Skip to content

Releases: Flowfin/jellyfin-plugin-sso

5.0.0-JF12-beta

5.0.0-JF12-beta Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 13 Aug 05:49
Immutable release. Only release title and notes can be modified.
86f750b

Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.47).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.

What's Changed

  • Refuse a token that vouches for its own signing key, and prove the rows bite by @iderex in #1334
  • Read the discovery facts with the parser family the screen walks by @iderex in #1335
  • Refuse an advertised symmetric key, and show which control refuses it by @iderex in #1336
  • Report both release lines on the README badge by @iderex in #1337
  • Ship the OpenVEX document on every release leg by @iderex in #1338

Full Changelog: 4.3.0-beta.32...5.0.0-JF12-beta.47

4.3.0-beta

Choose a tag to compare

@github-actions github-actions released this 13 Aug 05:46
Immutable release. Only release title and notes can be modified.
86f750b

Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.33).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

What's Changed

  • Refuse a token that vouches for its own signing key, and prove the rows bite by @iderex in #1334
  • Read the discovery facts with the parser family the screen walks by @iderex in #1335
  • Refuse an advertised symmetric key, and show which control refuses it by @iderex in #1336
  • Report both release lines on the README badge by @iderex in #1337
  • Ship the OpenVEX document on every release leg by @iderex in #1338

Full Changelog: 4.3.0-beta.32...4.3.0-beta.33

5.0.0-JF12-beta

5.0.0-JF12-beta Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 12 Aug 05:47
Immutable release. Only release title and notes can be modified.
fce0362

Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.46).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.

What's Changed

  • Add a relogin-only harness pass that reuses an initialised Jellyfin by @iderex in #1326
  • Refuse a JWT that declares itself a token for the other endpoint by @iderex in #1327
  • Unpack the archive the documented local build actually writes by @iderex in #1331
  • Screen the role claim in the scopes its reader enters by @iderex in #1332
  • Gate the legacy plaintext secret migration with a scripted phase by @iderex in #1333

Full Changelog: 4.3.0-beta.31...5.0.0-JF12-beta.46

4.3.0-beta

Choose a tag to compare

@github-actions github-actions released this 12 Aug 05:44
Immutable release. Only release title and notes can be modified.
fce0362

Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.32).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

What's Changed

  • Add a relogin-only harness pass that reuses an initialised Jellyfin by @iderex in #1326
  • Refuse a JWT that declares itself a token for the other endpoint by @iderex in #1327
  • Unpack the archive the documented local build actually writes by @iderex in #1331
  • Screen the role claim in the scopes its reader enters by @iderex in #1332
  • Gate the legacy plaintext secret migration with a scripted phase by @iderex in #1333

Full Changelog: 4.3.0-beta.31...4.3.0-beta.32

5.0.0-JF12-beta

5.0.0-JF12-beta Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Aug 05:20
Immutable release. Only release title and notes can be modified.
cc1d677

Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.45).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.

What's Changed

  • Pin the request body to one reader, and refuse a second [#1033] by @iderex in #1322
  • Measure what refusing an unreadable role claim would cost [#1053] by @iderex in #1323
  • Measure and gate branch coverage on the security surface by @iderex in #1325

Full Changelog: 4.3.0-beta.30...5.0.0-JF12-beta.45

5.0.0-JF12-beta

5.0.0-JF12-beta Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Aug 05:44
Immutable release. Only release title and notes can be modified.
43488c8

Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.44).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.

What's Changed

  • Measure the login latency on a pinned runner and archive the run by @iderex in #1310
  • Assert the parse surface's post-conditions under the fuzzer by @iderex in #1311
  • Replace the typographic dashes in this tree by @iderex in #1309
  • Derive the browser-bound authorize value's route set and classify every leg by @iderex in #1312
  • Pin the canonical name to one ordinal comparison on every route it arrives on by @iderex in #1313
  • Derive the test root once, and pin the walk's own duplicate decision by @iderex in #1315
  • Add the JWE and nested-JWT rows to the id_token forgery battery by @iderex in #1316
  • Follow the organisation default for the sponsor button (#1318) by @iderex in #1319
  • Report a Jellyfin account's SSO posture in one elevation-gated read by @iderex in #1320
  • Export the account-link table as a username-keyed document by @iderex in #1321

Full Changelog: 4.3.0-beta.29...5.0.0-JF12-beta.44

4.3.0-beta

Choose a tag to compare

@github-actions github-actions released this 11 Aug 05:17
Immutable release. Only release title and notes can be modified.
cc1d677

Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.31).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

What's Changed

  • Pin the request body to one reader, and refuse a second [#1033] by @iderex in #1322
  • Measure what refusing an unreadable role claim would cost [#1053] by @iderex in #1323
  • Measure and gate branch coverage on the security surface by @iderex in #1325

