Huge Bug - A Linked Managed User Given Admin Access!

Server Version#: 1.22.3.4392
Player Version#:? User Had Samsung TV

I have a dell poweredge t620 server running plex server on ubuntu.

My admin account is PIN protected and I have added a hand full of friends and family as managed users. These users are allowed selective access to my various libraries.

I received a link code for a friend when he entered it, it took him right into my admin account! He was using a Samsung TV, I know nothing more of the model. Thankfully he called me right away due to it looking different, since normally people go right to where all the accounts are shown along a long horizontal row. He was able to back out of my account and was taken to the account row were now my admin account showed with a lock as it is supposed to and protected by PIN.

Note: I did post this in General at first…not sure where to post it as I do not see a BUG section.

EDIT: I removed the part about logging people out as it has completely distracted everyone for the entire reason of my post.

Patient: It hurts when I do ___________.
Doctor: Well, don’t do that anymore.

When you authorize a device using a link code, you’re signing that device in on your account. It’s the equivalent of typing your password in on that device.

Managed users are a type of home user. The best practice is to not authorize home users outside your personally-owned, trusted devices. Home PINs provide mild protection when switching between home users, not as primary protection for an account.

https://support.plex.tv/articles/203815766-what-is-plex-home/

Consider sharing with them as “normal” Plex account users, with their own passwords.

https://support.plex.tv/articles/201105738-creating-and-managing-server-shares/

2 Likes

Thank you for the reply.

I guess they should just ignore the bug cause there is another way to do things…sounds legit.

It’s not a bug.

Plex warns you about this when you first set up Plex Home. As suggested, read the information in the links for more info.

I don’t recommend using manually created users with Plex Home, have them each create their own accounts and send a share that way.

:man_shrugging:

I am surprised at these responses.

99% of the time when you add an account this way. It opens on account selection.
It is VERY clear this is the intended design.

There is a very specific reason why I add accounts the way I do.
Let’s just ignore the fact I add people outside my immediate family circle for a moment.
I also have each of my 5 children’s devices linked to my account. I have 3 different libraries dedicated to porn as well. Only my admin profile and my wife has access to these libraries.
I do not want my children to have access to this on their devices…that starting to make sense why we should not ignore this OBVIOUS bug?

It’s not a bug, members of a Plex Home are managed by the Admin account -

So when your friend sent you the code, and you logged into plex.tv/link to input it, the plex app took you to your account on that device

Which is reason #967 why you don’t/shouldn’t do what you are doing with remote users

Something tells me you 3 still don’t understand.

There is a reason Plex allows only sharing specific libraries with managed users and having the ability to PIN protect them.

I think it is great you 3 love plex so much that you come into this post and attempt to “Officer Barbrady” it as I like to say.

It takes posts like this for devs to take note of issues.
It may take a while to fix…may take several others to point it out.
At any rate, I am just here to report issue.

But you can also share specific libraries with normal shared users that aren’t part of your plex home for remote users

What is your point?

My point?

is enabling a device when used in a Plex Home, doesn’t work the way you think it does/should.

Now should it it work that way, who know

And, sorry
I see now you were replying to a post above mine (maybe)

I am a Computer and Network Specialist III for one of the largest agencies in my state. I manage hundreds of devices and servers as well as provide helpdesk for so many programs and web based apps that I have lost count.

I am not here looking for a work around or advice on how to use Plex. I know how to use plex just fine and have done so for years. I have setup at least 3 dozen plex servers of various size and complexity.

If you are not a dev or someone employed by Plex, what I have to say has NOTHING to do with you.

I agree that this is a topic of frequent confusion.

The support pages for Home and Managed users make it very clear what they’re for, and what type of security they provide.

Maybe you can better explain why normal users don’t work for you, or how the interface doesn’t make it clear when to choose one vs. the other?

You are in a community forum, not a private direct line to plex

And just pointing out the obvious again -

From your 1st post -
NOPE. It deactivated all of my managed accounts.

And from the Plex Support Page -

  • For Managed User accounts, the Home admin or another regular account in the Home must sign in first, then switch to that Managed user. From then on, the Managed User will be able to select themselves in the user menu when they open the app.
2 Likes

I realize that. I mentioned the story cause it was funny to me and I felt it added some levity.
It was relevant since I had to relink like 12-13 devices back.

The point EVERYONE seems to be missing is the the whole point of the post.
For the first time ever (for me) it started the link in the admin profile.
I have linked and unlinked accounts hundreds of times and it has only loaded into admin profile 1 time.

How long you want to keep going with this?

Oh now it’s just fun is all
So every managed user, not a regular user you’ve added to a plex home, works as you described?

Even though it’s not suppose to work that way?

1 Like

Home user accounts are not meant for you to sign people in remotely. They are meant for folks you actually live in your home. Managed user accounts (99% of the time used for children) intentionally do not have passwords of their own so they cannot sign into any device they want without your knowledge

Just to be clear you are talking about using this correct In image? That is a bug if it is destroying the managed users from https://app.plex.tv/desktop/#!/settings/users-sharing

Unless you were signed into his account when you entered the link code you are signing him into your account. This is not in any way a bug,

3 Likes

Are you trying to say that everytime I have linked a device in my home and in the home of others on servers I set up for them that after adding the first managed user it has started in the account selection screen and this is not intended?

Would you like me to create a video to show you what I am saying?

I have linked HUNDREDS of managed users and linked. I can demonstrate this if you would like.
It will open on account selection screen every time.

Edit: Bigwheel, have I lost you as well on this? Here let me edit my initial post and remove the little story of getting signed out. That seems to be distracting all of you.