would need to create a user within Jellyfin for this purpose.

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search