dtourolle 192a8b3c67 fix(credentials): persist the fallback key instead of deriving an unstable one
The encrypted-file fallback derived its AES key from the hostname, a
hardcoded salt and `$USER`. Two problems, and the second is the one users
actually hit.

It was never secret. Every input is readable by anyone who can read the
ciphertext beside it, so the derivation bought nothing against the threat
its name implies. Calling the result "AES-256-GCM encrypted" oversold it.

And it was unstable. Renaming the machine, or launching from a context
where `$USER` is unset — a systemd user service, some desktop launchers —
changed the key and made every stored token undecryptable.
`load_credentials_file` reports a failed decrypt as "no stored
credentials", so this surfaced as being silently signed out with nothing
to explain it.

The key is now 32 random bytes persisted beside the credentials file, mode
0600, generated on first use. That is strictly better on both counts:
higher entropy, and it does not move when the machine does. It is still
obfuscation at rest rather than a secret — the key sits next to what it
opens — and the module docs now say so plainly instead of implying
otherwise. The keyring remains the only place a token is really protected.

The old derivation is kept solely to read a file written by an earlier
build; anything it opens is immediately rewritten under the persisted key,
so no one is signed out by the upgrade.

Verified against aarch64-linux-android as well as the host.
2026-09-07 22:24:45 +02:00
2026-08-27 17:58:06 +02:00
2026-01-26 22:21:54 +01:00
2026-08-27 17:58:06 +02:00
2026-08-27 17:58:06 +02:00
2026-01-26 22:21:54 +01:00
2026-01-26 22:21:54 +01:00

JellyTau logo
JellyTau

A cross-platform Jellyfin client built with Tauri, SvelteKit, and TypeScript.

Business logic lives in a Rust backend; a UI-rich Svelte frontend handles presentation and talks to it over Tauri's IPC. Targets Linux (libmpv) and Android (ExoPlayer).

Getting Started

This project uses bun as its package manager.

# Activate the Rust environment (fish shell)
source "$HOME/.cargo/env.fish"

# Install dependencies
bun install

# Run in development
bun run tauri dev

# Type-check the frontend
bun run check

# Build for Linux
bun run tauri build

# Build for Android
bun run tauri android build

For the full set of build, test, and Android helper scripts, see scripts/README.md.

Documentation

Topic Location
Architecture overview & subsystem docs docs/architecture/
Requirements, traceability & technical debt docs/requirements.md
Build & release process docs/build/build-release.md
Docker builds docs/build/docker.md
Traceability tooling & CI docs/traceability.md, docs/traceability-ci.md
Release checklist docs/release-checklist.md
UX flows docs/ux-flows.md
CI operations (builder image, secrets, runner) docs/build/ci-operations.md

Contributing

CONTRIBUTING.md covers the setup, the gates a change has to pass, and the two rules that catch people out (bug fixes start with a failing test; Jellyfin's taxonomy stays in Rust). Please also read the Code of Conduct.

Found a security problem? Do not open an issue — see SECURITY.md.

Verifying a download

Every release publishes SHA256SUMS covering all of its artifacts, plus an SBOM of what went into the build:

sha256sum -c SHA256SUMS

Desktop builds update themselves from Settings → Updates, verifying each payload against JellyTau's signing key before installing. Android installs are handled by the system installer, so the app links to the releases page instead.

VS Code + Svelte + Tauri + rust-analyzer.

License

MIT

S
Description
A jellyfin client with Tauri
Readme MIT
198 MiB
2026-09-07 20:30:29 +00:00
Languages
Rust 51.4%
TypeScript 25.4%
Svelte 16.2%
Kotlin 4.7%
Shell 1.7%
Other 0.5%