84 pull requests since v0.15.0. This release introduces the "Picked for you" Home rail powered by plugin shelves, Plugin Contract 1.5 with native Plex server migration to a bundled plugin, two-factor authentication (TOTP) and WebAuthn passkeys, granular per-user media access controls, a self-contained Linux AppImage player, and platform-native desktop integrations (Windows Snap Layouts and macOS Dock/menu bar).
Upgrade notes
Back up first. Eleven migrations: ten schema changes (all additive) and one Plex data migration.
-
Plex migration: Native Plex servers automatically migrate to instances of the bundled
plexplugin under Plugin Contract 1.5, carrying over tokens, user connections, and sync state without re-pushing historical progress (#972). -
Passkeys & 2FA: WebAuthn passkeys and TOTP two-factor authentication tables added for accounts (#923, #928).
-
Access restrictions: Content ratings are normalized into an integer column (
content_rating_age) with an automatic backfill job, allowing per-user restrictions by category and maximum age rating (#565). -
Plugin tables: Instances, account links, write grants, and home shelf declarations (#966, #972, #986).
-
Infohash blacklists: Release blacklist tracks torrent infohashes, applying bans across all indexers that list the same torrent (#896).
Dashboard and shelves
-
"Picked for you" Home rail: A generic recommendation foundation that any plugin can declare and fill with custom suggestions, scheduled in background jobs and verified against the catalog and user access restrictions (#986, #987, #999).
-
Plugin shelves API: Typed WIT 1.6 interface (
surfaces:shelfcapability) with event-driven cache invalidation, catalog verification, and per-user dismissal tracking (#986).
Plugins and extensions
-
Host Contract 1.5: Multi-instance plugin support, instance-scoped KV storage with size quotas, and sync run reports (#972).
-
Bundled Plex plugin: Native Plex servers moved into a bundled multi-instance plugin with automated schema migration (#972).
-
Plugin sideloading: CLI command (
mydia-cli plugin install <path>) for unpublished or local plugins (#970). -
Community store: Official extra plugins index for browsing and installing community plugins (#961, #971).
-
Config via env: Plugin settings configurable via environment variables (
PLUGIN_<SLUG>_SETTINGS) for container and headless deployments (#975). -
Write security: User confirmation prompts and standing write grants per plugin surface (#966).
-
Experimental assistant: Optional, unbundled plugin demonstrating plugin pages and shelf generation (#966, #974, #977, #978).
Accounts and security
-
Two-factor authentication (TOTP): Setup with QR code, encrypted secrets, replay guards, and single-use recovery codes (#923).
-
WebAuthn passkeys: Biometric and security key passwordless sign-in and second-factor authentication (#928).
-
Granular access controls: Restrict user accounts to specific media categories and content age ratings, enforced in queries and streaming (#565).
Player
-
Linux AppImage: Standalone Linux AppImage packaging built on Ubuntu 22.04 with in-place self-updates (#952).
-
Linux desktop integration: Native MPRIS media session integration, restored window shadows, and rounded corners (#916, #930, #933).
-
Windows integration: Immersive window chrome, Windows 11 Snap Layouts integration (HTMAXBUTTON), and fullscreen exit fixes (#941, #942).
-
macOS integration: Native macOS menu bar and Dock menu actions (#911), polished window chrome (#915).
-
Streaming & playback: Resumed HLS streams report accurate position without stalling, cast bar detaches without interrupting playback, and closing the cast bar hides it instead of stopping playback (#929, #993, #998).
-
Artwork & Web player: Bounded artwork decode sizes and WebGL fallback on Safari/Firefox to prevent black or disappearing posters (#940, #995).
-
Web app: Installable Progressive Web App (PWA) on iOS and iPadOS (#967).
-
Diagnostics: Remote player log capture, local rolling logs, and relay upload for diagnostics (#900).
-
Channel branding: Visual beta and dev badges on app icons, window headers, and settings (#935).
Media, library and discover
-
Discover: Regional streaming availability and home country filtering (#960, #962, #968).
-
Library filtering: Filter Movies and TV shows by specific library (#921), and export catalog as JSON or CSV (#919).
-
Poster display: Configurable poster fields, content rating and TV status badges, and mobile-friendly display toggles (#924, #925, #964).
-
File management: Remove empty item folders from disk when deleting media, selective file renaming by season or episode, and stricter import matching to prevent misfiling (#897, #939, #958, #959).
-
Metrics: Optional Prometheus metrics endpoint at
/metrics(#920).
Downloads and indexers
-
Infohash blacklists: Torrent infohashes recorded on blacklist rows to ban broken releases across all indexers (#896).
-
Release identity: Strict release identity check rejecting mismatched releases using alternate titles or alias matching without loose string distances (#899, #913).
-
Quality profiles: Hard limits enforced for max size, max resolution, and required HDR (#946).
Under the hood
-
Metadata relay v0.20.0: Cloudflare edge caching for client config and metadata lookups (#902, #962, #963).
-
P2P startup: Concurrent peer dialing and earlier connection attempts to reduce startup latency (#909).
-
Job processing: StatusTracker stabilizes sidebar job indicator against flickering on short tasks (#948, #979).
-
Freshness checks: Deterministic npmDeps.hash verification and cargo lock index retry resilience (#927, #969).