Support Jellyfin 12 alongside 10.11

Jellyfin 12 moved to .NET 10 and changed the IUserManager surface the
plugin relies on: Users/UsersIds became GetUsers()/GetUsersIds(),
ChangePassword takes a user id, HasPassword left the provider contract,
and the user cache is gone, so every lookup is a detached copy.

The plugin now multi-targets net9.0 (against 10.11.5) and net10.0
(against 12.0.0). The differences sit behind a JELLYFIN_12 constant in
Compat/UserManagerCompat.cs, whose ChangePasswordAsync also carries the
stored hash back onto the caller's instance: on 12 the UpdateUserAsync
that claims the account would otherwise write the stale null password
back over the one provisioning just set.

Each release ships one package per generation, with the fourth version
segment naming the target (x.y.z.11 and x.y.z.12) so a 12 server picks
the 12 package over the 10.11 one. scripts/package.sh wraps jprm for a
single generation and the workflows call it twice. The builder image
moves to the .NET 10 SDK, which builds both targets; the net9.0 test run
rolls forward onto the .NET 10 runtime.

CA1873 is a .NET 10 analyzer that flags the same log calls CA1848 does;
it is set to Info, as in the upstream Jellyfin 12 tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-11 19:25:16 +02:00
co-authored by Claude Opus 5
parent 17bb9a1e8a
commit bd08629fff
18 changed files with 411 additions and 111 deletions
@@ -43,8 +43,7 @@ public class ProvisioningTests
return created;
});
userManager.Setup(m => m.ChangePassword(It.IsAny<User>(), It.IsAny<string>()))
.Returns((User user, string password) =>
userManager.SetupChangePassword(users, (user, password) =>
{
callLog.Add($"ChangePassword(provider={user.AuthenticationProviderId})");
@@ -148,4 +147,69 @@ public class ProvisioningTests
Assert.NotNull(sharedUser);
Assert.False(string.IsNullOrEmpty(sharedUser!.Password));
}
[Fact]
public async Task CreateGroupAsync_StoredPasswordSurvivesClaimingTheAccount()
{
using var context = PluginTestContext.Create();
// Models Jellyfin 12, where the user manager keeps no cache: every lookup returns a
// detached copy of the stored row, and UpdateUserAsync writes back every column of the
// instance it is handed. The random password provisioning sets must survive the provider
// assignment that is saved afterwards through a different instance.
var stored = new List<User> { MakeUser("alice"), MakeUser("bob") };
var userManager = new Mock<IUserManager>();
userManager.Setup(m => m.GetUserById(It.IsAny<Guid>()))
.Returns((Guid id) => Copy(stored.Find(u => u.Id == id)));
userManager.Setup(m => m.CreateUserAsync(It.IsAny<string>()))
.ReturnsAsync((string name) =>
{
var row = MakeUser(name);
stored.Add(row);
return Copy(row)!;
});
// On 12 the helper resolves the stored row by id, so this writes the hash there and only
// there; on 10.11 it writes to the caller's instance, as the real server does.
userManager.SetupChangePassword(stored, (user, password) =>
{
user.Password = password;
return Task.CompletedTask;
});
userManager.Setup(m => m.UpdateUserAsync(It.IsAny<User>()))
.Returns((User user) =>
{
var row = stored.Find(u => u.Id == user.Id)!;
row.Password = user.Password;
row.AuthenticationProviderId = user.AuthenticationProviderId;
return Task.CompletedTask;
});
var service = MakeService(userManager);
var group = await service.CreateGroupAsync([stored[0].Id, stored[1].Id], null);
var row = stored.Find(u => u.Id == group.SharedUserId);
Assert.NotNull(row);
Assert.Equal(AuthProviderId, row!.AuthenticationProviderId);
Assert.False(
string.IsNullOrEmpty(row.Password),
"claiming the account must not overwrite the password provisioning stored");
}
/// <summary>
/// Copies the columns provisioning touches into a fresh instance with the same id, the way a
/// cache-less user manager hands out rows.
/// </summary>
private static User? Copy(User? row)
=> row is null
? null
: new User(row.Username, row.AuthenticationProviderId, row.PasswordResetProviderId)
{
Id = row.Id,
Password = row.Password,
};
}