• h0rnman@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    2
    ·
    18 hours ago

    You can already do number 2 (with some restrictions). You have to set up your networking tab correctly, use blank passwords, and uncheck “allow remote connections” for the “local” accounts. i have things set up so that external users are forced to log in and local users just pick a profile. If you also add your external users’ IP addresses to the LAN Networks box, they’ll be treated as an internal user too (though how you keep that up to date is a bit more challenging). It’s not precisely the Netflix experience but it works well enough for us

    • zephiriz@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      18 hours ago

      I’ll have to look into that. Last I remember they removed that and local simple pin. Because it could be used to bypass security even from outside network. You are running current version right?

      • h0rnman@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        4
        ·
        18 hours ago

        Ya - or close enough (10.11.3). My LAN networks are my server and workstation subnets (both /24s) and my external NAT (my public ip). I also have my reverse proxy address (from jellyfin’s perspective) in my known proxies. From there, my external users are set to allow remote connections, have passwords set, and are set to “hide this user from login screens” and my internal users are set to NOT allow remote connections and to NOT hide from login screens. After that, i just use my public dns for every device whether it’s internal or external and call it a day