Attribute annotations and scene saves to users

Server-authoritative attribution: on each scene PUT the server diffs incoming
annotation groups and stamps createdBy/editedBy (+ timestamps) from request.user,
ignoring client-sent stamps so authorship can't be forged. Each save also writes
a Revision (user, time, +N ~N −N summary, snapshot of the annotation layer),
visible in the admin and via /revisions/. Projects gain collaborators so several
users can edit one project and get distinct attribution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Your Name 2026-06-29 00:12:13 -04:00
parent 57ef570539
commit 36054ac329
8 changed files with 187 additions and 7 deletions

View file

@ -31,6 +31,17 @@ the scene JSON there.
| GET | `/api/projects/<id>/scene/` | `{fps, scene}` |
| PUT | `/api/projects/<id>/scene/` | replace `scene` and/or `fps` (JSON body) |
| GET | `/api/projects/<id>/otio/` | serve the uploaded OTIO file |
| GET | `/api/projects/<id>/revisions/` | save history (who / when / summary) |
### Attribution
Annotations are the authored unit, so that's what's attributed — and the server
is the authority (client-sent stamps are ignored, so authorship can't be
forged). On each scene `PUT` the server diffs incoming annotation groups against
the stored ones and stamps `createdBy`/`editedBy` (+ timestamps) from
`request.user`; it also writes a `Revision` (user, time, `+N ~N −N` summary,
snapshot of the annotation layer). A project is editable by its `owner` and any
`collaborators` (managed in the admin), so different users get distinct stamps.
The frontend currently loads `/one_two_three.otio` and persists annotations to
localStorage; pointing it at `/api/projects/<id>/otio/` and the scene endpoints