fix(jellyfin): send modern Authorization header on internal and admin requests - #25
Merged
SoPat712 merged 1 commit intoSep 27, 2026
Conversation
… requests Jellyfin 12 no longer honours the legacy X-Emby-Authorization / X-Emby-Token request headers. Client proxying was already moved to `Authorization` in 1d11bcd, but a few server-side call sites still used the legacy headers: - BackendLibraryIndexing / BackendLibraryRefresh (API key) - AdminHelperService.CreateJellyfinRequest (API key) - AdminAuthController avatar fetch (session token) - JellyfinAdminController non-admin session requests (sent both legacy headers) Against Jellyfin 12 these requests are unauthenticated (401). Send `Authorization: MediaBrowser ... Token="..."` via AuthHeaderHelper.CreateAuthHeader instead; this form is also accepted by older Jellyfin releases. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Jellyfin 12 ignores the legacy
X-Emby-Authorization/X-Emby-Tokenrequest headers. Sent against Jellyfin 12.1:POST /Users/AuthenticateByName(unknown user)X-Emby-Authorization: MediaBrowser Client="…", …Value cannot be null. (Parameter 'request.App')Authorization: MediaBrowser Client="…", …Token-only requests fail the same way (401 even with a valid key).
Client proxying on
devalready moved toAuthorizationin 1d11bcd. A few server-side call sites still send only the legacy headers, so on Jellyfin 12 they go out unauthenticated:BackendLibraryIndexing/BackendLibraryRefresh: API key viaX-Emby-TokenAdminHelperService.CreateJellyfinRequest: API key viaX-Emby-AuthorizationAdminAuthController: avatar fetch viaX-Emby-TokenJellyfinAdminController.CreateJellyfinRequestForSession: sent both legacy headersChange
All of these now send
Authorization: MediaBrowser … Token="…"through the existingAuthHeaderHelper.CreateAuthHeader. Older Jellyfin releases accept this form too. The duplicateX-Emby-TokeninJellyfinAdminControlleris dropped, because the full header already carries the token.BackendLibraryIndexingTestsnow asserts theAuthorizationheader instead ofX-Emby-Token.Testing
dotnet testondevwith and without this change: the same 593 tests fail in both runs. All of them are environment-only (ALLSTARR_TEST_POSTGRESnot set, nodockerbinary in the SDK container). There are no new failures.BackendLibraryIndexing,AdminAuthController,JellyfinAdmin*,BackendLibraryRefresh,AdminHelper*): 19/19 passed.🤖 Generated with Claude Code