Attribute annotations and scene saves to users

Server-authoritative attribution: on each scene PUT the server diffs incoming
annotation groups and stamps createdBy/editedBy (+ timestamps) from request.user,
ignoring client-sent stamps so authorship can't be forged. Each save also writes
a Revision (user, time, +N ~N −N summary, snapshot of the annotation layer),
visible in the admin and via /revisions/. Projects gain collaborators so several
users can edit one project and get distinct attribution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Your Name 2026-06-29 00:12:13 -04:00
parent 57ef570539
commit 36054ac329
8 changed files with 187 additions and 7 deletions

View file

@ -0,0 +1,30 @@
# Generated by Django 6.0.6 on 2026-06-29 03:47
import django.db.models.deletion
from django.conf import settings
from django.db import migrations, models
class Migration(migrations.Migration):
dependencies = [
('scenes', '0001_initial'),
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
]
operations = [
migrations.CreateModel(
name='Revision',
fields=[
('id', models.BigAutoField(auto_created=True, primary_key=True, serialize=False, verbose_name='ID')),
('created', models.DateTimeField(auto_now_add=True)),
('summary', models.CharField(blank=True, max_length=200)),
('annotations', models.JSONField(blank=True, default=dict)),
('project', models.ForeignKey(on_delete=django.db.models.deletion.CASCADE, related_name='revisions', to='scenes.project')),
('user', models.ForeignKey(null=True, on_delete=django.db.models.deletion.SET_NULL, related_name='+', to=settings.AUTH_USER_MODEL)),
],
options={
'ordering': ['-created'],
},
),
]

View file

@ -0,0 +1,20 @@
# Generated by Django 6.0.6 on 2026-06-29 04:11
from django.conf import settings
from django.db import migrations, models
class Migration(migrations.Migration):
dependencies = [
('scenes', '0002_revision'),
migrations.swappable_dependency(settings.AUTH_USER_MODEL),
]
operations = [
migrations.AddField(
model_name='project',
name='collaborators',
field=models.ManyToManyField(blank=True, related_name='shared_projects', to=settings.AUTH_USER_MODEL),
),
]