Emby is Jellyfin's upstream ancestor and speaks a near-identical MediaBrowser
API, so the existing Jellyfin stack is parameterised by a `MediaBrowserDialect`
rather than forked. `JellyfinClient`, its auth service, endpoint discovery, LAN
discovery, and the add/edit connection screens all take the dialect and keep one
implementation; `MediaBackend.emby` and `ConnectionKind.emby` carry it through
the neutral models, the Drift `kind` discriminator, downloads, and caches.
Every divergence below was measured against a live Emby 4.9.5 server, not
inferred from documentation, and each is documented at its capability getter.
Jellyfin's request strings stay byte-identical so nothing about its behaviour
changes.
Routes and auth
- Emby only accepts the pre-10.9 user-scoped item routes (`/Users/{id}/Items/…`,
`/Users/{id}/PlayedItems/…`, `/Users/{id}/FavoriteItems/…`); the unprefixed
forms Jellyfin 10.11 added return 404.
- The API is also served under a legacy `/emby` prefix, and both dialects accept
the token as `X-Emby-Token` or `api_key=`.
- Emby answers only its own LAN discovery datagram ("who is EmbyServer?") and
ignores Jellyfin's; its default HTTPS port is 8920.
- No `/QuickConnect` route exists, so Quick Connect stays Jellyfin-only.
Row fields Emby withholds
- `ProductionYear`, `OfficialRating`, `PremiereDate` and `DateCreated` are absent
from list rows unless named in `Fields`, which would otherwise strip the year
and age-rating badge from every card in the app.
- `UserData.LastPlayedDate` never appears on a list row under `Fields=UserData`,
`EnableUserData=true` or the user-scoped `Ids=` form — only on the single-item
detail route, or when the Emby-specific `UserDataLastPlayedDate` token is
requested. Without it every recency-ordered surface silently degrades to
library-add time, and `JellyfinApiCache.applyWatchState` stamps
`DateTime.now()` on watched rows, so an offline watch-state pull would rewrite
the cached play time of everything it walked.
Continue Watching and Next Up
- Emby computes Next Up per series only: the library-wide `/Shows/NextUp` query
returns nothing under every parameter combination tried. The shelf is
therefore reconstructed from a played-episode recency scan plus one
`/Shows/NextUp?SeriesId=` per distinct series, bounded by a shared wall clock
that covers the scan as well — per-request timeouts cannot bound the pass
because `MediaServerHttpClient` times the connect and receive phases
independently. Rows are stamped with their series' newest play from the same
response that ordered them, so no per-series enrichment request is needed.
- `/Shows/NextUp` ignores `NextUpDateCutoff`, and no server-side played-date
filter exists to delegate to (`MinDatePlayed` and `MinDateLastPlayed` are
ignored; `MinDateLastSaved`, `MinDateCreated` and `MinPremiereDate` filter
unrelated dates), so the 365-day window is applied to the scanned dates.
- The resume route returns items with no saved position, including plain next
episodes, so the Emby resume leg reads from `/Items?Filters=IsResumable`.
- Emby is ahead of Jellyfin in one place: `/Users/{id}/Items/{id}/HideFromResume`
makes Continue Watching removal a real capability.
Everything else
- `/Sessions/Playing` and `/Sessions/Playing/Progress` reject a body with no
`PlaySessionId` (HTTP 400), so playback reporting always sends one.
- Passing any `MediaTypes` value to the playlist query returns an empty list.
- There is no aggregate `/Items/Filters` route; the four filter facets are
reassembled from `/Genres`, `/OfficialRatings`, `/Studios` and `/Tags`.
- Metadata writes take name-pair lists (`Genres: [{'Name': 'Action'}]`); the
plain string array is accepted and then silently discarded.
- Custom artwork uploads must be base64 text, not raw bytes — which was broken
for Jellyfin too and is fixed for both.
