Footer storage/backend display and a staff role that actually grants staff
Footer: - Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%, red at 95% per DESIGN.md) and a used/total/free tooltip; the watched folder path is no longer printed. /api/status/ returns a compact storage summary instead of the path (the full storage page still shows paths to authenticated users). - Centre shows the backend API origin (empty = same origin). Staff get a link to /setup to point the browser elsewhere; everyone else sees it as plain text. The Account 'Backend connection' card is gone — this is installation plumbing, not a per-user setting. - Design spec updated to match. Staff role: - The custom role did nothing on several endpoints that only accepted Django's is_staff/is_superuser. One canonical check now exists: User.is_app_staff (superuser, Django staff, or the staff role), used by the stats/users APIs, item object permissions, can_delete, upload/ similarity/download/match querysets, and the management commands (which also pick staff-role accounts for e621 sync/match and file ownership). Verified with a role-only staff account (is_staff/is_superuser false): stats/users 200, all 32 downloads + 2 scans visible, others' items editable; the same account as role=user gets 403 for all of those.
This commit is contained in:
@@ -14,7 +14,6 @@ import { useE621 } from "@/store/e621";
|
||||
import { toast } from "@/store/toasts";
|
||||
|
||||
import { AvatarCard } from "./AvatarCard";
|
||||
import { BackendCard } from "./BackendCard";
|
||||
import { PreferencesCard } from "./PreferencesCard";
|
||||
|
||||
const BASE_URL_OPTIONS = [
|
||||
@@ -216,7 +215,6 @@ export default function AccountPage() {
|
||||
<>
|
||||
<AvatarCard />
|
||||
<PreferencesCard />
|
||||
<BackendCard />
|
||||
</>
|
||||
) : null}
|
||||
{loading && !credentials ? (
|
||||
|
||||
@@ -1,27 +0,0 @@
|
||||
import { Link } from "react-router-dom";
|
||||
|
||||
import { linkButtonClass } from "@/components/ui";
|
||||
import { getBackendUrl } from "@/lib/backend";
|
||||
|
||||
export function BackendCard() {
|
||||
const backend = getBackendUrl();
|
||||
|
||||
return (
|
||||
<section className="rounded-lg border border-ctp-surface0 bg-ctp-base p-5">
|
||||
<h2 className="text-sm font-semibold text-ctp-subtext1">
|
||||
Backend connection
|
||||
</h2>
|
||||
<p className="mt-1 text-xs text-ctp-overlay0">
|
||||
Where this app sends its API requests. Changing it signs you out.
|
||||
</p>
|
||||
<p className="mt-3 break-all font-mono text-xs text-ctp-subtext0">
|
||||
{backend || `${window.location.origin} (same origin)`}
|
||||
</p>
|
||||
<div className="mt-3">
|
||||
<Link to="/setup" className={linkButtonClass}>
|
||||
Change backend
|
||||
</Link>
|
||||
</div>
|
||||
</section>
|
||||
);
|
||||
}
|
||||
Reference in New Issue
Block a user