Jump to content

Just discovered a potentially horrifying problem


Go to solution Solved by Luke,

Recommended Posts

jluce50
Posted (edited)

I have a "restricted" library and a user that only has access to that library. No other users have permission to see anything in that library. I discovered today that if I'm logged in as a user that shouldn't have access to that library, I can click the three-dot menu (or right click) on the Playlists item in the My Media section of the Home Screen, select Shuffle, and it will play items from the restricted library's playlists. Very not good! Clicking on the Playlists item just shows me the playlists I expect to see (i.e. not restricted playlists).

firefox_VHbl37r8Q0.png.4b54a04a8d2abe54b10631830dd01f8d(Custom).png.c5c1343feffdad2296360750f894b224.png

 

Edited by jluce50
jluce50
Posted
On 1/19/2026 at 8:12 PM, Luke said:

HI there, can you please provide a specific example?

How to Report a Problem

Thanks !

 

 

Not sure what information is helpful, but here's the relevant info I can think of:

For the restricted library, "Exclude from global search" is enabled.

For my non-restricted user, the restricted library is unchecked in the Access panel of User settings.

It's difficult to reproduce since most of the time I get a "Playback error" or some other file from my library (no idea what's actually happening behind the scenes here...). I'll keep trying and post the relevant log info if I'm able to make it happen again.

jluce50
Posted
On 1/19/2026 at 8:12 PM, Luke said:

HI there, can you please provide a specific example?

How to Report a Problem

Thanks !

 

I was finally able to reproduce this again. I ran the test at 12:34, so I grabbed the relevant section of the log starting at 12:32 until the end. I replaced the title of the video with "[scrubbed]", but it should definitely not be playable by the user I'm logged in as. I know the whole log is ideal, but there's too much stuff to scrub out. Let me know if this isn't sufficient.

 

embyserver.txt

pwhodges
Posted

Heh - so maybe your security concern over logs prevents you potentially giving enough information to fix another security concern :) !   But actually, Luke will accept logs by PM, so you can get them to him that way for security.

Paul

Tigga5
Posted

Oh, this is awesome. Just tested this myself from my kid's account to see if it was a fluke. Literally the first thing that played was a restricted video from a library they don't even have access to. WTF??

This is truly pathetic. It's becoming a recurring theme that "Restricted" in Emby is just a polite suggestion rather than an actual permission. When are the devs going to start taking parental controls and data access seriously?

jluce50
Posted
6 hours ago, Tigga5 said:

Oh, this is awesome. Just tested this myself from my kid's account to see if it was a fluke. Literally the first thing that played was a restricted video from a library they don't even have access to. WTF??

This is truly pathetic. It's becoming a recurring theme that "Restricted" in Emby is just a polite suggestion rather than an actual permission. When are the devs going to start taking parental controls and data access seriously?


Is this you by any chance? Either way, looks like we're not the only ones frustrated by this...
 

 

DarKni8
Posted (edited)

Man this is some pathetic coding for such reputed app. It may be fixed in few years looking at track record

Edited by DarKni8
  • Solution
Posted

Hi, this is resolved for the next set of server and app releases. Thanks.

  • Like 1
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...