Footer storage/backend display and a staff role that actually grants staff

Footer:
- Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%,
  red at 95% per DESIGN.md) and a used/total/free tooltip; the watched
  folder path is no longer printed. /api/status/ returns a compact storage
  summary instead of the path (the full storage page still shows paths to
  authenticated users).
- Centre shows the backend API origin (empty = same origin). Staff get a
  link to /setup to point the browser elsewhere; everyone else sees it as
  plain text. The Account 'Backend connection' card is gone — this is
  installation plumbing, not a per-user setting.
- Design spec updated to match.

Staff role:
- The custom role did nothing on several endpoints that only accepted
  Django's is_staff/is_superuser. One canonical check now exists:
  User.is_app_staff (superuser, Django staff, or the staff role), used by
  the stats/users APIs, item object permissions, can_delete, upload/
  similarity/download/match querysets, and the management commands
  (which also pick staff-role accounts for e621 sync/match and file
  ownership).

Verified with a role-only staff account (is_staff/is_superuser false):
stats/users 200, all 32 downloads + 2 scans visible, others' items
editable; the same account as role=user gets 403 for all of those.
This commit is contained in:
2026-09-17 23:24:24 -05:00
parent a93500154c
commit 99f617d296
17 changed files with 123 additions and 78 deletions
+3 -18
View File
@@ -1,10 +1,11 @@
from rest_framework import mixins, permissions, status, viewsets
from rest_framework import mixins, status, viewsets
from rest_framework.authtoken.models import Token
from rest_framework.permissions import AllowAny, IsAuthenticated
from rest_framework.response import Response
from rest_framework.views import APIView
from django.db.models import Count, Q
from apps.core.permissions import IsAppStaff
from apps.library.models import MediaItem
from .models import User
@@ -83,22 +84,6 @@ class E621CredentialsView(APIView):
return Response(self._payload(user))
class IsStaffUser(permissions.BasePermission):
message = "Staff only."
def has_permission(self, request, view):
user = request.user
return bool(
user
and user.is_authenticated
and (
user.is_superuser
or user.is_staff
or user.role == user.ROLE_STAFF
)
)
def resolve_avatar_item(value):
"""Turn a "J-42" / "42" string into a MediaItem.
@@ -163,7 +148,7 @@ class UserViewSet(
):
"""Staff user directory: roles and J-ID avatars."""
permission_classes = [IsStaffUser]
permission_classes = [IsAppStaff]
http_method_names = ["get", "patch", "head", "options"]
def get_queryset(self):