Skip to content

Nexview 1.1.0

Latest

Choose a tag to compare

@DerKezorm DerKezorm released this 11 Oct 09:17

⚠️ Make a backup before updating. The update rebuilds the sign-in provider tables and moves the links of each person to the new ones. Nexview writes a backup to sicherungen/ in the data directory first (Before update to 1.1.0 in its name) and names the file in the start log. Going back to 1.0.1 works only with that backup, as described in the README under Going back to an older version.

Added

  • Sign-in follows the shared blueprint of the nex apps ("Anmeldung mit OIDC und authentik"), through the shared module nexoidc 1.0.12: several providers at once with one button each, authentik in one step with a blueprint to download, Microsoft Entra ID with common and organizations, invitations accepted through the provider (/api/oidc/<slug>/start?invite=), password sign-in that can be switched off once a provider is on (never for the operator), provider marks and unlinking in the users list.
  • NEXVIEW_CLIENT_IP=proxy now also takes the scheme from X-Forwarded-Proto (the rightmost value), so the redirect address behind a TLS proxy is https.

Changed

  • No more linking through a confirmed e-mail address. A person is recognised only by the identity at the provider. Links made that way before are already stored and keep working; new people link in the profile (with their password) or come with an invitation.
  • The routes moved to /api/oidc/.... The redirect address of providers set up with 1.0.1 (/api/auth/oidc/<slug>/callback) stays valid for those entries.
  • Changing a provider's issuer drops its links; removing a provider removes its links.
  • Saving the public address asks first when a provider knows the old redirect address (409 public_url_change).
  • A media-server sign-in no longer finds an account through an unconfirmed address. An address taken over from a sign-in provider, or typed into the profile and not yet confirmed through the link in the mail, no longer links a Plex, Jellyfin or Emby sign-in to that account (409 mediaserver_link_in_profile); sign in to the account and link the media server in the profile instead. Accounts linked to a provider in 1.0.1 count as having their address from the provider until it is confirmed.
  • Invitation keys in the address (?invite=) are masked in the log.
  • Plex, Jellyfin and Emby only match addresses Nexview has confirmed. If you run a media-server sign-in, check that your people have confirmed their address in the profile, or set it yourself as operator; nobody else is matched through it any more.

Fixed

  • Mails carry a Date header. Some providers dropped mails without one silently.