You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Added in-app mpv setup: the welcome and Client Settings screens now offer a one-click "Download mpv" on Windows (fetched and extracted from the shinchiro mpv builds) and copyable per-OS install commands on macOS and Linux, plus a link to mpv.io/installation.
Added native Jellyfin intro and credits skipping in mpv with prompt/always settings and forward-seek prompt acceptance.
Added Jellyfin recap and commercial segment skipping in mpv with their own prompt/always Client Settings, alongside the existing intro and credits options.
Added skip-segment markers on the mpv seek bar by injecting chapter ticks at each segment's boundaries, so the timeline shows where intros, credits, recaps, and commercials are skipped. Existing embedded file chapters are preserved and merged with the markers rather than replaced.
Added an MPC-HC player backend on Windows: a new "Player backend" client setting switches playback between mpv and MPC-HC, driven over slave mode (WM_COPYDATA / MpcApi.h) — open, resume, play/pause, seek, playback speed, audio/subtitle track selection, segment skipping with on-screen prompts and auto-skip countdowns, Jellyfin progress reporting, and end-of-file auto-advance to the next episode. The setting is a segmented switch that shows only the active backend's options and applies live without restarting the app; MPC-HC launches on first playback rather than at app start. Both players sit behind a new PlayerBackend trait with a capability probe. On MPC-HC, external subtitles play by requesting a server-side burned-in transcode, volume and mute are emulated through relative volume steps, and the configured default fullscreen behavior is applied on every load (matching mpv); chapter-marker pips and the mark-watched hotkey remain mpv-only and degrade gracefully. On every file open MediaFlick asserts the selected audio/subtitle track (translating mpv's 1-based track ids to MPC-HC's 0-based indexes) and the resume position. Because MPC-HC services CMD_SETPOSITION with a synchronous seek that can block its window for many seconds while it re-fetches a remote stream (the duration depends heavily on the file — sub-second on some, ~15s on high-bitrate 4K), all slave-mode commands are dispatched on a dedicated sender thread so the app stays responsive during the seek, rapid seeks are coalesced to the latest target, and a "Seeking..." on-screen message is shown until MPC-HC reports the seek completed.
Added unit tests for the CEF bridge origin allowlist, external-link scheme checks, and U+2028/U+2029, HTML, and percent-encoding escaping helpers, locking in recent security hardening.
Added a single-instance gate so only one MediaFlick session runs at a time: a stable id is persisted in instance.json (mirroring Jellyfin Desktop's instance file) and used to name a Windows mutex acquired at startup. A second launch detects the existing session, shows an "already running" message, and exits without starting a duplicate player or WebUI. CEF subprocesses are unaffected.
Added a reusable in-app error toast that surfaces user-facing failures as a dismissible notification injected into the WebUI (styled to match the update toast), with a Copy button to put the error text on the clipboard. It stays on screen until dismissed, and reports when playback is requested but no media player is configured, and when a player backend fails to start playback — mpv or MPC-HC failing to launch (for example a wrong executable path) or mpv rejecting the video — instead of failing silently in the log.
Changed
Redesigned the first-run welcome screen to match the app's dark, Jellyfin-compatible design system: removed the marketing-style gradient background, unified colors and typography with the settings dialog, reserved the violet→cyan gradient for the brand mark, and integrated the "get mpv" setup inline instead of as a nested card.
Stopped bundling mpv in the Windows installer and zip; the app now downloads mpv on first run or guides the user to install it, producing a much smaller installer.
Changed automatic intro and credits skipping to show a three-second countdown before seeking.
Moved app-owned dialog and load-error markup templates out of Rust source files.
Slimmed the README to a Why, Features, and short Install section, and moved the build instructions into a dedicated BUILDING.md.
Replaced the About and Client Settings dialog brand marks with the app logo.
Polished the About dialog and redesigned the update notification as a compact pill without installer filename copy.
Changed the default CEF cache location to the project-local .cache/cef directory instead of an upstream Jellyfin Desktop checkout path.
Updated the Rust cef crate to v149.1.0 (#12 by @renovate).
Updated the draft release workflow to use actions/cache@v6 (#14 by @renovate).
Updated the Rust sevenz-rust2 crate to v0.21.1 (#15 by @renovate).
Changed the Windows auto-update installer launch to use Inno Setup /SILENT instead of /VERYSILENT.
