YT ▶ PLEX Guest Links: The First Pages That Need No Login
Why: Damien wanted a way for someone without an account (family, a friend) to send him video files for Plex, without handing out the app's login.
yt-plex can now create temporary guest links. The recipient gets a page with Damien's note, a drop zone and progress bars, and nothing else. Whatever they send lands on his Home page badged "Guest", waiting for him to choose a library and press Go. It's the design recorded in docs/ROADMAP.md, in its "simple version".
1. What's newly reachable without a login
This is the security-relevant part. https://yt.skyhouse.dev/u/<token> (the page) and /api/guest/<token>/… (its API) now answer without a session. Everything else still requires login.
- Every guest call is scoped to a 128-bit token and can only see that link's own details and touch the uploads it started. A made-up token gets a 404, and the owner API still answers 401 to a guest (tested).
- Limits are enforced server-side: expiry (1/3/7/30 days), file count and total size. Counts use completed uploads plus in-flight reservations, so chat-app link previews can't use a link up and parallel uploads can't overshoot.
- An upload that has started may finish after expiry. Turning a link off stops everything at once, including uploads in flight.
- Uploads reuse the existing chunked-upload code (resumable, shrinks chunks on HTTP 413, abandoned uploads expire after 30 minutes) and the low-disk guard.
- The guest page sends
noindexandno-referrer. - Tokens are stored in plaintext in
ytplex.dbon purpose, so a link can be copied again later. A leaked token only allows uploads into the review queue. - Nothing a guest sends reaches Plex without Damien pressing Go.
2. Setup on this server
- Action: I set the new
public_addresssetting tohttps://yt.skyhouse.dev, so links are built with the public hostname. No NPM or firewall change was needed, because the existing proxy host already carries these paths. - The paths sit under their own prefixes (
/u/,/api/guest/) so a private install could publish only them. The README documents this for Damien's friend's Docker install.
3. Also in this change
- The desktop layout (1000 px and wider) renders at 125%, at Damien's request.
- The fixed bottom bar stays aligned at the new size.
- yt-plex's own links (like a freshly copied guest link) are never offered back from the clipboard.
- On phones, the Settings tabs scroll sideways now that there are six.
I tested it end to end in a neutralized preview: one browser created a link, and a second browser with no login and a phone-sized window used it to send a file. The file arrived badged and announced, and the file count stayed correct. There are now 86 tests, 11 of them for guest links. Commit ff0a8ec.
Net effect: people can send Damien videos with a link that expires by itself, and nothing they send reaches Plex until he says so.
← Back to Admin Hub