* docs(markers): design + implementation plans for multi-source markers & TheIntroDB contribution * fix(markers): TheIntroDB read-path correctness (TVDB, real confidence, best candidate) Honor TVDB ids in /media lookups (previously dropped — anime/TheTVDB-first libraries got no markers), decode and use the real per-segment confidence and submission_count instead of a hardcoded 0.9, and pick the most-submitted / highest-confidence candidate when several are returned. Adds httptest coverage for the introdb client and provider. Phase 1 of docs/superpowers/plans/2026-06-06-marker-sources-and-contribution-implementation.md Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(markers): multi-source dispatch, per-provider config, per-segment provenance Add marker_provider_config (per-provider fetch enable/priority + contribute gates, contribution off by default) and a cached ProviderConfigStore. Add Registry.FetchMerged: query all fetch-enabled providers concurrently and keep the best candidate per segment (submission_count, then confidence, then fetch priority), stamping each winning marker with its provider/algorithm. Thread per-segment provenance through MarkerUpdatePayload and scanner.MarkerUpdate (additive SegmentProvenance overrides) so a merged result writes correct per-segment provider/confidence/algorithm; the legacy shared columns keep a summary. The lazy-playback path now uses FetchMerged. With only TheIntroDB enabled, behavior is unchanged. Phase 2 of docs/superpowers/plans/2026-06-06-marker-sources-and-contribution-implementation.md Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(markers): TheIntroDB submission client, contribution audit, service engine Add a markers.Submitter capability and implement it on the introdb provider (POST /v3/submit, GET /v3/user/stats; key required, usage-limit aware, applies the null start/end conventions). Add the marker_contributions audit table and a value-hash-keyed ContributionStore for idempotency. Add ContributionService: resolves enabled submitter providers, gates eligibility (never re-submit online-sourced markers; auto runs require contribute_auto_local + scanner-intro above the per-provider confidence threshold), checks idempotency, submits, and records. Wired in main.go; no trigger yet (admin API and task follow). Phase 3 of docs/superpowers/plans/2026-06-06-marker-sources-and-contribution-implementation.md Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(api): admin marker editing, contribution, and provider config endpoints Add the RequireAdmin marker API: GET/PUT /admin/files/{id}/markers (read with provenance; manual upsert where a segment object sets and null clears), DELETE .../markers/{segment}, POST .../contribute and GET .../contributions, plus GET/PUT /admin/markers/providers[/{provider}] and a .../validate key-check returning user stats. Manual writes go through the priority-gated UpsertMarkers (source=manual) and notify live sessions; a new FileRepository.ClearMarkers nulls a segment's columns. Validation mirrors the contribution rules. Phase 4 of docs/superpowers/plans/2026-06-06-marker-sources-and-contribution-implementation.md Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(markers): daily auto-contribution task for local intro markers Add ContributeMarkersTask (daily 04:00, after local detection): when a provider has contribute_enabled + contribute_auto_local, page through episode files with a scanner intro marker at/above the provider's confidence threshold (new ContributionStore.CandidateLocalIntroFiles keyset query) and run them through ContributionService with Auto=true. No-op when no provider opts in; idempotent and resumable across runs. Phase 5 of docs/superpowers/plans/2026-06-06-marker-sources-and-contribution-implementation.md Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(intromarkers): refine chromaprint starts with dialogue cues * feat(markers): finish marker management backend * feat(web): add marker editing UI * feat(markers): use plugin marker providers * fix(markers): address PR review feedback * feat(player): show marker labels on seek hover * fix(markers): type nullable marker mutation params * feat(markers): audit marker edits and add permission --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
102 lines
2.1 KiB
Go
102 lines
2.1 KiB
Go
package auth
|
|
|
|
import (
|
|
"fmt"
|
|
"sort"
|
|
"strings"
|
|
|
|
"github.com/Silo-Server/silo-server/internal/models"
|
|
)
|
|
|
|
type Permission string
|
|
|
|
const (
|
|
PermissionMarkerEdit Permission = "marker_edit"
|
|
PermissionMetadataCuration Permission = "metadata_curation"
|
|
)
|
|
|
|
var assignablePermissions = map[Permission]struct{}{
|
|
PermissionMarkerEdit: {},
|
|
PermissionMetadataCuration: {},
|
|
}
|
|
|
|
func assignablePermissionList() []string {
|
|
out := make([]string, 0, len(assignablePermissions))
|
|
for permission := range assignablePermissions {
|
|
out = append(out, string(permission))
|
|
}
|
|
sort.Strings(out)
|
|
return out
|
|
}
|
|
|
|
func isAssignablePermission(permission Permission) bool {
|
|
_, ok := assignablePermissions[permission]
|
|
return ok
|
|
}
|
|
|
|
func NormalizePermissions(values []string) ([]string, error) {
|
|
if len(values) == 0 {
|
|
return []string{}, nil
|
|
}
|
|
|
|
seen := make(map[string]struct{}, len(values))
|
|
out := make([]string, 0, len(values))
|
|
for _, raw := range values {
|
|
key := strings.TrimSpace(raw)
|
|
if key == "" {
|
|
continue
|
|
}
|
|
permission := Permission(key)
|
|
if !isAssignablePermission(permission) {
|
|
return nil, fmt.Errorf("unknown permission %q", key)
|
|
}
|
|
if _, ok := seen[key]; ok {
|
|
continue
|
|
}
|
|
seen[key] = struct{}{}
|
|
out = append(out, key)
|
|
}
|
|
sort.Strings(out)
|
|
return out, nil
|
|
}
|
|
|
|
func DefaultUserPermissions() []string {
|
|
return []string{string(PermissionMarkerEdit)}
|
|
}
|
|
|
|
func HasAssignedPermission(user *models.User, permission Permission) bool {
|
|
if user == nil {
|
|
return false
|
|
}
|
|
for _, value := range user.Permissions {
|
|
if value == string(permission) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func HasEffectivePermission(user *models.User, permission Permission) bool {
|
|
if user == nil || !user.Enabled {
|
|
return false
|
|
}
|
|
if user.Role == "admin" {
|
|
return isAssignablePermission(permission)
|
|
}
|
|
return HasAssignedPermission(user, permission)
|
|
}
|
|
|
|
func EffectivePermissions(user *models.User) []string {
|
|
if user == nil || !user.Enabled {
|
|
return []string{}
|
|
}
|
|
if user.Role == "admin" {
|
|
return assignablePermissionList()
|
|
}
|
|
permissions, err := NormalizePermissions(user.Permissions)
|
|
if err != nil {
|
|
return []string{}
|
|
}
|
|
return permissions
|
|
}
|