i believe the maintainers stance is that jellyfin should not be exposed and it should always be behind a vpn
not necessarily always a VPN, but you can also use a reverse proxy like caddy or nginx where encryption and security are primary concerns instead of something non-essential like in jellyfin.
Their stance is actually that exposing it is fine
Frankly at this point, everything that is not explicitly fully public should be...
Unfortunately, yeah.
I doubt that, how would that work? You would need to give all your friends a VPN login into your local network for all of their devices, including TVs.