Full Changelog: 4.3.0-beta.30...4.3.0-beta.31

4.3.0-beta

Choose a tag to compare

@github-actions github-actions released this 10 Aug 05:41
Immutable release. Only release title and notes can be modified.
43488c8

Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.30).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

What's Changed

  • Measure the login latency on a pinned runner and archive the run by @iderex in #1310
  • Assert the parse surface's post-conditions under the fuzzer by @iderex in #1311
  • Replace the typographic dashes in this tree by @iderex in #1309
  • Derive the browser-bound authorize value's route set and classify every leg by @iderex in #1312
  • Pin the canonical name to one ordinal comparison on every route it arrives on by @iderex in #1313
  • Derive the test root once, and pin the walk's own duplicate decision by @iderex in #1315
  • Add the JWE and nested-JWT rows to the id_token forgery battery by @iderex in #1316
  • Follow the organisation default for the sponsor button (#1318) by @iderex in #1319
  • Report a Jellyfin account's SSO posture in one elevation-gated read by @iderex in #1320
  • Export the account-link table as a username-keyed document by @iderex in #1321

Full Changelog: 4.3.0-beta.29...4.3.0-beta.30

5.0.0-JF12-beta

5.0.0-JF12-beta Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Aug 05:16
Immutable release. Only release title and notes can be modified.
d307ae0

Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.43).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.

What's Changed

  • Add a roles fuzz target and seed its repeated-key grammar [#1158] by @iderex in #1291
  • Name the screened discovery refusal in Test connection [#1064] by @iderex in #1293
  • Bound the provider-authored text in the discovery read's warning [#1194] by @iderex in #1294
  • Refuse the roles when two copies of the role claim disagree [#1040] by @iderex in #1295
  • Refuse a token whose JWS header marks an extension critical [#1038] by @iderex in #1296
  • Pin that a repeated scalar aud collapses to the last occurrence [#1193] by @iderex in #1297
  • Prove the non-parallel-collection rule can go red [#1173] by @iderex in #1298
  • Fold the untrusted-JSON rule into the conformance home [#1037] by @iderex in #1299
  • Retry the logout discovery read inside a stated budget [#1183] by @iderex in #1300
  • Audit a refused role claim with its reason and never its value [#1149] by @iderex in #1301
  • Rewrite the em dash out of the admin page and the translation surface by @iderex in #1302
  • Pin the OIDC redirect_uri to one builder over one canonical base by @iderex in #1304
  • Pin the OpenID validation basis to one file and one algorithm set by @iderex in #1305
  • Name each logout_token refusal instead of collapsing eleven into one by @iderex in #1306
  • Name the repeated member in the refusal entry, neutralised at the log call [#1195] by @iderex in #1307
  • Build every OpenID client with its discovery metadata already set [#1067] by @iderex in #1308

Full Changelog: 4.3.0-beta.28...5.0.0-JF12-beta.43

4.3.0-beta

Choose a tag to compare

@github-actions github-actions released this 09 Aug 05:14
Immutable release. Only release title and notes can be modified.
d307ae0

Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.29).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json

What's Changed

  • Add a roles fuzz target and seed its repeated-key grammar [#1158] by @iderex in #1291
  • Name the screened discovery refusal in Test connection [#1064] by @iderex in #1293
  • Bound the provider-authored text in the discovery read's warning [#1194] by @iderex in #1294
  • Refuse the roles when two copies of the role claim disagree [#1040] by @iderex in #1295
  • Refuse a token whose JWS header marks an extension critical [#1038] by @iderex in #1296
  • Pin that a repeated scalar aud collapses to the last occurrence [#1193] by @iderex in #1297
  • Prove the non-parallel-collection rule can go red [#1173] by @iderex in #1298
  • Fold the untrusted-JSON rule into the conformance home [#1037] by @iderex in #1299
  • Retry the logout discovery read inside a stated budget [#1183] by @iderex in #1300
  • Audit a refused role claim with its reason and never its value [#1149] by @iderex in #1301
  • Rewrite the em dash out of the admin page and the translation surface by @iderex in #1302
  • Pin the OIDC redirect_uri to one builder over one canonical base by @iderex in #1304
  • Pin the OpenID validation basis to one file and one algorithm set by @iderex in #1305
  • Name each logout_token refusal instead of collapsing eleven into one by @iderex in #1306
  • Name the repeated member in the refusal entry, neutralised at the log call [#1195] by @iderex in #1307
  • Build every OpenID client with its discovery metadata already set [#1067] by @iderex in #1308

Full Changelog: 4.3.0-beta.28...4.3.0-beta.29