Commit Graph

3 Commits

Author SHA1 Message Date
fda59741b5 feat: sync the profile picture from the OIDC provider
All checks were successful
Build Plugin / build (push) Successful in 1m1s
Pocket ID exposes an avatar through the standard picture claim, pointing at
/api/users/{id}/profile-picture.png. On login the plugin now fetches that URL
and writes it to the Jellyfin user's profile image, so SSO users get their
avatar without setting one by hand.

The picture is fetched anonymously. The access token is deliberately not sent,
because the address ultimately originates from a token payload and must not be
treated as a trusted destination for credentials. Non-http(s) URLs, non-image
content types and anything over 5 MB are rejected, and an identical image is
not rewritten so the image cache is left alone. Any failure is logged and
swallowed: a broken avatar must never block a login.

Controlled by the new "Sync the profile picture" setting, on by default, with
the claim name configurable for providers that do not use "picture".

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-29 15:41:51 +02:00
Pascal Linxweiler
7dc79bf003 fix: admin role mapping grants only, revoke behind opt-in
SSO login for an existing admin whose token lacked the admin role was
silently demoting the account, locking admins out of the dashboard.
Missing admin role now leaves the flag alone unless
RevokeAdminWithoutRole is enabled.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 14:44:07 +02:00
Pascal Linxweiler
2380e97e79 feat: initial Jellyfin OIDC auth plugin
OpenID Connect SSO for Jellyfin 10.10 (net8.0). Authorization code flow
with PKCE via IdentityModel.OidcClient, automatic user creation with
random password, role based admin/access mapping, plugin repo manifest.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 13:07:54 +02:00