Adds a Schedule tab (Kitsu-style production schedule) under each
project: tasks grouped by type with drag-to-reschedule bars, Day/Week/
Month zoom, manual date-range control, weekend shading, a frozen task
column, and a two-tier month/date axis header. Requires a new
start_date field on Task (start_date was previously missing; only
deadline existed) and shadcn DatePicker inputs replace native date
inputs on the Schedule toolbar and TaskDetailPanel's Start Date/
Deadline fields.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Users can now hold multiple roles, each with its own editable set of
create/edit/delete-style permissions across assets, shots, tasks, task
assignment, review approve/retake, submissions, uploads, and notes
(including internal vs. client note visibility). The 4 existing roles
(coordinator/director/artist/developer) are migrated into the new system
as system roles, seeded to reproduce today's actual behavior exactly;
admins can create custom roles (e.g. "Reviewer", "Outsourcing") via the
new Role Management page and assign multiple roles to a user via a new
"Manage Roles" action on the Team page.
Backend:
- New Role/Permission models and role_permissions/user_roles tables,
plus a one-off, idempotent seed/backfill migration script.
- New require_permission()/user_has_permission() dependency, wired into
the actual mutation endpoints across shots/assets/tasks/reviews,
always preserving existing ownership- and self-service-based access
(e.g. artists editing their own task status, own notes, own uploads,
own submissions) as an unconditional fallback alongside the new
permission checks - nothing that worked before now requires a role.
- New endpoints: PUT/DELETE on task submissions (wires up soft-deletion
columns that existed on the model but were never exposed), plus full
role CRUD and per-user role assignment.
- Along the way: fixed newly-created users not being linked to their
matching system role (silently leaving them with zero permissions),
and unified an inconsistency between the single vs. bulk task status
endpoints that allowed different roles to bulk-update status.
Frontend:
- Role Management page with a grouped, human-readable permission editor
(icons, plain-language action labels, per-resource select-all, live
selected count) replacing an earlier dense matrix prototype.
- hasPermission() added to the existing usePermission() composable
without touching its current isAdmin/isCoordinatorOrAdmin consumers.
- Note composer gets an Internal/Client toggle; submissions gain inline
edit/delete actions gated the same ownership-or-permission way as notes.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Task status badges (bulk change-status popover, right-click menu) now
use the real per-project TaskStatusesStore colors/labels instead of the
hardcoded TaskStatus enum, matching EditableTaskStatus everywhere.
- Suppress the native browser context menu from leaking through gaps in
the task table (header/empty space), open popovers/dropdowns and their
submenus, the status Select, and a second right-click at the same
coordinates (the popover's positioning anchor now has
pointer-events: none so it doesn't intercept the repeat click).
- Fix 404s on /api/settings/* caused by a double-declared route prefix.
- Fix 422 on bulk-applying a custom task status by relaxing
BulkStatusUpdate.status from the TaskStatus enum to str, matching the
existing single-task update schema.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>