- frontend: hash routing (project list / create / editor), per-project init
(load OTIO + scene + clip from the API), create form with otio + clip upload,
annotation saves/deletes pushed as deltas, edit/add buttons gated on auth
- auth: own login form in cljs posting to session login/logout endpoints
(httpOnly cookie — no JWT in JS); /api/me/ drives the UI's signed-in state
- backend: add /api/login/ and /api/logout/ (session auth)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Project gains a clip FileField; POST /api/projects/ creates one from an
uploaded otio + clip (<=100 MB), owned by the requester
- add /api/me/ and project-detail; scene GET is public (view without login),
PUT stays owner/collaborator-only
- serve media in DEBUG (range requests for video seek); CORS for the cljs dev
origin with credentials
- seed_demo now builds the Challengers project from the bundled otio + 480p clip
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Server-authoritative attribution: on each scene PUT the server diffs incoming
annotation groups and stamps createdBy/editedBy (+ timestamps) from request.user,
ignoring client-sent stamps so authorship can't be forged. Each save also writes
a Revision (user, time, +N ~N −N summary, snapshot of the annotation layer),
visible in the admin and via /revisions/. Projects gain collaborators so several
users can edit one project and get distinct attribution.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A Project (owner, OTIO file, fps, scene JSON) persists the timeline. Session
API: list projects, GET/PUT scene, serve OTIO. Admin manages users/projects;
seed_demo creates a project from the bundled one_two_three.otio.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>