mirror of
https://github.com/advplyr/audiobookshelf.git
synced 2026-05-30 23:40:40 +02:00
[Enhancement]: Password-less authentication using link sent to email address #2308
Closed
opened 2026-04-25 00:05:58 +02:00 by adam
·
2 comments
No Branch/Tag Specified
master
book_tags_genres_dedupe
episode_download_fallback
Issue-4540-SortBy-StartedDate-and-FinishedDate
episode_meta_tagging
fix_authorize_race_condition
redirect_transcode_requests
progress_updated_sort
fix_ereader_socket_event
fix_change_empty_root_password
fix_podcast_session_track_index
fix_set_token
session_modal_user
localize_durations
fix_oidc_create_user
jwt_auth_refactor
fix_scanner_deleting_single_file_books
fix_mediaprogress_updatedat_2
experimental_next_client
podcast_episode_duration
episode-timestamps-clickable
book_author_secondary_sort_title
podcast_useragents
pathexists_user_access
fix_pathexists_join
book_author_secondary_sort
clean_duplicate_mediaprogress
sanitize_html_description
trix_prevent_attachments
check_path_api_fix
fix_mediaprogress_updatedat
increase_express_json_limit
fix_dockerfile_nunicode
search_episodes
audiobook_tools_update
episode_secondary_sorts
hls_stream_url_update
new_session_track_endpoint
audiobook_tools_enhancements
watcher_rescans_update
player_track_tooltip
fix_exclude_prefixes_crash
socket_item_events
fix_podcast_episode_scanner_promise
new_stats_controller
count_cache_for_userpermissions
parsing-opf-v3
validate_migration_files
fix-quick-match-all-crash
fix-chapter-end-sleep-timer
stringify_sequelize_query
remove-col-ambiguity
fix_next_prev_edit_description
details_trim_whitespace
fix_content_url_basepath
fix_logger_fatal
progress_bar_visibility
batch-edit-populate-map-details
feed_generator_updates
bookmark-modal-updates
migrate-library-item-in-scanner
migrate-new-library-items
migrate-podcasts-new-library-item-2
migrate-podcasts-new-library-item
fix-remove-episode-from-playlist
playback-session-use-new-library-item
refactor-library-item
fix-heatmap-caption
feed-episodes-upsert
share-media-player-media-session-api
remove-old-playlist
remove_old_collection_object
plugin-implementation-demo
feed_migration
refactor-feeds-from-item
fix_remove_authors_no_books
v2.17.3-fk-constraints-migration
migrations-first-upgrade
sqlite_2
feature/nuxt-target-server
waveform
sqlite
playlists
video
v2.35.1
v2.35.0
v2.34.0
v2.33.2
v2.33.1
v2.33.0
v2.32.1
v2.32.0
v2.31.0
v2.30.0
v2.29.0
v2.28.0
v2.27.0
v2.26.3
v2.26.2
v2.26.1
v2.26.0
v2.25.1
v2.25.0
v2.24.0
v2.23.0
v2.22.0
v2.21.0
v2.20.0
v2.19.5
v2.19.4
v2.19.3
v2.19.2
v2.19.1
v2.19.0
v2.18.1
v2.18.0
v2.17.7
v2.17.6
v2.17.5
v2.17.4
v2.17.3
v2.17.2
v2.17.1
v2.17.0
v2.16.2
v2.16.1
v2.16.0
v2.15.1
v2.15.0
v2.14.0
v2.13.4
v2.13.3
v2.13.2
v2.13.1
v2.13.0
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.11.0
v2.10.1
v2.10.0
v2.9.0
v2.8.1
v2.8.0
v2.7.2
v2.7.1
v2.7.0
v2.6.0
v2.5.0
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.23
v2.2.22
v2.2.21
v2.2.20
v2.2.19
v2.2.18
v2.2.17
v2.2.16
v2.2.15
v2.2.14
v2.2.13
v2.2.12
v2.2.11
v2.2.10
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.5
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.24
v2.0.23
v2.0.22
v2.0.21
v2.0.20
v2.0.19
v2.0.18
v2.0.17
v2.0.16
v2.0.15
v2.0.14
v2.0.13
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v1.7.2
v1.7.1
v1.7.0
v1.6.0
v1.5.5
v1.5.0
v1.4.11
v1.4.9
v1.4.7
v1.4.6
v1.4.4
v1.4.2
v1.4.0
v1.4.1
v1.3.4
v1.3.3
v1.3.1
v1.2.8
v1.2.6
v1.2.5
v1.2.4
v1.2.1
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.9
v1.1.8
v1.0.0
0.9.61-beta.0
0.9.61-beta
Labels
Clear labels
authentication
backlog
bug
chapter editor
config-issue
ebooks
encoding/embedding
enhancement
help wanted
listening sessions & progress
planned
possible plugin
progress sync
pull-request
sorting/filtering/searching
unable to reproduce
upload
users & permissions
waiting
Mirrored from GitHub Pull Request
No Label
enhancement
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/audiobookshelf#2308
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @ZLoth on GitHub (Oct 13, 2024).
Type of Enhancement
Web Interface/Frontend
Describe the Feature/Enhancement
I would like to be able to configure my server to offer a password-less authenticaiton. The process would work as follows:
The server administrator still needs a password "just in case", and that username/password can be bypassed by going to https://abs.yoursite.com/login/?autoLaunch=0
Why would this be helpful?
I share my server with one-two other people who can be best described as technically challeged. This includes setting the password using a very weak and well-known password think it is secure. By setting up a email link, this eliminates the password.
Future Implementation (Screenshot)
Initial login:

Once the user enters in their email address (and possibly a CAPTCHA test), they will see the following:
If your email address is found on the server, you will receive a email with a link to click on to log into the server. Please note that this link will expire at 6:24 AM Eastern Time.
The Email will look like:
Subject: Audiobookshelf login request for user@example.com
Text:
A login request has been received for the audiobookshelf server at abs.example.com for the (Web Client/Android Client/iOS Client). If this is you, please click on the link below by 6:24 AM Eastern Time:
https://abs.example.com/login/?token=EJoxARR9Yn9OSnbNo1ZMnMFM0K2g1jLPwcOSXatozEC2W3EnnV
If this isn't you, then delete this email.
Once the link is clicked, the appropriate screen comes up for Web Page or mobile device login...
Web Page:
You are now successfully logged in. Click here to go to audiobookshelf.
Mobile Login:
You are now successfully logged in. Please close this page and return to the audiobookshelf app to complete the login process.
Audiobookshelf Server Version
v2.14.0
Current Implementation (Screenshot)
Currently, only username/password authentication.
@advplyr commented on GitHub (Oct 13, 2024):
I'm pretty sure you can set up a flow like that using OIDC with an auth provider like Authentik.
One of the benefits of us adding in OIDC is it allows users to use an auth provider that can do these things instead of us building out every different use-case. Building out different auth methods and flows could be a full time dev effort so we want to leverage auth providers that are already doing this really well.
@Sapd did the bulk of the OIDC implementation for Abs and may have more thoughts.
When we do start working on the authentication again I'd really like to focus on implementing the JWT auth in a more standard way
@Sapd commented on GitHub (Oct 14, 2024):
Yep what you are describing is usually called magic link login.
You can do it with keycloak with this additional software: https://github.com/p2-inc/keycloak-magic-link
However keycloak is not so easy to configure if you're new in that topic
Otherwise if you have access for setup of the other peoples computer, I would suggest you just use Authentik with Webauthn. They do not need to have any password then, they can just authenticate using their browser (the browser will either ask for a PIN or fingerprint to unlock an automatically generated secure key on the computer).
You just have to login them once and then webauthn.