Deploy:
- Multi-stage Dockerfile (shadow-cljs release → Python+ffmpeg runtime), fly.toml
(one machine, scale-to-zero, SQLite on a volume), .dockerignore, DEPLOY.md
- Same-origin release build: api-port defaults "9001" for dev, "" in release
(no CORS in prod)
- env-driven settings (SECRET_KEY/DEBUG/ALLOWED_HOSTS/DB_PATH/CSRF), WhiteNoise
serving static + the SPA, R2 (S3-compatible) media storage when R2_* is set
- thumbnails reworked storage-agnostic: download clip, ffmpeg select-pass, upload
tiles via default_storage (R2 in prod, disk in dev)
- pin channels/daphne; add whitenoise/django-storages/boto3
UI:
- frame step buttons flanking play (disabled at timeline bounds)
- Add-annotation button moved into the toolbar, made prominent
- picker mode pulses a 1-bit glow on clips / frame readout / (while linking)
annotation bars; linking an annotation bar inserts a timeline link
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Script pane: PDF tab beside annotations; "Add script annotation" arms
highlight mode on the draft, ✓/✕ to confirm/cancel, auto-scrolls to the
active annotation's highlights during playback. Adds Project.script.
- Realtime: Django Channels websocket per project broadcasts attributed
scene deltas after each save; peers merge them in (keeping local drafts).
- Logout link in the editor project-bar.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- frontend: hash routing (project list / create / editor), per-project init
(load OTIO + scene + clip from the API), create form with otio + clip upload,
annotation saves/deletes pushed as deltas, edit/add buttons gated on auth
- auth: own login form in cljs posting to session login/logout endpoints
(httpOnly cookie — no JWT in JS); /api/me/ drives the UI's signed-in state
- backend: add /api/login/ and /api/logout/ (session auth)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Project gains a clip FileField; POST /api/projects/ creates one from an
uploaded otio + clip (<=100 MB), owned by the requester
- add /api/me/ and project-detail; scene GET is public (view without login),
PUT stays owner/collaborator-only
- serve media in DEBUG (range requests for video seek); CORS for the cljs dev
origin with credentials
- seed_demo now builds the Challengers project from the bundled otio + 480p clip
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
PUT now takes {changed, deleted} and merges per annotation id, so concurrent
edits to different annotations both survive; same-annotation edits are
last-write-wins by arrival. No version/locking. No-op saves don't write a
revision. Tests cover merge, LWW, stale-client safety, attribution
(server-stamped/spoof-resistant, creator preserved), revisions, and access.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Server-authoritative attribution: on each scene PUT the server diffs incoming
annotation groups and stamps createdBy/editedBy (+ timestamps) from request.user,
ignoring client-sent stamps so authorship can't be forged. Each save also writes
a Revision (user, time, +N ~N −N summary, snapshot of the annotation layer),
visible in the admin and via /revisions/. Projects gain collaborators so several
users can edit one project and get distinct attribution.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A Project (owner, OTIO file, fps, scene JSON) persists the timeline. Session
API: list projects, GET/PUT scene, serve OTIO. Admin manages users/projects;
seed_demo creates a project from the bundled one_two_three.otio.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>