Files
jellytau/docs/specs
dtourolle da762da55d feat(profiles): multi-user profiles with PIN switching
A shared device can hold several accounts from the same server and switch
between them in a couple of taps. A profile can be locked behind a 4-8
digit PIN; one without a PIN is one tap away. Forgetting a PIN falls
through to the account's own Jellyfin password, so there is no reset flow
and no recovery secret to store.

Opt-in by construction: a single account with no PIN starts, plays and
downloads exactly as before, and never sees a picker.

Two decisions worth keeping:

- Switching is not logging out. auth_logout invalidates the token
  server-side, which is precisely what a switch must not do, or every
  switch back would cost a password. The switch runs as a plan
  (profiles/switch.rs) so the teardown *ordering* is unit-testable with
  no player and no server -- a straggler reporting after the active user
  flips would attribute one account's viewing to another, silently.

- The PIN gates switching, not the token at rest. Wrapping each token
  with its PIN would leave a locked profile unable to resume its own
  downloads or drain its own sync queue until somebody typed the code,
  which on a device that reboots nightly costs more than it defends
  against a four-digit secret. auth_initialize does refuse to restore a
  PIN-protected session, so the gate is on the session rather than on
  which screen is shown.

"Child account" is not modelled anywhere -- a child's profile is simply
one with no PIN. The frontend renders an opaque unlockMethod and never
compares a PIN, counts an attempt or infers a role.

Migration 024 adds user_pins, user_item_visibility, user_libraries and
download_grants, and backfills the existing user so an upgrade does not
blank its library. The visibility and grant tables are the schema half of
the cache-scoping and shared-download work; the read-path enforcement is
still to come (see docs/specs/multi-user-profiles.md).
2026-08-30 19:03:59 +02:00
..

Specs index

Feature specs for JellyTau. Start a new one from SPEC-TEMPLATE.md and run it past SPEC-REVIEW-CHECKLIST.md before accepting it.

What lives here

Only work that has not shipped. Once a spec is fully implemented its design is folded into the architecture docs — which are the maintained description of the build — and the spec file is deleted. Git history keeps the original, including its rejected alternatives and acceptance criteria; the architecture docs keep the reasoning that a future change still needs.

So: a file in this directory is a promise, not a description. If you want to know how something works, read docs/architecture/. If you want to know what is planned, read here.

Status vocabulary

Status Meaning
Proposed Written, not accepted. Nothing built.
Accepted Agreed as the design; implementation not started or not finished.
Partially implemented Some parts shipped; the spec names what is left.
Design authority No code of its own — it records a decision later specs act on.

Next free requirement ids (always re-check requirements.md before allocating): UR-079, IR-033, DR-232. Three specs below suggested ids that have since been taken by other work; each carries a ⚠️ note at the top.

Partially implemented

Spec What landed What is left
frontend-domain-model.md Catalog surface: MediaKind, from_jellyfin isolated, ticks → ms primaryImageTagimageId (~30 sites); player/session/reporting tick math; stream.type
libmpv2-migration.md LICENSE The libmpvlibmpv2 crate swap
read-through-media-cache.md DR-126…128, DR-133…138 — cache entries are download rows; local playback of downloads DR-122/124/125 — the read-through capture. DR-121 shipped as backend-owned stream selection and left this spec
scoped-search-boundary-implementation.md Stage 1: SearchScope owned by Rust (DR-063…067) Stage 2: result-side grouping (GROUP_ITEM_TYPES still in searchScope.ts)

Not started

Spec Blocked on / note
desktop-native-video.md mpv draws video on every desktop platform, then the webview <video> path and hls.js are deleted. Converts a measured 7% direct-play rate toward Android's 85%. Stacked on backend-owned stream selection.
backend-owned-stream-selection.md Rust owns direct-play-vs-transcode, transport and quality; players consume one StreamSelection. Partly built — StreamSelection, Transport and the .m3u8 sniff removal have landed.
build-provenance.md build.rs is still bare. ⚠️ suggested id DR-093 is taken.
player-facade-enforcement.md ~60 commands.player* sites still outside the facade; no lint rule. ⚠️ suggested id DR-095 is taken.
windows-native-audio-backend.md Blocked on the libmpv2 swap. ⚠️ suggested id IR-030 is taken.
linux-native-video-spike.md Spike run 2026-08-21: compositing works on Linux, X11 and Wayland. G1-G6 green bar the Tauri default_vbox() half of G1. The adaptive-bitrate question it was waiting on is answered: the server publishes one EXT-X-STREAM-INF, so there is no ladder for mpv to lose (DR-229). StreamSelection (DR-225) is the contract to consume.

Design authority

Spec Role
playback-backend-unification.md Why video cannot unify onto one native engine and audio can. The audio half has since shipped on Android; Windows has not.
scoped-search-boundary.md The boundary design the check:boundary rule came from. Stage 1 built.
scoped-search.md Superseded in part — its "frontend only, no Rust changes" decision is the leak the boundary spec reversed. UX still current.

Where the shipped specs went

Sixteen specs were folded into the architecture docs and deleted (2026-08-21). Where to look for each:

Shipped work Now documented in
Account menu & global chrome 02-svelte-frontend.md — App Shell and Chrome
Library mosaic 02-svelte-frontend.md — Library Mosaic
Series current-episode navigation 02-svelte-frontend.md — Series and Episode Navigation
Downloads as an offline library 02-svelte-frontend.md — Downloaded Browse
Favourites browsing 01-rust-backend.md — Favorites System
Streaming bitrate cap 01-rust-backend.md — Streaming quality ladder
Locally-indexed search 03-data-flow.md — Search Flow; 01-rust-backend.md — Background workers
Offline downloaded-only filter 06-downloads-and-offline.md — Offline Catalog Visibility
Audio equalizer · Android audio settings parity 05-platform-backends.md — Audio settings on ExoPlayer
Android native video spike 05-platform-backends.md — Native Video Compositing
Video background audio 05-platform-backends.md — Background Audio Handoff
Traceability gate repair traceability-ci.md
Boundary tripwire hardening scripts/check-frontend-boundary.sh (its header is the spec)
Playback docs corrections · req-coverage script removal Nothing to document — both were corrections that have been applied