4 ms·
Jellyfin's login system is a hot mess and makes it a non-starter for family use. Instead of going with the time tested login (saved) and then profile chooser (
by tekchip 4y ago
Jellyfin's login system is a hot mess and makes it a non-starter for family use.
Instead of going with the time tested login (saved) and then profile chooser (pin locked) they've decided that they would treat it like a PC with nothing but individual users. As a sort of after thought, they put in detecting if the user is connecting from the same network or not and letting a pin be used in place of the password.
First Joe User has no idea if they're on an internal network or not and the UI doesn't disclose this (probably wise from a security standpoint). So the result is users just defaulting to using their long password (my security requirement) all the time. Inconvenient, but not a dealbreaker per se. Unless you, like me, don't appreciate hearing teenagers bitch every time they have to re-type their password.
This issue is compounded greatly by the fact that the Roku app, and as far as I can tell, any other shared app situation, lets you either log the user out when closing the app, or save the login for some amount of time. In the first case we're back to the pain in the ass of every user typing their long password every single time they want to use the app (remember unsophisticated users who default to which method works every time). In the latter case in order to keep play history and such the previous user has to be logged out via a series of menus and then the new user has to type their long password circling back to where we started.
They have implemented a profile page, but the profile page is BEFORE the login phase. Which means I had to advise my family to pick fake names and nondescript images for profile images because that profile page is accessible to anyone who finds their way to the page on the internet. Quite frankly absurd.
I tried to outline this concern in the Matrix chat and the general take was "typing your password isn't that hard!" or responses that seemed to be strongly implying re-working this process would just be too hard or time consuming.
I don't doubt the difficulty, but this situation makes an otherwise awesome system entirely unusable for an unsophisticated multi-user configuration.
- Avamander 4y agoSave the password on your device if it's that hard to type? These shared password + PIN things are insecure and unnecessary to say the least.
- gsich 4y agojust get rid of yor password requirements
- faitswulff 4y agoThis is what I did. Just users with blank (0 length) passwords.
- counttheforks 4y agoYour argument is that passwords are not time tested?
- cmeacham98 4y agoHaving an account with a password isn't "time tested" and is something the average Joe wouldn't understand???
- blobevent 4y agoSecurity isnt a priority like features. Just look at the project issues and release history. Swiss cheese at best, despite the security focus claims.