Repository navigation
v2.10.6
Jellyscribe no longer sends saved passwords, cookies or the Seerr API key back to the browser. Before, the settings pages loaded each linked account's Letterboxd or Serializd password and cookies into the form, and the admin settings returned every user's password and the Seerr key. Anyone holding a session could read them. Saved values now show as "Saved" with an empty field. Leave it blank to keep the saved value, type to replace it, or tick "Remove saved cookies" or "Remove saved key" to drop it. Verify login works with the saved password, and an admin can move an account to another Jellyfin user or rename it without re-entering its password. Existing saved logins keep working after the upgrade. Thanks to Wouter Stulp, whose fork made stored secrets write-only first; this release builds on his work.