Changed the Windows in-app mpv download to install mpv inside the app installation directory.
Changed Windows mpv window raising on file load to pulse the window-minimized IPC property so the player window takes focus, instead of the ontop pulse which only changed z-order.
Scoped the Jellyfin page fetch and XMLHttpRequest hooks to PlaybackInfo, play-state report, and direct-stream URLs, so unrelated page requests pass straight through to the native implementation.
Reworked the Client Settings dialog into Player, Playback, and Application tabs so it no longer grows into one long scroll when a backend's options expand, and the backend-dependent options stay confined to the Player tab. Added a scroll-edge fade and chevron hint that appears when a section overflows the window, so there is still a visual cue that more settings exist below the fold even when scrollbars are hidden app-wide (the --hide-scrollbars renderer flag otherwise suppresses the dialog's own scrollbar). The tab strip is keyboard navigable with arrow keys.
Fixed
Fixed the Linux and macOS release builds failing to compile because the warnings = "deny" lint flagged the Windows-only MPC-HC segment helpers and mpv auto-download phases as dead code on those platforms.
Fixed every native bridge message (player commands, playback context, play-state reports) being delivered twice because sendBridgeRequest fired both a fetch and an <img> request as a fallback pair; it now sends one and only falls back to the image when fetch is unavailable. This was duplicating each play/pause/seek/volume command — and the duplicate seeks compounded MPC-HC's synchronous seek stalls.
Fixed the external player (mpv or MPC-HC) sometimes being left running after MediaFlick exits — for example after switching player backends at runtime — by binding each spawned player to a Windows job object the OS terminates when the app process ends.
Hardened the auto-updater to download installers only over HTTPS from GitHub-owned hosts and into a unique per-run directory, preventing redirect-to-untrusted-host and predictable-temp-path attacks.
Restricted the native mediaflick-desktop:// bridge to pages from our own local UI or the configured Jellyfin origin, so unrelated page content can no longer drive mpv, settings, or app exit.
Restricted Jellyfin playback-state reporting to http(s) targets and percent-encoded the media-segments item id, closing SSRF and path-injection vectors from page-supplied stream URLs.
Restricted the configured server URL and externally opened links to http/https (links also allow mailto), rejecting file:, data:, about:, and other schemes.
Pinned the Windows command-processor shim to the system cmd.exe resolved from SystemRoot instead of an attacker-settable COMSPEC override.
Surfaced mpv IPC command rejections in the log instead of silently treating every command as successful.
Fixed an auto-skipped intro/credits segment being consumed even when its seek failed, so the skip can be retried after the mpv session recovers.
Escaped U+2028/U+2029 in data injected into the Jellyfin page, preventing server-derived playback fields from breaking the injected script.
Fixed native mpv forward seeks not accepting an active skip-intro/credits prompt when mpv reports the seek event before the seeking property.
Fixed the in-app mpv download deleting a working install before the new archive is validated; the build is now extracted to a staging directory, checked for mpv.exe, and swapped into place with the previous install kept until the swap succeeds.
Fixed segment chapter markers overwriting a file's embedded chapters when a duration or media-segment update raced ahead of mpv's chapter-list event; marker injection now waits until the file's own chapters have been captured.
Fixed Linux and macOS update notifications by linking the updater dialog to the GitHub latest release page instead of offering unsupported automatic installation.
Fixed Linux and macOS first launch by auto-detecting a system mpv executable and using generic mpv executable wording in app UI.
Fixed Linux AppImage startup aborts with close symbol missing by preloading bundled CEF and stripping that preload from spawned mpv processes.
Fixed the mpv window staying at full-screen size after leaving fullscreen when playback starts fullscreen, by constraining the windowed size with --autofit=70%.
Added a Jellyfin Web integration check that logs a clear console error and shows a dismissible banner when the bridge cannot install its required hooks (for example, after an incompatible Jellyfin Web update), instead of silently failing to drive mpv.
Required a per-session token on mediaflick-desktop:// requests originating from the Jellyfin page, so in-origin scripts (such as a rogue Jellyfin plugin or injected content) can no longer forge bridge actions like app exit or playback control.
Fixed mpv commands silently failing after a half-open IPC connection by detecting a dead command-writer and restarting the mpv session, instead of waiting for the event stream to also disconnect.