Server-authoritative attribution: on each scene PUT the server diffs incoming annotation groups and stamps createdBy/editedBy (+ timestamps) from request.user, ignoring client-sent stamps so authorship can't be forged. Each save also writes a Revision (user, time, +N ~N −N summary, snapshot of the annotation layer), visible in the admin and via /revisions/. Projects gain collaborators so several users can edit one project and get distinct attribution. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
23 lines
731 B
Python
23 lines
731 B
Python
from django.contrib import admin
|
|
|
|
from .models import Project, Revision
|
|
|
|
|
|
@admin.register(Project)
|
|
class ProjectAdmin(admin.ModelAdmin):
|
|
list_display = ("name", "owner", "fps", "updated")
|
|
list_filter = ("owner",)
|
|
search_fields = ("name",)
|
|
filter_horizontal = ("collaborators",)
|
|
readonly_fields = ("created", "updated")
|
|
|
|
|
|
@admin.register(Revision)
|
|
class RevisionAdmin(admin.ModelAdmin):
|
|
list_display = ("project", "user", "created", "summary")
|
|
list_filter = ("project", "user")
|
|
date_hierarchy = "created"
|
|
readonly_fields = ("project", "user", "created", "summary", "annotations")
|
|
|
|
def has_add_permission(self, request):
|
|
return False # revisions are written by the API, not by hand
|