From 043de7a86c0afa0317a926c8a08c6038bb2c5e3c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Deluan=20Quint=C3=A3o?= Date: Wed, 9 Sep 2026 10:42:54 -0400 Subject: [PATCH] docs(jellyfin): correct the rationale for the public image endpoint (#6114) The comment justified anonymous access with "item ids are unguessable". That is not true: an artist id is a deterministic, unsalted hash of the artist name, id.NewHash(id.NewHash(str.Clear(lower(name)))), so it is computable offline by anyone who knows the name. The real reason the route is public is that upstream Jellyfin's is too. ImageController.GetItemImage carries no [Authorize] attribute (verified on v12.0, master/13.0.0, v10.11.9 and v10.10.7), and an anonymous request reaches LibraryManager.ItemIsVisible with a null user, which returns true unconditionally. Clients build cover URLs with no credentials at all, so requiring auth here would break them. No behavior change. --- server/jellyfin/images.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/server/jellyfin/images.go b/server/jellyfin/images.go index fcf69c039..9f1b9ce1a 100644 --- a/server/jellyfin/images.go +++ b/server/jellyfin/images.go @@ -34,8 +34,8 @@ func imageSize(maxWidth, maxHeight int) int { } func (api *Router) getItemImage(w http.ResponseWriter, r *http.Request) { - // Public endpoint, like real Jellyfin's image routes: clients fetch cover URLs without credentials - // and item ids are unguessable, so resolution runs elevated to bypass the visibility filter. + // Public, like Jellyfin's own image routes: clients build cover URLs without credentials, and + // upstream resolves them with no visibility check either (LibraryManager.ItemIsVisible, null user). ctx := request.WithUser(r.Context(), model.User{IsAdmin: true}) itemId, ok := itemIDParam(w, r, "itemId") if !ok {