Footer: - Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%, red at 95% per DESIGN.md) and a used/total/free tooltip; the watched folder path is no longer printed. /api/status/ returns a compact storage summary instead of the path (the full storage page still shows paths to authenticated users). - Centre shows the backend API origin (empty = same origin). Staff get a link to /setup to point the browser elsewhere; everyone else sees it as plain text. The Account 'Backend connection' card is gone — this is installation plumbing, not a per-user setting. - Design spec updated to match. Staff role: - The custom role did nothing on several endpoints that only accepted Django's is_staff/is_superuser. One canonical check now exists: User.is_app_staff (superuser, Django staff, or the staff role), used by the stats/users APIs, item object permissions, can_delete, upload/ similarity/download/match querysets, and the management commands (which also pick staff-role accounts for e621 sync/match and file ownership). Verified with a role-only staff account (is_staff/is_superuser false): stats/users 200, all 32 downloads + 2 scans visible, others' items editable; the same account as role=user gets 403 for all of those.
45 lines
1.4 KiB
Python
45 lines
1.4 KiB
Python
from django.contrib.auth.models import AbstractUser
|
|
from django.db import models
|
|
|
|
|
|
class User(AbstractUser):
|
|
"""Project user with optional e621 API credentials and an app role."""
|
|
|
|
ROLE_USER = "user"
|
|
ROLE_UPLOADER = "uploader"
|
|
ROLE_STAFF = "staff"
|
|
ROLE_CHOICES = [
|
|
(ROLE_USER, "User"),
|
|
(ROLE_UPLOADER, "Uploader"),
|
|
(ROLE_STAFF, "Staff"),
|
|
]
|
|
|
|
role = models.CharField(max_length=20, choices=ROLE_CHOICES, default=ROLE_USER)
|
|
avatar = models.ForeignKey(
|
|
"library.MediaItem",
|
|
null=True,
|
|
blank=True,
|
|
on_delete=models.SET_NULL,
|
|
related_name="+",
|
|
)
|
|
e621_username = models.CharField(max_length=100, blank=True, default="")
|
|
e621_api_key = models.CharField(max_length=100, blank=True, default="")
|
|
e621_base_url = models.CharField(max_length=200, default="https://e621.net")
|
|
# Per-user browse preferences (landing page, default filters, grid size).
|
|
preferences = models.JSONField(default=dict, blank=True)
|
|
|
|
@property
|
|
def e621_configured(self):
|
|
return bool(self.e621_username and self.e621_api_key)
|
|
|
|
@property
|
|
def can_upload(self):
|
|
return self.is_superuser or self.role in {self.ROLE_UPLOADER, self.ROLE_STAFF}
|
|
|
|
@property
|
|
def is_app_staff(self):
|
|
"""Staff in this app: superusers, Django staff, or the staff role."""
|
|
return bool(
|
|
self.is_superuser or self.is_staff or self.role == self.ROLE_STAFF
|
|
)
|