Tracearr v2.8.0-beta.1 - Members can sign in
Member sign-in
People you share a server with can sign in to Tracearr with their Jellyfin, Emby or Plex account once you turn it on in Settings → Sign-in, server by server. On a user's page you can Allow or Block one person whatever the switch says. Members land on a personal dashboard of their own watching and requests, and never see a trust score, a violation, or anyone else's name or titles.
Jellyfin Quick Connect
A Jellyfin member can sign in without typing a password: the login page shows a code, they enter it in Jellyfin under Quick Connect, and Tracearr signs them in once it is approved.
Sign-in methods and View as
Username and password, single sign-on, the owner's Plex account and media server accounts can each be switched off, except the last method an owner can still use. From a user's page, an owner can view Tracearr as any admin or member, read-only for up to an hour.
New
- Members sign in with a Jellyfin or Emby password, Jellyfin Quick Connect, or their Plex account
- Member sign-in is off by default; turn it on in Settings → Sign-in, then per server
- Each person is Allow, Block or Default on their user page; Allow works even with both switches off
- /login?all also lists servers whose switch is off but where someone set to Allow has an account
- Someone the media server accepts but the owner keeps out is told to contact the server owner
- Members see their own history, stats and requests, browse libraries, and never a trust score or a violation
- Members land on a personal dashboard: last 30 days, top titles as posters, how you watch, all-time moments, requests
- Owners and admins switch the dashboard between Server and Personal, where Personal shows their own watching
- The member Library overview is what's new plus Most Popular without counts, with a Not watched by you link
- OIDC sign-in links to an allowed member by email or username
- Each sign-in method can be switched off, except the last one the owner can still sign in with
- Owners can view Tracearr as any admin or member from the user page, read-only for up to an hour
- Show members anonymous server activity gives members counts of other streams and plays, never names or titles
- The user page shows how many times each person signed in and when they last did
Improved
- Settings → Sign-in is one card that says who each sign-in method covers
- The login page only shows the sign-in methods that are switched on, including Plex
Fixes
- Signing in with OIDC on a new install now creates the owner instead of failing on a missing username
- Open on server and notification links use the server's public address when one is set
- The supervised image fixes ownership of a separately mounted image cache and /data/backup
- A concurrent streams rule kills the stream again instead of skipping it as condition cleared (#1308)
Security
- A page on another port or subdomain of the same host can no longer act with your session
- A Plex sign-in can only be finished in the browser that started it
- Crafted image paths can no longer reach other Plex, Jellyfin or Emby endpoints through the image proxy
Notes
- TRUST_PROXY=true now trusts one proxy hop and is needed for x-forwarded-host; two chained proxies need TRUST_PROXY=2
- TRUST_PROXY must be true, false, a hop count or proxy IPs/CIDRs; any other value stops startup
- CORS_ORIGIN=* now allows only requests without a session; list any other origin that needs one