Skip to content

fix(jellyfin): send modern Authorization header on internal and admin requests - #25

Merged
SoPat712 merged 1 commit into
SoPat712:devfrom
maun200:fix/jellyfin12-internal-auth-headers
Sep 27, 2026
Merged

SoPat712 merged 1 commit into
SoPat712:devfrom
maun200:fix/jellyfin12-internal-auth-headers

Conversation

@maun200

@maun200 maun200 commented Sep 23, 2026

Copy link
Copy Markdown

Problem

Jellyfin 12 ignores the legacy X-Emby-Authorization / X-Emby-Token request headers. Sent against Jellyfin 12.1:

Header POST /Users/AuthenticateByName (unknown user)
X-Emby-Authorization: MediaBrowser Client="…", … 400 Value cannot be null. (Parameter 'request.App')
Authorization: MediaBrowser Client="…", … 401 (expected)

Token-only requests fail the same way (401 even with a valid key).

Client proxying on dev already moved to Authorization in 1d11bcd. A few server-side call sites still send only the legacy headers, so on Jellyfin 12 they go out unauthenticated:

  • BackendLibraryIndexing / BackendLibraryRefresh: API key via X-Emby-Token
  • AdminHelperService.CreateJellyfinRequest: API key via X-Emby-Authorization
  • AdminAuthController: avatar fetch via X-Emby-Token
  • JellyfinAdminController.CreateJellyfinRequestForSession: sent both legacy headers

Change

All of these now send Authorization: MediaBrowser … Token="…" through the existing AuthHeaderHelper.CreateAuthHeader. Older Jellyfin releases accept this form too. The duplicate X-Emby-Token in JellyfinAdminController is dropped, because the full header already carries the token.

BackendLibraryIndexingTests now asserts the Authorization header instead of X-Emby-Token.

Testing

  • dotnet test on dev with and without this change: the same 593 tests fail in both runs. All of them are environment-only (ALLSTARR_TEST_POSTGRES not set, no docker binary in the SDK container). There are no new failures.
  • The affected test classes (BackendLibraryIndexing, AdminAuthController, JellyfinAdmin*, BackendLibraryRefresh, AdminHelper*): 19/19 passed.
  • I found the underlying issue while running v2.0.3 against Jellyfin 12.1 (client logins failed with the 400 above). We run a build-time patch equivalent to this change in production.

🤖 Generated with Claude Code

… requests

Jellyfin 12 no longer honours the legacy X-Emby-Authorization / X-Emby-Token
request headers. Client proxying was already moved to `Authorization` in
1d11bcd, but a few server-side call sites still used the legacy headers:

- BackendLibraryIndexing / BackendLibraryRefresh (API key)
- AdminHelperService.CreateJellyfinRequest (API key)
- AdminAuthController avatar fetch (session token)
- JellyfinAdminController non-admin session requests (sent both legacy headers)

Against Jellyfin 12 these requests are unauthenticated (401). Send
`Authorization: MediaBrowser ... Token="..."` via AuthHeaderHelper.CreateAuthHeader
instead; this form is also accepted by older Jellyfin releases.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@SoPat712
SoPat712 merged commit 78e305a into SoPat712:dev Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants