What’s your go too (secure) method for casting over the internet with a Jellyfin server.

I’m wondering what to use and I’m pretty beginner at this

  • @scoobydoo27@lemmy.zip
    link
    fedilink
    English
    09 months ago

    So I’m another newbie dummy to reverse proxies. I’ve got my jellyfin accessible at jellyfin.mydomain.com but I can only access it through the web. How do I share with other people who want to use the apps? I can’t get my apps to find my instance.

      • @scoobydoo27@lemmy.zip
        link
        fedilink
        English
        09 months ago

        That was the problem, I couldn’t access anything away from my LAN. I finally figured it out though. I’m using Pangolin to access my services outside of my LAN and by default it adds a SSO option. Once I turned that off, my iPhone app was able to find my server through my domain name just fine. Thanks!

        • @pory@lemmy.world
          link
          fedilink
          English
          09 months ago

          Do note that without that layer you were using Pangolin for, your system might be compromised by a vulnerability in Jellyfin’s server or a brute force attack on your Jellyfin admin account.

          • @scoobydoo27@lemmy.zip
            link
            fedilink
            English
            09 months ago

            Understood. I set a strong password and a max login attempt on my account.

            If someone does get into my account, wouldn’t they only be able to watch what I have on my server anyway?

            • @pory@lemmy.world
              link
              fedilink
              English
              09 months ago

              if they got in…

              You’re trusting Jellyfin to not have some form of privilege escalation attack available. I’m not saying they do have one or that anyone’s exploiting it in the field, but yeah. Also if your Jellyfin admin account is allowed to download subtitles to content folders, a “just fuck shit up” style vandal-hacker could delete your media probably. If you mount the media read-only that wouldn’t be a concern.

              • @scoobydoo27@lemmy.zip
                link
                fedilink
                English
                09 months ago

                Gotcha. Jellyfin is my backup server behind plex so I’ll just keep it shut off unless I’m using it and set all security things I can within jellyfin when I am using it.

                How likely is it someone even finds my server and domain?