Releases: Flowfin/jellyfin-plugin-sso
Release list
5.0.0-JF12-beta
Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.47).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.
What's Changed
- Refuse a token that vouches for its own signing key, and prove the rows bite by @iderex in #1334
- Read the discovery facts with the parser family the screen walks by @iderex in #1335
- Refuse an advertised symmetric key, and show which control refuses it by @iderex in #1336
- Report both release lines on the README badge by @iderex in #1337
- Ship the OpenVEX document on every release leg by @iderex in #1338
Full Changelog: 4.3.0-beta.32...5.0.0-JF12-beta.47
4.3.0-beta
Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.33).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
What's Changed
- Refuse a token that vouches for its own signing key, and prove the rows bite by @iderex in #1334
- Read the discovery facts with the parser family the screen walks by @iderex in #1335
- Refuse an advertised symmetric key, and show which control refuses it by @iderex in #1336
- Report both release lines on the README badge by @iderex in #1337
- Ship the OpenVEX document on every release leg by @iderex in #1338
Full Changelog: 4.3.0-beta.32...4.3.0-beta.33
5.0.0-JF12-beta
Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.46).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.
What's Changed
- Add a relogin-only harness pass that reuses an initialised Jellyfin by @iderex in #1326
- Refuse a JWT that declares itself a token for the other endpoint by @iderex in #1327
- Unpack the archive the documented local build actually writes by @iderex in #1331
- Screen the role claim in the scopes its reader enters by @iderex in #1332
- Gate the legacy plaintext secret migration with a scripted phase by @iderex in #1333
Full Changelog: 4.3.0-beta.31...5.0.0-JF12-beta.46
4.3.0-beta
Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.32).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
What's Changed
- Add a relogin-only harness pass that reuses an initialised Jellyfin by @iderex in #1326
- Refuse a JWT that declares itself a token for the other endpoint by @iderex in #1327
- Unpack the archive the documented local build actually writes by @iderex in #1331
- Screen the role claim in the scopes its reader enters by @iderex in #1332
- Gate the legacy plaintext secret migration with a scripted phase by @iderex in #1333
Full Changelog: 4.3.0-beta.31...4.3.0-beta.32
5.0.0-JF12-beta
Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.45).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.
What's Changed
- Pin the request body to one reader, and refuse a second [#1033] by @iderex in #1322
- Measure what refusing an unreadable role claim would cost [#1053] by @iderex in #1323
- Measure and gate branch coverage on the security surface by @iderex in #1325
Full Changelog: 4.3.0-beta.30...5.0.0-JF12-beta.45
5.0.0-JF12-beta
Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.44).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.
What's Changed
- Measure the login latency on a pinned runner and archive the run by @iderex in #1310
- Assert the parse surface's post-conditions under the fuzzer by @iderex in #1311
- Replace the typographic dashes in this tree by @iderex in #1309
- Derive the browser-bound authorize value's route set and classify every leg by @iderex in #1312
- Pin the canonical name to one ordinal comparison on every route it arrives on by @iderex in #1313
- Derive the test root once, and pin the walk's own duplicate decision by @iderex in #1315
- Add the JWE and nested-JWT rows to the id_token forgery battery by @iderex in #1316
- Follow the organisation default for the sponsor button (#1318) by @iderex in #1319
- Report a Jellyfin account's SSO posture in one elevation-gated read by @iderex in #1320
- Export the account-link table as a username-keyed document by @iderex in #1321
Full Changelog: 4.3.0-beta.29...5.0.0-JF12-beta.44
4.3.0-beta
Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.31).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
What's Changed
- Pin the request body to one reader, and refuse a second [#1033] by @iderex in #1322
- Measure what refusing an unreadable role claim would cost [#1053] by @iderex in #1323
- Measure and gate branch coverage on the security surface by @iderex in #1325
Full Changelog: 4.3.0-beta.30...4.3.0-beta.31
4.3.0-beta
Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.30).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
What's Changed
- Measure the login latency on a pinned runner and archive the run by @iderex in #1310
- Assert the parse surface's post-conditions under the fuzzer by @iderex in #1311
- Replace the typographic dashes in this tree by @iderex in #1309
- Derive the browser-bound authorize value's route set and classify every leg by @iderex in #1312
- Pin the canonical name to one ordinal comparison on every route it arrives on by @iderex in #1313
- Derive the test root once, and pin the walk's own duplicate decision by @iderex in #1315
- Add the JWE and nested-JWT rows to the id_token forgery battery by @iderex in #1316
- Follow the organisation default for the sponsor button (#1318) by @iderex in #1319
- Report a Jellyfin account's SSO posture in one elevation-gated read by @iderex in #1320
- Export the account-link table as a username-keyed document by @iderex in #1321
Full Changelog: 4.3.0-beta.29...4.3.0-beta.30
5.0.0-JF12-beta
Jellyfin 12.0 (.NET 10) beta 5.0.0-JF12-beta (plugin version 5.0.0.43).
Install via the beta repository URL (a Jellyfin 12.0 server picks this build automatically by targetAbi):
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
Scope note (#743): the JF12/5.0 line is not validated against a live Jellyfin 12.0 server yet - no 12.0 GA server exists to run the E2E checklist against. It is CI-built and unit/conformance-tested only, and it is NOT part of the 4.x (Jellyfin 10.11) release-candidate gate; the 5.0 line clears its own live-validation gate when a Jellyfin 12.0 RC/GA build is available. Use these betas for testing, not production.
What's Changed
- Add a roles fuzz target and seed its repeated-key grammar [#1158] by @iderex in #1291
- Name the screened discovery refusal in Test connection [#1064] by @iderex in #1293
- Bound the provider-authored text in the discovery read's warning [#1194] by @iderex in #1294
- Refuse the roles when two copies of the role claim disagree [#1040] by @iderex in #1295
- Refuse a token whose JWS header marks an extension critical [#1038] by @iderex in #1296
- Pin that a repeated scalar aud collapses to the last occurrence [#1193] by @iderex in #1297
- Prove the non-parallel-collection rule can go red [#1173] by @iderex in #1298
- Fold the untrusted-JSON rule into the conformance home [#1037] by @iderex in #1299
- Retry the logout discovery read inside a stated budget [#1183] by @iderex in #1300
- Audit a refused role claim with its reason and never its value [#1149] by @iderex in #1301
- Rewrite the em dash out of the admin page and the translation surface by @iderex in #1302
- Pin the OIDC redirect_uri to one builder over one canonical base by @iderex in #1304
- Pin the OpenID validation basis to one file and one algorithm set by @iderex in #1305
- Name each logout_token refusal instead of collapsing eleven into one by @iderex in #1306
- Name the repeated member in the refusal entry, neutralised at the log call [#1195] by @iderex in #1307
- Build every OpenID client with its discovery metadata already set [#1067] by @iderex in #1308
Full Changelog: 4.3.0-beta.28...5.0.0-JF12-beta.43
4.3.0-beta
Jellyfin 10.11 beta 4.3.0-beta (plugin version 4.3.0.29).
Install via the beta repository URL:
https://raw.githubusercontent.com/Flowfin/jellyfin-plugin-sso/manifest-beta/manifest.json
What's Changed
- Add a roles fuzz target and seed its repeated-key grammar [#1158] by @iderex in #1291
- Name the screened discovery refusal in Test connection [#1064] by @iderex in #1293
- Bound the provider-authored text in the discovery read's warning [#1194] by @iderex in #1294
- Refuse the roles when two copies of the role claim disagree [#1040] by @iderex in #1295
- Refuse a token whose JWS header marks an extension critical [#1038] by @iderex in #1296
- Pin that a repeated scalar aud collapses to the last occurrence [#1193] by @iderex in #1297
- Prove the non-parallel-collection rule can go red [#1173] by @iderex in #1298
- Fold the untrusted-JSON rule into the conformance home [#1037] by @iderex in #1299
- Retry the logout discovery read inside a stated budget [#1183] by @iderex in #1300
- Audit a refused role claim with its reason and never its value [#1149] by @iderex in #1301
- Rewrite the em dash out of the admin page and the translation surface by @iderex in #1302
- Pin the OIDC redirect_uri to one builder over one canonical base by @iderex in #1304
- Pin the OpenID validation basis to one file and one algorithm set by @iderex in #1305
- Name each logout_token refusal instead of collapsing eleven into one by @iderex in #1306
- Name the repeated member in the refusal entry, neutralised at the log call [#1195] by @iderex in #1307
- Build every OpenID client with its discovery metadata already set [#1067] by @iderex in #1308
Full Changelog: 4.3.0-beta.28...4.3.0-beta.29