Footer storage/backend display and a staff role that actually grants staff
Footer: - Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%, red at 95% per DESIGN.md) and a used/total/free tooltip; the watched folder path is no longer printed. /api/status/ returns a compact storage summary instead of the path (the full storage page still shows paths to authenticated users). - Centre shows the backend API origin (empty = same origin). Staff get a link to /setup to point the browser elsewhere; everyone else sees it as plain text. The Account 'Backend connection' card is gone — this is installation plumbing, not a per-user setting. - Design spec updated to match. Staff role: - The custom role did nothing on several endpoints that only accepted Django's is_staff/is_superuser. One canonical check now exists: User.is_app_staff (superuser, Django staff, or the staff role), used by the stats/users APIs, item object permissions, can_delete, upload/ similarity/download/match querysets, and the management commands (which also pick staff-role accounts for e621 sync/match and file ownership). Verified with a role-only staff account (is_staff/is_superuser false): stats/users 200, all 32 downloads + 2 scans visible, others' items editable; the same account as role=user gets 403 for all of those.
This commit is contained in:
@@ -9,6 +9,7 @@ user following it.
|
||||
import logging
|
||||
|
||||
from django.contrib.auth import get_user_model
|
||||
from django.db.models import Q
|
||||
from django.utils import timezone
|
||||
|
||||
from apps.library import e621
|
||||
@@ -32,7 +33,9 @@ def preferred_fetch_user(username=None):
|
||||
if username:
|
||||
return User.objects.filter(username=username).first()
|
||||
return (
|
||||
User.objects.filter(is_staff=True)
|
||||
User.objects.filter(
|
||||
Q(is_superuser=True) | Q(is_staff=True) | Q(role=User.ROLE_STAFF)
|
||||
)
|
||||
.exclude(e621_username="")
|
||||
.exclude(e621_api_key="")
|
||||
.order_by("id")
|
||||
|
||||
Reference in New Issue
Block a user