Attribute annotations and scene saves to users

Server-authoritative attribution: on each scene PUT the server diffs incoming
annotation groups and stamps createdBy/editedBy (+ timestamps) from request.user,
ignoring client-sent stamps so authorship can't be forged. Each save also writes
a Revision (user, time, +N ~N −N summary, snapshot of the annotation layer),
visible in the admin and via /revisions/. Projects gain collaborators so several
users can edit one project and get distinct attribution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Your Name 2026-06-29 00:12:13 -04:00
parent 57ef570539
commit 36054ac329
8 changed files with 187 additions and 7 deletions

View file

@ -11,6 +11,8 @@ class Project(models.Model):
owner = models.ForeignKey(settings.AUTH_USER_MODEL, on_delete=models.CASCADE,
related_name="projects")
collaborators = models.ManyToManyField(settings.AUTH_USER_MODEL, blank=True,
related_name="shared_projects")
name = models.CharField(max_length=200)
otio = models.FileField(upload_to="otio/", blank=True, null=True)
fps = models.FloatField(default=NTSC_24)
@ -23,3 +25,21 @@ class Project(models.Model):
def __str__(self):
return f"{self.name} (#{self.pk})"
class Revision(models.Model):
"""One scene save: who, when, a summary, and a snapshot of the authored
(annotation) layer — the audit trail tying timeline changes to users."""
project = models.ForeignKey(Project, on_delete=models.CASCADE, related_name="revisions")
user = models.ForeignKey(settings.AUTH_USER_MODEL, on_delete=models.SET_NULL,
null=True, related_name="+")
created = models.DateTimeField(auto_now_add=True)
summary = models.CharField(max_length=200, blank=True)
annotations = models.JSONField(default=dict, blank=True)
class Meta:
ordering = ["-created"]
def __str__(self):
return f"{self.project_id} @ {self.created:%Y-%m-%d %H:%M} by {self.user_id}"