diff --git a/pkgs/by-name/je/jellyfin/fix-playlist-visibility.patch b/pkgs/by-name/je/jellyfin/fix-playlist-visibility.patch new file mode 100644 index 000000000000..86dd4f629243 --- /dev/null +++ b/pkgs/by-name/je/jellyfin/fix-playlist-visibility.patch @@ -0,0 +1,26 @@ +From 5f13afa1cecfae398ff7d84ed89fc45b14b71c61 Mon Sep 17 00:00:00 2001 +From: Shadowghost +Date: Thu, 4 Jun 2026 19:00:03 +0200 +Subject: [PATCH] Fix playlist visibility + +--- + MediaBrowser.Controller/Entities/Folder.cs | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/MediaBrowser.Controller/Entities/Folder.cs b/MediaBrowser.Controller/Entities/Folder.cs +--- a/MediaBrowser.Controller/Entities/Folder.cs ++++ b/MediaBrowser.Controller/Entities/Folder.cs +@@ -811,7 +811,10 @@ namespace MediaBrowser.Controller.Entities + + private bool RequiresPostFiltering2(InternalItemsQuery query) + { +- if (query.IncludeItemTypes.Length == 1 && query.IncludeItemTypes[0] == BaseItemKind.BoxSet) ++ // BoxSets and Playlists can have per-user visibility (shares/open access) that is stored in the ++ // serialized item data and cannot be evaluated by the database query, so filter them in memory. ++ if (query.IncludeItemTypes.Length > 0 ++ && query.IncludeItemTypes.All(t => t == BaseItemKind.BoxSet || t == BaseItemKind.Playlist)) + { + Logger.LogDebug("Query requires post-filtering due to BoxSet query"); + return true; +-- +2.51.0 diff --git a/pkgs/by-name/je/jellyfin/package.nix b/pkgs/by-name/je/jellyfin/package.nix index 15505b3a49a6..d0dabbd88fc7 100644 --- a/pkgs/by-name/je/jellyfin/package.nix +++ b/pkgs/by-name/je/jellyfin/package.nix @@ -1,6 +1,7 @@ { lib, fetchFromGitHub, + fetchpatch, nixosTests, dotnetCorePackages, buildDotnetModule, @@ -23,6 +24,34 @@ buildDotnetModule (finalAttrs: { hash = "sha256-HCs4ZsutVoVH+bBZANjpPeMyV8e63Yemjg9DSr0R9zg="; }; + patches = [ + # Prevent SSRF, local file disclosure and DoS via external references in SVG rendering. + # (No public PR.) + (fetchpatch { + url = "https://github.com/jellyfin/jellyfin/commit/cefa78fc1de2410e5c5c6da5062c98fe98b22d17.patch"; + hash = "sha256-TxGo+sLLG+C9omxrwvO6byzw+iRqONVLXrQKwkrY22s="; + }) + + # Fix MaxLoginAttempts not honored. + # https://github.com/jellyfin/jellyfin/pull/17274 + (fetchpatch { + url = "https://github.com/jellyfin/jellyfin/commit/8b826d981bcfec22063d6008e38016f4b77790d0.patch"; + hash = "sha256-Nav05TcpjBJABybU0BVyJ0UyxKi+6nDNBQ6tjY0DPT8="; + }) + + # GHSA-9x85-gx46-6522 + # Reject user impersonation when retrieving private playlist items. + # (No public PR.) + (fetchpatch { + url = "https://github.com/jellyfin/jellyfin/commit/911ac3769cdcce50a8f6e0b3c0739d509bd9a23f.patch"; + hash = "sha256-MwaTwqhuBc7yWW3cL6htlyDQ9O1wt5iFCOM/oVTi6P0="; + }) + + # Don't let unauthorized users to list other's private playlists. + # https://github.com/jellyfin/jellyfin/pull/17025 + ./fix-playlist-visibility.patch + ]; + propagatedBuildInputs = [ sqlite ]; projectFile = "Jellyfin.Server/Jellyfin.Server.csproj";