Attribute annotations and scene saves to users
Server-authoritative attribution: on each scene PUT the server diffs incoming annotation groups and stamps createdBy/editedBy (+ timestamps) from request.user, ignoring client-sent stamps so authorship can't be forged. Each save also writes a Revision (user, time, +N ~N −N summary, snapshot of the annotation layer), visible in the admin and via /revisions/. Projects gain collaborators so several users can edit one project and get distinct attribution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
57ef570539
commit
36054ac329
8 changed files with 187 additions and 7 deletions
|
|
@ -1,6 +1,6 @@
|
|||
from django.contrib import admin
|
||||
|
||||
from .models import Project
|
||||
from .models import Project, Revision
|
||||
|
||||
|
||||
@admin.register(Project)
|
||||
|
|
@ -8,4 +8,16 @@ class ProjectAdmin(admin.ModelAdmin):
|
|||
list_display = ("name", "owner", "fps", "updated")
|
||||
list_filter = ("owner",)
|
||||
search_fields = ("name",)
|
||||
filter_horizontal = ("collaborators",)
|
||||
readonly_fields = ("created", "updated")
|
||||
|
||||
|
||||
@admin.register(Revision)
|
||||
class RevisionAdmin(admin.ModelAdmin):
|
||||
list_display = ("project", "user", "created", "summary")
|
||||
list_filter = ("project", "user")
|
||||
date_hierarchy = "created"
|
||||
readonly_fields = ("project", "user", "created", "summary", "annotations")
|
||||
|
||||
def has_add_permission(self, request):
|
||||
return False # revisions are written by the API, not by hand
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue