Footer: - Left is now 'Backend Storage:' with a capacity bar (blue, peach at 80%, red at 95% per DESIGN.md) and a used/total/free tooltip; the watched folder path is no longer printed. /api/status/ returns a compact storage summary instead of the path (the full storage page still shows paths to authenticated users). - Centre shows the backend API origin (empty = same origin). Staff get a link to /setup to point the browser elsewhere; everyone else sees it as plain text. The Account 'Backend connection' card is gone — this is installation plumbing, not a per-user setting. - Design spec updated to match. Staff role: - The custom role did nothing on several endpoints that only accepted Django's is_staff/is_superuser. One canonical check now exists: User.is_app_staff (superuser, Django staff, or the staff role), used by the stats/users APIs, item object permissions, can_delete, upload/ similarity/download/match querysets, and the management commands (which also pick staff-role accounts for e621 sync/match and file ownership). Verified with a role-only staff account (is_staff/is_superuser false): stats/users 200, all 32 downloads + 2 scans visible, others' items editable; the same account as role=user gets 403 for all of those.
28 lines
898 B
Python
28 lines
898 B
Python
from rest_framework import permissions
|
|
|
|
|
|
class CanUpload(permissions.BasePermission):
|
|
"""Only uploader/staff/admin accounts may add items to the library."""
|
|
|
|
message = "Your account is not allowed to upload."
|
|
|
|
def has_permission(self, request, view):
|
|
user = request.user
|
|
return bool(user and user.is_authenticated and user.can_upload)
|
|
|
|
|
|
class IsUploaderOrStaffOrReadOnly(permissions.BasePermission):
|
|
"""Owners and staff can change an item; everyone can read."""
|
|
|
|
message = "Only the uploader or staff can change this item."
|
|
|
|
def has_object_permission(self, request, view, obj):
|
|
if request.method in permissions.SAFE_METHODS:
|
|
return True
|
|
user = request.user
|
|
if not (user and user.is_authenticated):
|
|
return False
|
|
if user.is_app_staff:
|
|
return True
|
|
return obj.uploaded_by_id == user.id
|