Assuming the user will not be connecting over vpn, but is both remote and non-technical, how would you expose Jellyfin to them securely?

you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 4 months ago (4 children)
  • [–] 2 points 4 months ago (2 children)

    That's exactly the point I'm getting at. Putting an auth wall doesn't work with many apps, and if you add exceptions to the API then you're not really protecting anything.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago* (1 child)

    @BakedCatboy @anon_8675309
    I think that could be fixed with authentication through headers (netbird reverse proxy supports that, no idea about pangolin though) but apps should also support adding custom headers on requests

  • source
  • parent
  • hideshow 1 child comment
  • [–] 3 points 4 months ago

    Yes that's what I would like to advocate for. I did something similar with LunaSea, but often people suggest doing that with Jellyfin and are not aware that almost no apps support it, and that adding exceptions for the API makes you basically as secure as not having it. But people tend to get very defensive when you try to tell them that something won't work, so I try to phrase it as a question to see if I can get them to understand what the limitations are in a way that's less confrontational.

  • source
  • parent