Release Notes
Security
- Fix GHSA-h3r4-r2f2-qf59 (CVE-PENDING)
- All users who link Plex or Emby media servers should upgrade as soon as possible
- After upgrading, it is highly recommended to rotate your Plex token and Emby API key
- To rotate Plex token:
- In Media Sources > Plex click Re-authenticate with Plex and complete the sign in to generate a new token
- Restart ErsatzTV so it picks up the new token immediately; connection details are cached for up to 30 minutes
- In https://app.plex.tv/ Account Settings > Authorized Devices delete the old ErsatzTV authorized device
- Restart the Plex server to immediately invalidate the token that the old authorized device used
- To rotate Emby API key:
- Generate new API key in Emby's Dashboard > Advanced > API Keys
- In Media Sources > Emby click Edit Emby Connection, paste the new API key and click Save Changes
- Delete the old API key in Emby's API Keys screen
- To rotate Plex token:
- Jellyfin users are not affected and have no reason to rotate the API key
- Fix case where specifically-crafted requests could access management UI over streaming port
Added
- Add
Re-authenticate with Plexbutton to the Plex media sources page- Use this to replace the credentials ErsatzTV uses (after a Plex password reset, or after signing out of all Plex devices) without removing media sources or synchronized content
- This registers ErsatzTV with Plex as a new device, so Plex issues a new token; signing in again previously returned the same token
- To revoke the old token, remove the old
ErsatzTVentry fromAuthorized Devicesat plex.tv and restart your Plex server
Changed
- BREAKING CHANGE: require
X-Etv-Api-Keyheader for all API requests under/api- The API key is automatically created at startup and can be found in the
api-secrets.jsonfile in the config folder - Scripted schedule scripts are passed the API key in the
ETV_API_KEYenvironment variable, and must send it in theX-Etv-Api-Keyheader on every call- The key is not passed as a command line argument, so it does not appear in the process list or in logs
- Scripts that use the bundled docker entrypoint (
/app/scripted-schedules/entrypoint.py) need no changes - Hand-written scripts and generated clients must be updated; the API key security scheme is now included in the OpenAPI descriptions
- Troubleshooting playback endpoints are requested directly by the browser, so they authorize with the management UI session instead of the API key
- The API key is automatically created at startup and can be found in the
- Plex servers that are no longer listed at plex.tv are now flagged instead of deleted
- Previously, re-authenticating before re-claiming a server at app.plex.tv would delete that server along with its libraries and all of its media
- Flagged servers are skipped during scans, and are removed only when you choose to remove them
Fixed
- Fix Plex page staying disabled until restart when a sign-in is not completed within two minutes, or when plex.tv cannot be reached
- Fix Plex page showing no indication that ErsatzTV has been signed out of Plex
- Fix mirror channels falling out of sync when using the next streaming engine