you may also utilize the ip blacklist/whitelist in dashboard->networking->remote access settings if you know the intended clients ip or the bad actors ip
(i only assume this feature is functional but i use an external firewall instead of jellyfin's setting)