Footer storage/backend display and a staff role that actually grants staff

Footer:
- Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%,
  red at 95% per DESIGN.md) and a used/total/free tooltip; the watched
  folder path is no longer printed. /api/status/ returns a compact storage
  summary instead of the path (the full storage page still shows paths to
  authenticated users).
- Centre shows the backend API origin (empty = same origin). Staff get a
  link to /setup to point the browser elsewhere; everyone else sees it as
  plain text. The Account 'Backend connection' card is gone — this is
  installation plumbing, not a per-user setting.
- Design spec updated to match.

Staff role:
- The custom role did nothing on several endpoints that only accepted
  Django's is_staff/is_superuser. One canonical check now exists:
  User.is_app_staff (superuser, Django staff, or the staff role), used by
  the stats/users APIs, item object permissions, can_delete, upload/
  similarity/download/match querysets, and the management commands
  (which also pick staff-role accounts for e621 sync/match and file
  ownership).

Verified with a role-only staff account (is_staff/is_superuser false):
stats/users 200, all 32 downloads + 2 scans visible, others' items
editable; the same account as role=user gets 403 for all of those.
This commit is contained in:
2026-09-17 23:24:24 -05:00
parent a93500154c
commit 99f617d296
17 changed files with 123 additions and 78 deletions
+2 -1
View File
@@ -82,7 +82,8 @@ All tag chips, counters, and sidebar taxonomy badges strictly adhere to e621's e
- Right: System status pill with real backend values, never hardcoded: environment (`DEV`/`PROD`), git commit hash, the actual host OS, page generation time, and the total e621 API request time for that page load — e.g. `ENV: PROD · a1b2c3d · LINUX · 18ms (e621: 4ms)`. Followed by the user avatar.
- **Global Footer Status Strip (`#11111b`, height: 32px):**
- The strip placement is a proposal; its values are real and drawn from the existing stats data.
- Left: the watched folder path — `📁 Local Storage: /mnt/media/library`. This is the only place the path appears (J621 is folder-based; it is just a path on disk, not a NAS/appliance indicator).
- Left: `🖴 Backend Storage: <bar> 61.3%` — disk usage of the watched folder, colour-coded per the DESIGN.md capacity thresholds, with used/total/free in the tooltip. The folder path is no longer printed in the shell.
- Center: the backend API origin (empty means same origin). Staff can click it to open `/setup` and point the browser at another backend.
- Right: `⚡ Active Workers: N running | Queue: M pending` — the count of active optimization/ingest jobs and queued downloads (the original app surfaced this on its stats page; the footer simply keeps it visible).
- The build version (`<env> @ <git commit hash>`) is shown by the header status pill only — never repeated in the footer.
- **Collapsible Sidebar (Behavior):**