Footer storage/backend display and a staff role that actually grants staff
Footer: - Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%, red at 95% per DESIGN.md) and a used/total/free tooltip; the watched folder path is no longer printed. /api/status/ returns a compact storage summary instead of the path (the full storage page still shows paths to authenticated users). - Centre shows the backend API origin (empty = same origin). Staff get a link to /setup to point the browser elsewhere; everyone else sees it as plain text. The Account 'Backend connection' card is gone — this is installation plumbing, not a per-user setting. - Design spec updated to match. Staff role: - The custom role did nothing on several endpoints that only accepted Django's is_staff/is_superuser. One canonical check now exists: User.is_app_staff (superuser, Django staff, or the staff role), used by the stats/users APIs, item object permissions, can_delete, upload/ similarity/download/match querysets, and the management commands (which also pick staff-role accounts for e621 sync/match and file ownership). Verified with a role-only staff account (is_staff/is_superuser false): stats/users 200, all 32 downloads + 2 scans visible, others' items editable; the same account as role=user gets 403 for all of those.
This commit is contained in:
@@ -0,0 +1,13 @@
|
||||
from rest_framework import permissions
|
||||
|
||||
|
||||
class IsAppStaff(permissions.BasePermission):
|
||||
"""Superusers, Django staff, and accounts with the app's staff role."""
|
||||
|
||||
message = "Staff only."
|
||||
|
||||
def has_permission(self, request, view):
|
||||
user = request.user
|
||||
return bool(
|
||||
user and user.is_authenticated and user.is_app_staff
|
||||
)
|
||||
@@ -31,13 +31,21 @@ class StatusView(APIView):
|
||||
|
||||
def get(self, request):
|
||||
started = getattr(request, "start_time", time.perf_counter())
|
||||
from apps.library.tools import storage_info
|
||||
|
||||
watched = storage_info()["watched_folder"]
|
||||
payload = {
|
||||
"app": "J621",
|
||||
"env": settings.APP_ENV,
|
||||
"git_hash": settings.GIT_COMMIT_HASH,
|
||||
"version": settings.APP_VERSION,
|
||||
"os": get_os_info(),
|
||||
"watched_folder": settings.WATCHED_FOLDER,
|
||||
"storage": {
|
||||
"used": watched["used"],
|
||||
"total": watched["total"],
|
||||
"free": watched["free"],
|
||||
"percent_used": watched["percent_used"],
|
||||
},
|
||||
"e621_time_ms": None, # e621 latency is measured client-side
|
||||
"workers": _worker_counts(),
|
||||
}
|
||||
@@ -51,10 +59,7 @@ class StatsView(APIView):
|
||||
permission_classes = [IsAuthenticated]
|
||||
|
||||
def get(self, request):
|
||||
user = request.user
|
||||
if not (
|
||||
user.is_staff or user.is_superuser or user.role == user.ROLE_STAFF
|
||||
):
|
||||
if not request.user.is_app_staff:
|
||||
raise PermissionDenied("Staff only.")
|
||||
from apps.library.tools import storage_info
|
||||
|
||||
|
||||
Reference in New Issue
Block a user