Commit Graph

7 Commits

Author SHA1 Message Date
4b827941ee fix: make the release workflow build and package a real Jellyfin plugin
All checks were successful
Build Plugin / build (push) Successful in 4m29s
Release Plugin / release (push) Successful in 1m7s
The release workflow was copied from another project and could not succeed on
any tag: it installed the .NET 8 SDK for a net9.0 project, published a
JellyfinSso.csproj that does not exist, called a missing update_manifest.py,
and zipped the entire publish tree instead of the three DLLs declared in
build.yaml.

Replace it with a tag-driven release:

- Build with the .NET 9 SDK, injecting the tag version via -p:Version,
  -p:AssemblyVersion and -p:FileVersion so the assembly no longer carries a
  hardcoded 1.0.3.0.
- Package via scripts/build_plugin.py, which emits the JPRM layout Jellyfin
  expects: the build.yaml artifacts plus a generated meta.json. The previous
  zips shipped without meta.json, which only worked for repository installs
  because Jellyfin synthesises one from the folder name.
- Update manifest.json via scripts/update_manifest.py, keeping build.yaml as
  the single source of truth for plugin metadata.
- Commit the zip and manifest to main and attach the zip to the Gitea release.
  Pushing uses the injected token, falling back to a RELEASE_TOKEN secret when
  the built-in one lacks write access.

Also fix the published download URLs. manifest.json and the README pointed at
pascallinxweiler/jellyfinplugin, which 404s; the repository is jellyfinsso, so
the plugin repository could not be added to Jellyfin and no version could be
downloaded. The workflow now derives the URL from GITHUB_REPOSITORY.

Add a build workflow so main and pull requests are compiled and packaged.

Co-Authored-By: Claude <noreply@anthropic.com>
v1.0.4.0
2026-07-29 15:18:40 +02:00
10ea812a3c ja 2026-07-29 15:01:15 +02:00
Pascal Linxweiler
7dc79bf003 fix: admin role mapping grants only, revoke behind opt-in
SSO login for an existing admin whose token lacked the admin role was
silently demoting the account, locking admins out of the dashboard.
Missing admin role now leaves the flag alone unless
RevokeAdminWithoutRole is enabled.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 14:44:07 +02:00
Pascal Linxweiler
606f14dfab feat: log OIDC claims and admin mapping, case-insensitive roles
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 14:41:24 +02:00
Pascal Linxweiler
fd36fb246b fix: target Jellyfin 10.11 / net9.0
Server 10.11 moved PermissionKind to Jellyfin.Database.Implementations.Enums,
SetPermission to a Jellyfin.Data extension, and ChangePassword now takes a
user id. Plugin built against 10.10 failed to load silently.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 13:57:25 +02:00
Pascal Linxweiler
da5de2fd6a chore: point plugin repo manifest at git.linxweiler.xyz, ship dist zip
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 13:08:52 +02:00
Pascal Linxweiler
2380e97e79 feat: initial Jellyfin OIDC auth plugin
OpenID Connect SSO for Jellyfin 10.10 (net8.0). Authorization code flow
with PKCE via IdentityModel.OidcClient, automatic user creation with
random password, role based admin/access mapping, plugin repo manifest.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 13:07:54 +02:00