i believe the maintainers stance is that jellyfin should not be exposed and it should always be behind a vpn

I doubt that, how would that work? You would need to give all your friends a VPN login into your local network for all of their devices, including TVs.

or your friend can setup VPN on his Router box.

But then all of his traffic goes through my internet. Unless he has a special high end router that can only route specific domains.

You dont need high end box, a old mini pc running pfsense/opnsense is enough.

High end, as in feature rich.

If you think most non tech people can just casually find an old pc, install and setup pfsense, then you are out of touch with reality. And they also would have to let it run all the time and have space for it. That's just not something realistic. It's not an option for my friends. Might also break chromecast.

not necessarily always a VPN, but you can also use a reverse proxy like caddy or nginx where encryption and security are primary concerns instead of something non-essential like in jellyfin.

Their stance is actually that exposing it is fine

Frankly at this point, everything that is not explicitly fully public should be...

Unfortunately, yeah.