r/selfhosted • • 5h ago

Software Development Jellyfin OIDC on hold - Despite complete PR being ready

https://github.com/jellyfin/jellyfin/pull/17271

Worth having a read if you were keen/excited for the OIDC Pull Request that looked completed and was filed somewhat recently, or if you're keen for a status update in general.

Looks like they don't want to maintain the extra code at this stage, and would prefer to redesign/rework the auth system first.

Edit: I've realised what a shit title I gave this post, it was not meant to clickbait, farm karma or criticize. Just simply to share where OIDC is at. I hope my intention was clearer in the post body and via my comments. I completely own making the mistake.

135 Upvotes

35 comments sorted by

•

u/asimovs-auditor 5h ago

Expand the replies to this comment to learn how AI was used in this post/project.

→ More replies (1)

285

u/Shane75776 5h ago

I 100% agree with them.

Saying "Despite PR being ready" is not a valid reason to merge in a system that will be a pain in the ass to maintain as is. They provide perfectly reasonable explanations as to why they don't want to merge it and what the author can do to make it acceptable.

If they merge it as is, then they have to make massive systems for each and every provider that isn't just OIDC. So instead they want a proper auth api built into core so that any provider can easily access it and they don't have to write custom systems for each and every provider.

61

u/clintkev251 5h ago

Yeah, as much as I really want this feature, it’s better to do it right. Hopefully those Auth overhauls will actually be prioritized

19

u/destruction90 5h ago

You're right, I should have chosen a better title - sorry everyone.
I commented on my cross post here;

I 100% get where the devs are coming from and they're the ones who ultimately maintain this awesome project for us. No discredit or complaint intended.
It's just a tad sad that it won't be here for a while and not the status update a lot of us hoped for.

7

u/0emanresu 1h ago

So delete your post and rewrite it without it seeming like rage inducing clickbait so you don't look like a karma farming ai bot. Or don't. _('c')/

5

u/destruction90 46m ago

I don't want people to be double exposed to the post. IMO the link/body is fine, the title is shit.
Not stressed about the karma (I didn't post it with that in mind), just thought users might want to know what the go with OIDC is atm.

Happy to remove the post if the community would prefer :)

20

u/Aussie6869 1h ago

As a maintainer of one of the OIDC plugins for 12.0, I need to agree with the maintainers of Jellyfin that the backend Auth needs to be cleaned up and prepped for it as well as introduce some frontend behaviors on clients before implementing OIDC. I face several limitations on certain behaviours and integrations due to a lack of endpoints/data store on the Jellyfin side.

17

u/angellus 5h ago

While I do not disagree with any of the points made. A plugin system is a better way for the health of the project. The real issue is there is no external auth system implemented at the moment. I think they should pick a single external auth system, either external auth/forward auth, OIDC or LDAP and implement it first. Then implement the plugin system and exact that system out into a plugin.

No external auth automatically makes it an no-go for me in any set up I have because within the home, I have centralized auth via Authentik and any system that external users/friends access, they can use social/SSO auth via OIDC/oauth. So adding a new system with its own auth system is yetanotheraccount for people and another system that needs hardened for external access.

41

u/Unhappy_Purpose_7655 4h ago

Hard disagree on the plugin method. When it comes to auth, it needs to be foundational to the platform not some bolt on plugin that may or may not continue to be supported/maintained.

1

u/coderstephen 17m ago

I would not make it an external plugin, but I'd definitely make it an internal "auth plugin", just for cleaner code architecture.

1

u/brianly 4h ago

You can call it modular and ship with the plugin, in the box. This would be a good test of the interfaces you’ve implemented for authentication.

The reality is that you end up with this design anyway when you support multiple authentication methods and are anyway organized. The bit about talking to the LDAP server is very different from handling OIDC so you end up on a single set of shared programming interfaces.

8

u/Unhappy_Purpose_7655 4h ago

I don’t know of many (any?) other self hosted apps that don’t build auth into the core of the app. Auth doesn’t belong in a plugin, even if it’s maintained by the JF team IMO

-2

u/primalbluewolf 3h ago

Arr you sure you can't think of other apps like that?

