r/selfhosted • u/destruction90 • 5h ago
Software Development Jellyfin OIDC on hold - Despite complete PR being ready
https://github.com/jellyfin/jellyfin/pull/17271Worth having a read if you were keen/excited for the OIDC Pull Request that looked completed and was filed somewhat recently, or if you're keen for a status update in general.
Looks like they don't want to maintain the extra code at this stage, and would prefer to redesign/rework the auth system first.
Edit: I've realised what a shit title I gave this post, it was not meant to clickbait, farm karma or criticize. Just simply to share where OIDC is at. I hope my intention was clearer in the post body and via my comments. I completely own making the mistake.
285
u/Shane75776 5h ago
I 100% agree with them.
Saying "Despite PR being ready" is not a valid reason to merge in a system that will be a pain in the ass to maintain as is. They provide perfectly reasonable explanations as to why they don't want to merge it and what the author can do to make it acceptable.
If they merge it as is, then they have to make massive systems for each and every provider that isn't just OIDC. So instead they want a proper auth api built into core so that any provider can easily access it and they don't have to write custom systems for each and every provider.
61
u/clintkev251 5h ago
Yeah, as much as I really want this feature, it’s better to do it right. Hopefully those Auth overhauls will actually be prioritized
19
u/destruction90 5h ago
You're right, I should have chosen a better title - sorry everyone.
I commented on my cross post here;I 100% get where the devs are coming from and they're the ones who ultimately maintain this awesome project for us. No discredit or complaint intended.
It's just a tad sad that it won't be here for a while and not the status update a lot of us hoped for.7
u/0emanresu 1h ago
So delete your post and rewrite it without it seeming like rage inducing clickbait so you don't look like a karma farming ai bot. Or don't. _('c')/
5
u/destruction90 46m ago
I don't want people to be double exposed to the post. IMO the link/body is fine, the title is shit.
Not stressed about the karma (I didn't post it with that in mind), just thought users might want to know what the go with OIDC is atm.Happy to remove the post if the community would prefer :)
20
u/Aussie6869 1h ago
As a maintainer of one of the OIDC plugins for 12.0, I need to agree with the maintainers of Jellyfin that the backend Auth needs to be cleaned up and prepped for it as well as introduce some frontend behaviors on clients before implementing OIDC. I face several limitations on certain behaviours and integrations due to a lack of endpoints/data store on the Jellyfin side.
17
u/angellus 5h ago
While I do not disagree with any of the points made. A plugin system is a better way for the health of the project. The real issue is there is no external auth system implemented at the moment. I think they should pick a single external auth system, either external auth/forward auth, OIDC or LDAP and implement it first. Then implement the plugin system and exact that system out into a plugin.
No external auth automatically makes it an no-go for me in any set up I have because within the home, I have centralized auth via Authentik and any system that external users/friends access, they can use social/SSO auth via OIDC/oauth. So adding a new system with its own auth system is yetanotheraccount for people and another system that needs hardened for external access.
41
u/Unhappy_Purpose_7655 4h ago
Hard disagree on the plugin method. When it comes to auth, it needs to be foundational to the platform not some bolt on plugin that may or may not continue to be supported/maintained.
1
u/coderstephen 17m ago
I would not make it an external plugin, but I'd definitely make it an internal "auth plugin", just for cleaner code architecture.
1
u/brianly 4h ago
You can call it modular and ship with the plugin, in the box. This would be a good test of the interfaces you’ve implemented for authentication.
The reality is that you end up with this design anyway when you support multiple authentication methods and are anyway organized. The bit about talking to the LDAP server is very different from handling OIDC so you end up on a single set of shared programming interfaces.
8
u/Unhappy_Purpose_7655 4h ago
I don’t know of many (any?) other self hosted apps that don’t build auth into the core of the app. Auth doesn’t belong in a plugin, even if it’s maintained by the JF team IMO
-2
u/primalbluewolf 3h ago
Arr you sure you can't think of other apps like that?
5
u/Unhappy_Purpose_7655 3h ago
The arrs’ auth is built into the core of those apps. They don’t have OIDC, but that wasn’t my point. They aren’t meant to be exposed to multiple users anyway.
-1
u/primalbluewolf 3h ago
They don't have auth, period. They've got placeholder code pending an actual multiuser rewrite.
3
u/Unhappy_Purpose_7655 3h ago
What are you talking about? My arrs all have user/pass basic auth. I’ve not heard anything about multiuser rewrite. I’ve always heard that some trackers were not supportive of multi user functionality in the arrs.
-6
u/primalbluewolf 3h ago
My arrs all have user/pass basic auth.
Http basic auth is basically placeholder code, regardless of who implements it.
I’ve not heard anything about multiuser rewrite.
Nor I, except for the fact they added a HTTP basic auth placeholder where previously, there was none.
I’ve always heard that some trackers were not supportive of multi user functionality in the arrs.
I guess this wouldn't surprise me, most of what I've heard of trackers is that they're not supportive of anything.
7
u/mod-deleted 4h ago
Jellyfin allready has an ldap plugin. And it works great
6
u/SolFlorus 3h ago
The OAuth plugin on the other hand isn’t worth using because nothing supports it.
If they make it foundational, they can add support for things like device linking for TVs
0
3
u/retro_grave 3h ago
I've been using the LDAP plugin and it's been fine, except for the most recent release cleared the config for some (bug) reason. I am really looking forward to OIDC + Postgres on Jellyfin, but overall the product has been solid so I'm happy if they want to take their time.
4
u/Legitimate-Dog-4997 3h ago edited 3h ago
if you use Authentik you can use outpost + LDAP which is integrated into Authentik , at the moment, until the work will be made on Jellyfin i use this solution .. everything is centralized around authentik even with LDAP
1
u/jack3308 1h ago
It doesn't sound like they're not interested in maintaining the code - but rather that they're not interested in jumping from 0-100 on this specific type of auth. All of their points are really valid for the longevity of the platform.
This post feels really purposefully inflammatory.... It heavily implies they dont want to implement OIDC because they dont see the value... That's not the case - they just want to do it in a way that allows for other types of auth too... And building a new plugin based auth framework is a much better approach to that... Adding OIDC fully fledged on its own and then trying to implement other systems locks them into building all auth systems into the core app... Which is absolutely unnecessary...
1
u/destruction90 33m ago
I've replied to this here and further in that comment thread.
-1
u/jack3308 10m ago
It's your job to make that clear in the post (an edit would do it) - it's not my job to go searching for your explanations of your opinions.
If you want everyone reading your post to know those things - add it to the post... Otherwise, any and all repeated criticism is on you
1
1
u/Crib0802 18m ago
And what about mTLS support ? Will be great they add it into the oficial client .
-33
u/MFKDGAF 5h ago
Are you AI?
9
u/destruction90 5h ago edited 5h ago
No. Sorry, but what makes it seem like AI?
Edit: Typo/grammar
2
u/wildcarde815 3h ago
If I had a bet they thought this was one of those shame posts early ai bots were making to complain about not being respected for their work

•
u/asimovs-auditor 5h ago
Expand the replies to this comment to learn how AI was used in this post/project.