Milestones
List view
Security and quality alerts are worked before anything else; every open alert is one issue here (rule of 2026-09-05, fleet-wide since 2026-09-06).
No due date•3/4 issues closedWorks alone, works with every supported sibling
No due date•2/3 issues closedThe README, the security policy, the operator guide, the changelog, and everything needed for the plugin catalogue.
No due date•40/43 issues closedTake the gate of iderex/jellyfin-plugin-sso as the target, adopt what fits, and give one line of reasoning for every difference in either direction.
No due date•40/43 issues closedConfig and store migration, what unpairing means for data that already moved, and what disable and uninstall leave behind.
No due date•8/12 issues closedThe dashboard page, the endpoints behind it, the configuration schema, and the authorization every one of them enforces.
No due date•10/14 issues closedThe versioned contract the two sync plugins code against. Versioned from day one, and it never hands out key material.
No due date•1/7 issues closedMapping users across two servers and resolving the same item on both, with conflict rules that refuse rather than guess.
No due date•10/15 issues closedWhere long-term and per-pairing key material lives, what protects it at rest, what protection the host cannot give, and what happens on backup, restore and corruption.
No due date•7/9 issues closedEstablishment, verification, request authentication, replay refusal, rotation and revocation. The core of the plugin.
No due date•42/47 issues closedWrite down what is being defended, against whom, and what the wire looks like, before any protocol code exists. The threat model is the reference every later issue argues against.
No due date•12/13 issues closedTurn the unchanged plugin template into this plugin: its own identity, its own manifest, a real test project, a pinned toolchain, and the headless test policy the whole plan is built on.
No due date•12/12 issues closed