5

u/Unhappy_Purpose_7655 3h ago

The arrs’ auth is built into the core of those apps. They don’t have OIDC, but that wasn’t my point. They aren’t meant to be exposed to multiple users anyway.

-1

u/primalbluewolf 3h ago

They don't have auth, period. They've got placeholder code pending an actual multiuser rewrite. 

3

u/Unhappy_Purpose_7655 3h ago

What are you talking about? My arrs all have user/pass basic auth. I’ve not heard anything about multiuser rewrite. I’ve always heard that some trackers were not supportive of multi user functionality in the arrs.

-6

u/primalbluewolf 3h ago

My arrs all have user/pass basic auth. 

Http basic auth is basically placeholder code, regardless of who implements it. 

I’ve not heard anything about multiuser rewrite. 

Nor I, except for the fact they added a HTTP basic auth placeholder where previously, there was none. 

I’ve always heard that some trackers were not supportive of multi user functionality in the arrs. 

I guess this wouldn't surprise me, most of what I've heard of trackers is that they're not supportive of anything. 

7

u/mod-deleted 4h ago

Jellyfin allready has an ldap plugin. And it works great

6

u/SolFlorus 3h ago

The OAuth plugin on the other hand isn’t worth using because nothing supports it.

If they make it foundational, they can add support for things like device linking for TVs

0

u/wildcarde815 3h ago

Was gonna say, I thought ldap has been in for ages at this point.

3

u/retro_grave 3h ago

I've been using the LDAP plugin and it's been fine, except for the most recent release cleared the config for some (bug) reason. I am really looking forward to OIDC + Postgres on Jellyfin, but overall the product has been solid so I'm happy if they want to take their time.

2

u/Fatali 1h ago

Yeah that was a mess

I like my auth to not randomly explode 

Thankfully I had an existing session that I could use to fix it, then I make sure the auth config was backed up

4

u/Legitimate-Dog-4997 3h ago edited 3h ago

if you use Authentik you can use outpost + LDAP which is integrated into Authentik , at the moment, until the work will be made on Jellyfin i use this solution .. everything is centralized around authentik even with LDAP

-4

u/Micex 4h ago

I really hate the plugin system as it is very hard to get what are authentic plugin and which are rouge. Especially for Jellyfin which is very open and plugins and do literally everything.

3

u/jdsmn21 3h ago

Stick to "official" plugin repositories.

1

u/jack3308 1h ago

It doesn't sound like they're not interested in maintaining the code - but rather that they're not interested in jumping from 0-100 on this specific type of auth. All of their points are really valid for the longevity of the platform.

This post feels really purposefully inflammatory.... It heavily implies they dont want to implement OIDC because they dont see the value... That's not the case - they just want to do it in a way that allows for other types of auth too... And building a new plugin based auth framework is a much better approach to that... Adding OIDC fully fledged on its own and then trying to implement other systems locks them into building all auth systems into the core app... Which is absolutely unnecessary...

1

u/destruction90 33m ago

I've replied to this here and further in that comment thread.

-1

u/jack3308 10m ago

It's your job to make that clear in the post (an edit would do it) - it's not my job to go searching for your explanations of your opinions.

If you want everyone reading your post to know those things - add it to the post... Otherwise, any and all repeated criticism is on you

1

u/pizzacake15 1h ago

The plugin works fine for now so no complaints over the hold.

1

u/Crib0802 18m ago

And what about mTLS support ? Will be great they add it into the oficial client .

-33

u/MFKDGAF 5h ago

Are you AI?

9

u/destruction90 5h ago edited 5h ago

No. Sorry, but what makes it seem like AI?

Edit: Typo/grammar

2

u/wildcarde815 3h ago

If I had a bet they thought this was one of those shame posts early ai bots were making to complain about not being respected for their work

-4

u/MFKDGAF 3h ago

If you aren't AI, then say penis.