Require elevation for plugin configuration pages #5651

Open
opened 2025-12-22 02:09:43 +01:00 by backuprepo · 1 comment
Owner

Originally created by @nielsvanvelzen on GitHub (Apr 30, 2024).

We've added additional security policies to the plugin endpoints in #11436. We did not add those to the plugin configuration pages due to time constraints for the 10.9 release. The web client requests these pages in an iframe (without authentication) and as such it needs additional changes.

We must secure this endpoint to avoid leaking plugin configuration pages and their related assets (JS/CSS/images etc). This might need changes in plugins too.

Originally created by @nielsvanvelzen on GitHub (Apr 30, 2024). We've added additional security policies to the plugin endpoints in #11436. We did not add those to the plugin configuration pages due to time constraints for the 10.9 release. The web client requests these pages in an iframe (without authentication) and as such it needs additional changes. We must secure this endpoint to avoid leaking plugin configuration pages and their related assets (JS/CSS/images etc). This might need changes in plugins too.
backuprepo added the
security
confirmed
labels 2025-12-22 02:09:43 +01:00
Author
Owner

@jellyfin-bot commented on GitHub (Apr 30, 2024):

Hi, it seems like your issue report has the following item(s) that need to be addressed:

  • This bug report was not filed using the issue template.

This is an automated message, currently under testing. Please file an issue here if you encounter any problems.

@jellyfin-bot commented on GitHub (Apr 30, 2024): Hi, it seems like your issue report has the following item(s) that need to be addressed: - This bug report was not filed using the issue template. This is an automated message, currently under testing. Please file an issue [here](https://github.com/jellyfin/jellyfin-triage-scripts/issues) if you encounter any problems.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: starred/jellyfin#5651
No description provided.