Backend: - User.role (user/uploader/staff) with can_upload; uploads and downloads gated to uploader+; owners and staff can edit their items - MediaItem.uploaded_by plus J-<id> identity (serializer, admin, scan_files --user, first superuser as default owner) - API resolves J-<id>, bare numeric ids and MD5s; neighbors and lookup return j_ids - Guest safety: mirror e621's anonymous default blacklist into Redis (parses comments, negations and wildcards), flag hidden_from_guests and filter lists, details and lookups for anonymous users - POST /api/online/downloads/ writes an e621 file into the watched folder and indexes it for the uploader - MariaDB + Redis via docker compose (host ports 3307/6380), PyMySQL driver shim, Redis cache replacing the file cache; SQLite data dumped and loaded into MariaDB Frontend: - Single /detail/:itemId route with an adaptive shell: J-<id> renders the library item, bare numbers render the e621 post - Legacy /view/<md5> and /online/view/<id> redirect to canonical URLs - Cards expose J-IDs; library custom-data editor is read-only for non-owners - Role gating: Upload hidden/blocked for regular users, account shows the role, guest hint on the library
28 lines
930 B
Python
28 lines
930 B
Python
from rest_framework import permissions
|
|
|
|
|
|
class CanUpload(permissions.BasePermission):
|
|
"""Only uploader/staff/admin accounts may add items to the library."""
|
|
|
|
message = "Your account is not allowed to upload."
|
|
|
|
def has_permission(self, request, view):
|
|
user = request.user
|
|
return bool(user and user.is_authenticated and user.can_upload)
|
|
|
|
|
|
class IsUploaderOrStaffOrReadOnly(permissions.BasePermission):
|
|
"""Owners and staff can change an item; everyone can read."""
|
|
|
|
message = "Only the uploader or staff can change this item."
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
if request.method in permissions.SAFE_METHODS:
|
|
return True
|
|
user = request.user
|
|
if not (user and user.is_authenticated):
|
|
return False
|
|
if user.is_superuser or user.role == user.ROLE_STAFF:
|
|
return True
|
|
return obj.uploaded_by_id == user.id
|