Consolidate the wiki: canonical Coding Standards, merged Architecture, split Provider Setup
Restructure the wiki into one coherent, audience-grouped set with a single home
for each fact.
- New Coding-Standards page: the one canonical statement of the architecture,
comment/documentation (#864), and object-oriented rules; the repo's CLAUDE.md
and CONTRIBUTING.md now point here instead of restating them.
- Merged the two stale, mutually-overlapping Architecture pages into one, re-based
on the current module-DAG reality (the old pages claimed the module split was
"not pursued" and that no IPluginServiceRegistrator existed — both were wrong
and contradicted docs/ARCHITECTURE.md). Cites modules and types, never
file:line, so it cannot drift on a move again.
- Split Provider-Setup (1172 lines, ~73% not provider-specific) into Provider
Setup (recipes) + a new Hardening & Options Reference; folded the security-
control narrative into the Security Model. Every moved section left a pointer.
- Merged Release-Policy + Release-QA-Checklist into Releasing (renamed the
per-release ladder to "release promotion ladder" to end the Beta-rung name
collision); merged OpenSSF-Best-Practices + Maturity-Map into Security &
Maturity Self-Assessment. Old slugs kept as redirect stubs.
- Rebuilt the sidebar into four audience groups (Getting started / How it works /
Security / Standards & process). Fixed the broken anchors, corrected the beta
publish-trigger to the daily scheduler (it is not "every merge"), de-referenced
the design records to module/type names, and trimmed Home's README duplication.
Publish the ASVS 5.0 + RFC 9700 security conformance self-assessment [#734]
New Security-Conformance wiki page: maps the RP authentication surface to OWASP ASVS 5.0 (V1 output/CSP, V6 auth incl. id_token + SAML XSW resistance, V7 session/revocation, V8 authz/last-admin, V11 crypto, V12 SSRF, brute-force) and the RFC 9700 OAuth BCP (PKCE-S256, exact redirect-URI, RFC 9207 iss/mix-up, no implicit/hybrid/ROPC; DPoP/JARM/PAR N-A-by-role justified), each row Met/Partial/N-A with a source-file citation. Accepted-residuals section records the min-key-strength floor (#733) and discovery/JWKS SSRF parity (#755) as open with reasoned risk, header completeness as met, and #708 as fixed. Framed as a maintainer self-assessment, no certification. Linked from Home and the sidebar.
Add an honest Silver/Gold/OSPS maturity map [#749]
New Maturity-Map wiki page: Met/Planned/Structurally-N-A buckets against OpenSSF Silver, Gold and OSPS Baseline. States prominently that review is single-maintainer + AI-assisted and the CODEOWNERS accounts are the maintainer team, not independent auditors; dispositions Gold bus_factor, contributors_unassociated, two_person_review and OSPS-QA-07.01/AC-03.01 as not-met-by-design with named compensating controls. Linked from Home and the sidebar.
Publish the native-OIDC coexistence stance [#721]
New Native-OIDC-Coexistence page: upstream watch (jellyfin#17271 open, 13.0 at the earliest; discussion #16470), the complementary-and-strictly-broader stance, a capability comparison against the native draft, and the link-model migration honesty ((mode, provider name, subject) + TOFU issuer vs upstream's (providerId, issuer, subject) key; legacy username links; SAML links stay plugin-owned). Roadmap gains the Upstream-watch section; Home and the sidebar link the page.
Advance maturity to Beta and add the role-gate denial troubleshooting entry
Flip Home/Roadmap/Migrating from Alpha to Beta for the 4.3.0 release: drop the
Alpha for-testing-only warning block for a concise Beta status, move the ladder
marker to Beta, and soften the production-use wording to Beta-appropriate. Add a
Troubleshooting entry mapping the reworded role-gate denial message (#668).
Document SSO-only login: runbook, security summary, lockout recovery
The mode shipped (#665) but the wiki still called it not implemented, and
the settings page points at a Provider Setup runbook that did not exist.
- Provider Setup: full operator runbook (enforcement semantics, break-glass
guard, the four elevation-gated endpoints, server-managed state, recovery)
- Security Model: enforcement-property summary and the audited transitions
- Troubleshooting: locked-out recovery entry (break-glass, config-XML edit)
- SSO-Only Login Design: status corrected to implemented, kept as the record
- Home: feature listed under what it does today
Refresh wiki to Alpha stage, packaged-release install, and three-part versioning
- Home/Installation/Migrating: replace the In-Development banner with the Alpha
maturity; document the plugin-catalog install (stable/beta manifest URLs) and the
multi-target net9.0/net10.0 build for Jellyfin 10.11 and 12.0; drop the
build-from-source-only / no-manifest wording now that the channels are live.
- Release-Policy/OpenSSF: describe the three-part X.Y.Z scheme, with the channel and
Jellyfin generation as a tag/release-name suffix and Z covering both bug-fix and
security, instead of the retired four-part X.Y.Z.W (W=security).
- Provider-Setup: fix "recieve" typo.
- OpenSSF/Release-Policy/Release-QA-Checklist/Rollback/Threat-Model: use the wiki page
name as link text for docs that moved out of the repo (Review Gate, Rollback,
Release QA Checklist, Provider Setup, Architecture Internals, Threat Model).
Migrate design, process, and provider docs from the repo into the wiki
Add wiki pages for the per-provider setup guides, the delivery-pipeline
threat model, the release/rollback/review-gate/QA process docs, the DORA
delivery metrics, the OpenSSF best-practices assessment, the single-logout
and SSO-only-login design notes, and an architecture-internals code map.
Retarget every internal link: cross-doc references now point at wiki pages,
references to files that stay in the repo point at full github blob URLs,
and provider screenshots point at raw.githubusercontent URLs. Add a grouped
navigation to Home (user docs / architecture & security / process & release
/ design records), cross-link Login-Flow and Architecture with the new
Architecture-Internals map, and cross-link Security-Model with Threat-Model.
Sync the Home and Roadmap status notes with the reworked README
Sync the Home and Roadmap status with the semi-halted README notice
Add the Architecture page and link it from Home
Add a Login Flow page describing both sign-in flows end to end
Walk an OpenID Connect and a SAML 2.0 sign-in through the four shared stages
(challenge, identity provider, callback validation, session mint), each with a
sequence sketch, and cover role mapping, canonical-link account resolution,
self-service linking, edge rate limiting, and Quick Connect for non-web
clients. Cross-link each validation step to the Security Model rather than
restating it, and add the page to the Home Pages list.
Add a Roadmap page with the maturity ladder; sync the Home status to In-Development
Add 'Migrating from 9p4' wiki page
Document the switch from the archived 9p4/jellyfin-plugin-sso: same
plugin GUID, so it is an in-place upgrade that preserves the config;
the pre-alpha/test-only caveat; the fail-closed behavior changes an
upgrader must check (OIDC asymmetric-signing + sub keying, SAML SHA-1/
DTD/time/audience); and the rollback path. Linked from Home.
Refs iderex/jellyfin-plugin-sso#150
Add the pre-alpha production-use warning to the wiki Home page
Mirrors the README warning: pre-alpha, developer testing only, not to
be installed on a production system. Refs iderex/jellyfin-plugin-sso#179
Initial wiki: Home, Installation, Security Model, Troubleshooting