[Question]: Is being able to download without account intended? #4737

Closed
opened 2026-02-07 01:06:55 +03:00 by OVERLORD · 2 comments
Owner

Originally created by @Emporea on GitHub (Mar 27, 2023).

Please describe your bug

Is it intended that you can download any file, regarding of being logged into jellyfin or not, given the link?

Even if the possible combinations of alpha-numeric characters are pretty high its still possible to just download without any account.

https://jelly.example.tld/Items/69d5e4f61ff1a70e47775feb6d25db31/Download?api_key=fe70149b3b7147bc8a99006af1952770

Is there a way for me to disable this?

Jellyfin Version

10.8.0

if other:

No response

Environment

No response

Jellyfin logs

No response

FFmpeg logs

No response

Please attach any browser or client logs here

No response

Please attach any screenshots here

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
Originally created by @Emporea on GitHub (Mar 27, 2023). ### Please describe your bug Is it intended that you can download any file, regarding of being logged into jellyfin or not, given the link? Even if the possible combinations of alpha-numeric characters are pretty high its still possible to just download without any account. `https://jelly.example.tld/Items/69d5e4f61ff1a70e47775feb6d25db31/Download?api_key=fe70149b3b7147bc8a99006af1952770` Is there a way for me to disable this? ### Jellyfin Version 10.8.0 ### if other: _No response_ ### Environment _No response_ ### Jellyfin logs _No response_ ### FFmpeg logs _No response_ ### Please attach any browser or client logs here _No response_ ### Please attach any screenshots here _No response_ ### Code of Conduct - [X] I agree to follow this project's Code of Conduct
OVERLORD added the bug label 2026-02-07 01:06:55 +03:00
Author
Owner

@nielsvanvelzen commented on GitHub (Mar 27, 2023):

Your example includes your personal access token so it does use authentication.

@nielsvanvelzen commented on GitHub (Mar 27, 2023): Your example includes your personal access token so it does use authentication.
Author
Owner

@Emporea commented on GitHub (Mar 27, 2023):

Allright. This makes sense. Sorry😳

@Emporea commented on GitHub (Mar 27, 2023): Allright. This makes sense. Sorry😳
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/jellyfin#4737