Footer storage/backend display and a staff role that actually grants staff
Footer: - Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%, red at 95% per DESIGN.md) and a used/total/free tooltip; the watched folder path is no longer printed. /api/status/ returns a compact storage summary instead of the path (the full storage page still shows paths to authenticated users). - Centre shows the backend API origin (empty = same origin). Staff get a link to /setup to point the browser elsewhere; everyone else sees it as plain text. The Account 'Backend connection' card is gone — this is installation plumbing, not a per-user setting. - Design spec updated to match. Staff role: - The custom role did nothing on several endpoints that only accepted Django's is_staff/is_superuser. One canonical check now exists: User.is_app_staff (superuser, Django staff, or the staff role), used by the stats/users APIs, item object permissions, can_delete, upload/ similarity/download/match querysets, and the management commands (which also pick staff-role accounts for e621 sync/match and file ownership). Verified with a role-only staff account (is_staff/is_superuser false): stats/users 200, all 32 downloads + 2 scans visible, others' items editable; the same account as role=user gets 403 for all of those.
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
from django.contrib.auth import get_user_model
|
||||
from django.core.management.base import BaseCommand, CommandError
|
||||
from django.db.models import Q
|
||||
|
||||
from apps.library import e621, matching
|
||||
from apps.library.models import MatchTask, MediaItem
|
||||
@@ -35,7 +36,11 @@ class Command(BaseCommand):
|
||||
else:
|
||||
user = (
|
||||
User.objects.filter(
|
||||
is_staff=True, e621_api_key__gt="", e621_username__gt=""
|
||||
Q(is_superuser=True)
|
||||
| Q(is_staff=True)
|
||||
| Q(role=User.ROLE_STAFF),
|
||||
e621_api_key__gt="",
|
||||
e621_username__gt="",
|
||||
)
|
||||
.order_by("id")
|
||||
.first()
|
||||
|
||||
@@ -4,6 +4,7 @@ from pathlib import Path
|
||||
from django.conf import settings
|
||||
from django.contrib.auth import get_user_model
|
||||
from django.core.management.base import BaseCommand
|
||||
from django.db.models import Q
|
||||
|
||||
from apps.library.models import MediaLocation
|
||||
from apps.library.services import ALLOWED_EXTENSIONS, index_file
|
||||
@@ -42,11 +43,19 @@ class Command(BaseCommand):
|
||||
)
|
||||
return
|
||||
else:
|
||||
owner = User.objects.filter(is_superuser=True).order_by("id").first()
|
||||
owner = (
|
||||
User.objects.filter(
|
||||
Q(is_superuser=True)
|
||||
| Q(is_staff=True)
|
||||
| Q(role=User.ROLE_STAFF)
|
||||
)
|
||||
.order_by("-is_superuser", "id")
|
||||
.first()
|
||||
)
|
||||
if owner is None:
|
||||
self.stderr.write(
|
||||
self.style.WARNING(
|
||||
"No superuser found; scanned files will have no owner. "
|
||||
"No staff user found; scanned files will have no owner. "
|
||||
"Use --user <name> to assign one."
|
||||
)
|
||||
)
|
||||
|
||||
@@ -22,6 +22,6 @@ class IsUploaderOrStaffOrReadOnly(permissions.BasePermission):
|
||||
user = request.user
|
||||
if not (user and user.is_authenticated):
|
||||
return False
|
||||
if user.is_superuser or user.role == user.ROLE_STAFF:
|
||||
if user.is_app_staff:
|
||||
return True
|
||||
return obj.uploaded_by_id == user.id
|
||||
|
||||
@@ -92,7 +92,7 @@ class SimilarityCheckViewSet(
|
||||
def get_queryset(self):
|
||||
queryset = SimilarityCheck.objects.all()
|
||||
user = self.request.user
|
||||
if not (user.is_staff or user.is_superuser):
|
||||
if not user.is_app_staff:
|
||||
queryset = queryset.filter(user=user)
|
||||
return queryset
|
||||
|
||||
|
||||
@@ -250,7 +250,7 @@ class VisualGroupsView(APIView):
|
||||
|
||||
|
||||
def can_delete(user, item):
|
||||
if user.is_superuser or user.role == user.ROLE_STAFF:
|
||||
if user.is_app_staff:
|
||||
return True
|
||||
return item.uploaded_by_id == user.id
|
||||
|
||||
|
||||
@@ -155,7 +155,7 @@ class TempUploadViewSet(
|
||||
def get_queryset(self):
|
||||
queryset = TempUpload.objects.select_related("library_item")
|
||||
user = self.request.user
|
||||
if not (user.is_staff or user.is_superuser):
|
||||
if not user.is_app_staff:
|
||||
queryset = queryset.filter(user=user)
|
||||
return queryset
|
||||
|
||||
@@ -227,9 +227,7 @@ class TempUploadViewSet(
|
||||
|
||||
temp = TempUpload.objects.filter(pk=pk).first()
|
||||
is_owner = temp is not None and temp.user_id == user.id
|
||||
if temp is None or not (
|
||||
is_owner or user.is_staff or user.is_superuser
|
||||
):
|
||||
if temp is None or not (is_owner or user.is_app_staff):
|
||||
raise Http404
|
||||
if not temp.file:
|
||||
raise Http404
|
||||
|
||||
@@ -242,11 +242,7 @@ class MediaItemViewSet(
|
||||
|
||||
def _can_match(self, request, item):
|
||||
user = request.user
|
||||
return bool(
|
||||
user.is_superuser
|
||||
or user.role == user.ROLE_STAFF
|
||||
or item.uploaded_by_id == user.id
|
||||
)
|
||||
return bool(user.is_app_staff or item.uploaded_by_id == user.id)
|
||||
|
||||
@action(detail=True, methods=["post"], permission_classes=[CanUpload])
|
||||
def match(self, request, pk=None):
|
||||
@@ -424,7 +420,7 @@ class DownloadTaskViewSet(
|
||||
if post_id.isdigit():
|
||||
queryset = queryset.filter(post_id=int(post_id))
|
||||
user = self.request.user
|
||||
if not (user.is_staff or user.is_superuser):
|
||||
if not user.is_app_staff:
|
||||
queryset = queryset.filter(user=user)
|
||||
return queryset
|
||||
|
||||
@@ -491,7 +487,7 @@ class MatchTaskViewSet(
|
||||
reap_stale_match_tasks()
|
||||
queryset = MatchTask.objects.all()
|
||||
user = self.request.user
|
||||
if not (user.is_staff or user.is_superuser):
|
||||
if not user.is_app_staff:
|
||||
queryset = queryset.filter(user=user)
|
||||
return queryset
|
||||
|
||||
|
||||
Reference in New Issue
Block a user