- Trickplay, media segments and lyrics 404 on Emby, so scrub previews are absent
and intro/credit markers fall back to chapter names.
Verified against a local Emby 4.9.5 and a Jellyfin 10.11.11 control server:
onboarding, browse, detail, playable stream URLs serving real bytes, subtitle
sidecars, watch-state write and restore, hubs, cross-server aggregation and
search across both backends simultaneously.
66 lines
2.9 KiB
Dart
66 lines
2.9 KiB
Dart
import '../utils/device_identity.dart';
|
|
|
|
/// Builds the `MediaBrowser` Authorization header value understood by both
|
|
/// Jellyfin and Emby. Every field value is percent-encoded, and the server
|
|
/// reverses that encoding while parsing the header. The same value is used at
|
|
/// auth time and on every authenticated request so either dialect sees a
|
|
/// consistent client identity.
|
|
///
|
|
/// Encoding is what keeps the header sendable at all. A device name like
|
|
/// `Bjørn PC` cannot travel verbatim: `dart:io` rejects header values above
|
|
/// 0x7F outright, and CFNetwork puts the raw code unit on the wire as a
|
|
/// Latin-1 byte, which the server rejects as a malformed header before the
|
|
/// request is routed. It also removes the grammar hazards the header has no
|
|
/// escape for: quotes, commas, and `=` inside a value.
|
|
///
|
|
/// Both dialects require non-empty client, device, and version fields when
|
|
/// creating a session, so those values use stable fallbacks. An empty device
|
|
/// ID is omitted for authenticated requests, where the server can recover it
|
|
/// from the token; unauthenticated entry points must call
|
|
/// [requireJellyfinDeviceId].
|
|
String buildJellyfinAuthHeader({
|
|
required String clientName,
|
|
required String clientVersion,
|
|
required String deviceName,
|
|
required String deviceId,
|
|
String? accessToken,
|
|
}) {
|
|
String field(String name, String value) => '$name="${Uri.encodeComponent(value)}"';
|
|
|
|
final client = _meaningful(clientName);
|
|
final effectiveClient = client.isEmpty ? 'Plezy' : client;
|
|
final device = _meaningful(deviceName);
|
|
final version = _meaningful(clientVersion);
|
|
final id = _meaningful(deviceId);
|
|
final token = _meaningful(accessToken ?? '');
|
|
|
|
final parts = <String>[
|
|
field('Client', effectiveClient),
|
|
field('Device', device.isEmpty ? effectiveClient : device),
|
|
if (id.isNotEmpty) field('DeviceId', id),
|
|
field('Version', version.isEmpty ? '1.0' : version),
|
|
if (token.isNotEmpty) field('Token', token),
|
|
];
|
|
return 'MediaBrowser ${parts.join(', ')}';
|
|
}
|
|
|
|
final RegExp _controlCharacters = RegExp(r'[\x00-\x1f\x7f-\x9f]');
|
|
|
|
/// Percent-encoding makes any byte transportable, so the only values worth
|
|
/// filtering are the ones that carry no identity at all — a name of control
|
|
/// characters would otherwise reach the server's device list as `%00` noise
|
|
/// instead of falling back to a readable label.
|
|
String _meaningful(String value) => value.replaceAll(_controlCharacters, '').trim();
|
|
|
|
/// Validates the stable device identity required by unauthenticated
|
|
/// MediaBrowser session creation. Never substitute a placeholder: both
|
|
/// dialects key sessions and access tokens by this value, so a shared fallback
|
|
/// would collide across installations.
|
|
String requireJellyfinDeviceId(String deviceId) {
|
|
final sanitized = sanitizeHeaderValue(deviceId);
|
|
if (sanitized == null || sanitized != deviceId || sanitized.contains('"')) {
|
|
throw ArgumentError.value(deviceId, 'deviceId', 'must be a non-empty HTTP-safe value');
|
|
}
|
|
return sanitized;
|
|
}
|