I thought that you can still access media directly via the URL without any authentication, how would authelia change that?
Comment on Plex has paywalled my server!
kuhli@lemmy.dbzer0.com 2 days agoYou can address the 2fa by putting it behind something like authelia, but still, the project needs to step it up
ipkpjersi@lemmy.ml 2 days ago
kuhli@lemmy.dbzer0.com 2 days ago
Yes! You just have to set up your reverse proxy to send everything through it and it’ll block the unauthenticated access.
The downside is that apps stop working since they don’t have a way to authenticate with authelia. I’ve installed it as a PWA on my phone and use an old laptop with the TV interface on my TV, but it’s not perfect
ipkpjersi@lemmy.ml 1 day ago
Are you sure that works? I’m pretty sure they mentioned that reverse proxies are an unsupported (and not working) use case with Jellyfin, but I might have to look into authelia some time then.
rumba@lemmy.zip 1 day ago
I just put it behind an HAProxy a few minutes ago, It appears to be fine. You just need something capable enough to handle web sockets. I’ve made it all the way through an episode of The real monsters without any problems.
Again, you’re not going to be able to 2FA it that way, what I’m looking at doing is IP whitelisting it in HAProxy using a small web helper that is 2FA, accessed via the same port but on a separate path.
kuhli@lemmy.dbzer0.com 1 day ago
Its unsupported, but I have mine running behind nginx and haven’t run into any problems other than the aforementioned app issues.
rumba@lemmy.zip 2 days ago
Authelia is super easy, if the clients can handle it