Video playback on mobile doesn't work on self-hosted instance that enforces TLS 1.3

(#3562) Bug Confirmed media mobile self-hosting

Observed behaviour

When attempting to play a video on our self-hosted instance on the mobile client (and only the mobile client), it instead displays an error message saying "Could not play this video." Our self-hosted instance was behind a reverse proxy that was configured to enforce TLS 1.3, i.e. reject connections using TLS 1.2 and lower. The fullscreen media player used on mobile (at least on Android) can't connect to this, though the rest of the app can. Relaxing the restriction to TLS 1.2 fixed the issue, though we also weren't able to enforce known good algorithms under TLS 1.2. Fluxer uses media-kit for its mobile video player, which uses libmpv v0.37.0 (or possibly older), which statically links libffmpeg, which is what actually downloads the video. To do so, ffmpeg statically links libmbedtls (a TLS library). So the network stack for the video player is actually completely isolated from the rest of the app, and also at least 3 years out of date. There's also an open issue on media-kit's GitHub for this: https://github.com/media-kit/media-kit/issues/1437 While it'd be nice to support modern TLS throughout the whole app, I can see there's multiple dependencies involved here. Therefore, in the short term, it might be nice to at least document this limitation somewhere. Although maybe this issue counts as documentation :)

Reproduction steps

  1. Configure an self-hosted instance behind a reverse proxy with the minimum TLS version set to 1.3
  2. Try to play a video in the mobile client
  3. Enjoy the 1 frame of playback UI followed by "Could not play this video."

Platform

Android, Self-hosting

screen-20260814-221437-1786742073479.mp4 | 2.3 MB
  1. Elias changed the status from Awaiting confirmation to Confirmed

3 comments

Sign in with Fluxer to comment and vote.
Comment by Elias
EliasStaff 1 vote
Status changed from Needs triage to Confirmed
I think we will have to fork and manage an updated version of media-kit due to the package not getting updates until the package manager comes back. Since there is some others issues caused by it being out of date.
Comment by Tarek
TarekMod 1 vote
Status changed from Confirmed to Awaiting confirmation
Confirmed issue is present, tested it on my own instance by only allowing TLS1.3
Comment by Floogle
Floogle OP1 vote
As a side note, we also noticed that VP8-encoded webm files couldn't play on some phones even with the TLS fix (couldn't play on Xperia 1 V, could play on Pixel 8), but the fix is probably the same.