Footer storage/backend display and a staff role that actually grants staff

Footer:
- Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%,
  red at 95% per DESIGN.md) and a used/total/free tooltip; the watched
  folder path is no longer printed. /api/status/ returns a compact storage
  summary instead of the path (the full storage page still shows paths to
  authenticated users).
- Centre shows the backend API origin (empty = same origin). Staff get a
  link to /setup to point the browser elsewhere; everyone else sees it as
  plain text. The Account 'Backend connection' card is gone — this is
  installation plumbing, not a per-user setting.
- Design spec updated to match.

Staff role:
- The custom role did nothing on several endpoints that only accepted
  Django's is_staff/is_superuser. One canonical check now exists:
  User.is_app_staff (superuser, Django staff, or the staff role), used by
  the stats/users APIs, item object permissions, can_delete, upload/
  similarity/download/match querysets, and the management commands
  (which also pick staff-role accounts for e621 sync/match and file
  ownership).

Verified with a role-only staff account (is_staff/is_superuser false):
stats/users 200, all 32 downloads + 2 scans visible, others' items
editable; the same account as role=user gets 403 for all of those.
This commit is contained in:
2026-09-17 23:24:24 -05:00
parent a93500154c
commit 99f617d296
17 changed files with 123 additions and 78 deletions
+7
View File
@@ -35,3 +35,10 @@ class User(AbstractUser):
@property
def can_upload(self):
return self.is_superuser or self.role in {self.ROLE_UPLOADER, self.ROLE_STAFF}
@property
def is_app_staff(self):
"""Staff in this app: superusers, Django staff, or the staff role."""
return bool(
self.is_superuser or self.is_staff or self.role == self.ROLE_STAFF
)
+3 -18
View File
@@ -1,10 +1,11 @@
from rest_framework import mixins, permissions, status, viewsets
from rest_framework import mixins, status, viewsets
from rest_framework.authtoken.models import Token
from rest_framework.permissions import AllowAny, IsAuthenticated
from rest_framework.response import Response
from rest_framework.views import APIView
from django.db.models import Count, Q
from apps.core.permissions import IsAppStaff
from apps.library.models import MediaItem
from .models import User
@@ -83,22 +84,6 @@ class E621CredentialsView(APIView):
return Response(self._payload(user))
class IsStaffUser(permissions.BasePermission):
message = "Staff only."
def has_permission(self, request, view):
user = request.user
return bool(
user
and user.is_authenticated
and (
user.is_superuser
or user.is_staff
or user.role == user.ROLE_STAFF
)
)
def resolve_avatar_item(value):
"""Turn a "J-42" / "42" string into a MediaItem.
@@ -163,7 +148,7 @@ class UserViewSet(
):
"""Staff user directory: roles and J-ID avatars."""
permission_classes = [IsStaffUser]
permission_classes = [IsAppStaff]
http_method_names = ["get", "patch", "head", "options"]
def get_queryset(self):
+13
View File
@@ -0,0 +1,13 @@
from rest_framework import permissions
class IsAppStaff(permissions.BasePermission):
"""Superusers, Django staff, and accounts with the app's staff role."""
message = "Staff only."
def has_permission(self, request, view):
user = request.user
return bool(
user and user.is_authenticated and user.is_app_staff
)
+10 -5
View File
@@ -31,13 +31,21 @@ class StatusView(APIView):
def get(self, request):
started = getattr(request, "start_time", time.perf_counter())
from apps.library.tools import storage_info
watched = storage_info()["watched_folder"]
payload = {
"app": "J621",
"env": settings.APP_ENV,
"git_hash": settings.GIT_COMMIT_HASH,
"version": settings.APP_VERSION,
"os": get_os_info(),
"watched_folder": settings.WATCHED_FOLDER,
"storage": {
"used": watched["used"],
"total": watched["total"],
"free": watched["free"],
"percent_used": watched["percent_used"],
},
"e621_time_ms": None, # e621 latency is measured client-side
"workers": _worker_counts(),
}
@@ -51,10 +59,7 @@ class StatsView(APIView):
permission_classes = [IsAuthenticated]
def get(self, request):
user = request.user
if not (
user.is_staff or user.is_superuser or user.role == user.ROLE_STAFF
):
if not request.user.is_app_staff:
raise PermissionDenied("Staff only.")
from apps.library.tools import storage_info
+4 -1
View File
@@ -9,6 +9,7 @@ user following it.
import logging
from django.contrib.auth import get_user_model
from django.db.models import Q
from django.utils import timezone
from apps.library import e621
@@ -32,7 +33,9 @@ def preferred_fetch_user(username=None):
if username:
return User.objects.filter(username=username).first()
return (
User.objects.filter(is_staff=True)
User.objects.filter(
Q(is_superuser=True) | Q(is_staff=True) | Q(role=User.ROLE_STAFF)
)
.exclude(e621_username="")
.exclude(e621_api_key="")
.order_by("id")
@@ -1,5 +1,6 @@
from django.contrib.auth import get_user_model
from django.core.management.base import BaseCommand, CommandError
from django.db.models import Q
from apps.library import e621, matching
from apps.library.models import MatchTask, MediaItem
@@ -35,7 +36,11 @@ class Command(BaseCommand):
else:
user = (
User.objects.filter(
is_staff=True, e621_api_key__gt="", e621_username__gt=""
Q(is_superuser=True)
| Q(is_staff=True)
| Q(role=User.ROLE_STAFF),
e621_api_key__gt="",
e621_username__gt="",
)
.order_by("id")
.first()
@@ -4,6 +4,7 @@ from pathlib import Path
from django.conf import settings
from django.contrib.auth import get_user_model
from django.core.management.base import BaseCommand
from django.db.models import Q
from apps.library.models import MediaLocation
from apps.library.services import ALLOWED_EXTENSIONS, index_file
@@ -42,11 +43,19 @@ class Command(BaseCommand):
)
return
else:
owner = User.objects.filter(is_superuser=True).order_by("id").first()
owner = (
User.objects.filter(
Q(is_superuser=True)
| Q(is_staff=True)
| Q(role=User.ROLE_STAFF)
)
.order_by("-is_superuser", "id")
.first()
)
if owner is None:
self.stderr.write(
self.style.WARNING(
"No superuser found; scanned files will have no owner. "
"No staff user found; scanned files will have no owner. "
"Use --user <name> to assign one."
)
)
+1 -1
View File
@@ -22,6 +22,6 @@ class IsUploaderOrStaffOrReadOnly(permissions.BasePermission):
user = request.user
if not (user and user.is_authenticated):
return False
if user.is_superuser or user.role == user.ROLE_STAFF:
if user.is_app_staff:
return True
return obj.uploaded_by_id == user.id
+1 -1
View File
@@ -92,7 +92,7 @@ class SimilarityCheckViewSet(
def get_queryset(self):
queryset = SimilarityCheck.objects.all()
user = self.request.user
if not (user.is_staff or user.is_superuser):
if not user.is_app_staff:
queryset = queryset.filter(user=user)
return queryset
+1 -1
View File
@@ -250,7 +250,7 @@ class VisualGroupsView(APIView):
def can_delete(user, item):
if user.is_superuser or user.role == user.ROLE_STAFF:
if user.is_app_staff:
return True
return item.uploaded_by_id == user.id
+2 -4
View File
@@ -155,7 +155,7 @@ class TempUploadViewSet(
def get_queryset(self):
queryset = TempUpload.objects.select_related("library_item")
user = self.request.user
if not (user.is_staff or user.is_superuser):
if not user.is_app_staff:
queryset = queryset.filter(user=user)
return queryset
@@ -227,9 +227,7 @@ class TempUploadViewSet(
temp = TempUpload.objects.filter(pk=pk).first()
is_owner = temp is not None and temp.user_id == user.id
if temp is None or not (
is_owner or user.is_staff or user.is_superuser
):
if temp is None or not (is_owner or user.is_app_staff):
raise Http404
if not temp.file:
raise Http404
+3 -7
View File
@@ -242,11 +242,7 @@ class MediaItemViewSet(
def _can_match(self, request, item):
user = request.user
return bool(
user.is_superuser
or user.role == user.ROLE_STAFF
or item.uploaded_by_id == user.id
)
return bool(user.is_app_staff or item.uploaded_by_id == user.id)
@action(detail=True, methods=["post"], permission_classes=[CanUpload])
def match(self, request, pk=None):
@@ -424,7 +420,7 @@ class DownloadTaskViewSet(
if post_id.isdigit():
queryset = queryset.filter(post_id=int(post_id))
user = self.request.user
if not (user.is_staff or user.is_superuser):
if not user.is_app_staff:
queryset = queryset.filter(user=user)
return queryset
@@ -491,7 +487,7 @@ class MatchTaskViewSet(
reap_stale_match_tasks()
queryset = MatchTask.objects.all()
user = self.request.user
if not (user.is_staff or user.is_superuser):
if not user.is_app_staff:
queryset = queryset.filter(user=user)
return queryset