Synced rows only ever had the Played flag set. Jellyfin computes Next Up
from LastPlayedDate on the member's own row and Continue Watching from
the resume position, so a member watching through the shared account got
the tick on each episode but their Next Up never advanced. Members are
now written the way BaseItem.MarkPlayed/MarkUnplayed write: date and
position included. Rows the old version ticked without a date are
repaired the next time the item syncs.
PlaybackFinished was also treated as an unwatched toggle. Jellyfin raises
it on every stop, not just completion (and on 10.11 PlaybackStart resets
Played to false first), so a stop halfway through on the shared account
cleared members' own watched state whenever Sync unwatched was on.
Playback-derived reasons (PlaybackFinished, PlaybackProgress,
UpdateUserData) now only ever mirror "watched"; TogglePlayed and Import
remain explicit and mirror either way. PlaybackProgress is acted on so
the tick lands as soon as the completion threshold is crossed, including
for clients that never report a stop.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Replaces the plugin template with a working plugin that lets several
users share one viewing account while keeping their individual watched
lists accurate.
Three pieces:
- Auto-creating groups. Logging in as "alice+bob" with any named
member's own password provisions the shared account and signs you in.
Verified against 10.11.5: AuthenticateUser offers unmatched usernames
to every enabled provider and re-queries afterwards, which is the hook
this relies on. Gated on a real member password so knowing two
usernames is not enough to create an account.
- Multi-password authentication. IRequiresResolvedUser hands us the
resolved shared account; each member's live stored hash is checked via
ICryptoProvider.Verify. Deliberately avoids re-entering
UserManager.AuthenticateUser, which would trip every member's
failed-attempt counter whenever a different member's password matched.
- One-way played-state sync. Shared account to members only, filtered to
PlaybackFinished/TogglePlayed/Import so playback progress ticks are
ignored. No loop guard needed: member writes carry a non-shared id.
Membership is stored as user IDs rather than re-parsed from the username,
so shared accounts can be renamed freely. The +/name collision resolves
itself because Jellyfin only consults the plugin when no local user
matches the typed name.
Targets Jellyfin 10.11.x / net9.0. Adds Gitea CI (test, build, release),
a builder image, and 34 tests covering the auth and sync rules.