Files
vfxreview/lib/render-pipeline/session-auth.ts
T
twotalesanimation cc89415a29 feat(pipeline): render queue, worker service and automated preview generation
One "Queue Export" click now renders the EXR sequence, then rebuilds the shot
headlessly with the studio slate/overlay template to produce the delivery MOV
and review MP4. Implements RenderPipeline2 phases 1-2 plus the preview stage.

Server:
- New models Export, RenderJob, ExportEvent, Machine, WorkerHeartbeat, plus
  Project.deliveryConfig and per-submission slate fields (Export.vfxScope,
  Export.submissionNote, inherited from the shot's previous export).
  Both migrations are purely additive; no existing column is touched.
- lib/render-pipeline: server-enforced state machine, transactional version
  increment with supersede, atomic FOR UPDATE SKIP LOCKED claim gated by
  machine availability windows, and a lease reaper run from instrumentation.ts.
- /api/ext/* endpoints for the panel and workers; session-auth mirrors under
  /api/render and /api/machines for the web UI.
- Pipeline pages: render queue, export detail, machine monitoring, plus an
  Exports tab on shot detail.

RenderWorker (.NET 8 Windows service, new):
- Registration, heartbeat as cancel channel, claim loop, aerender runner with
  progress parsing and stall watchdog, crash recovery and disk-spooled
  reporting that survives server downtime.
- Preview stage: headless AE assembles the preview comp into a throwaway AEP
  with both output modules queued, then a single aerender pass renders them.
  Preview jobs are not claimed while an interactive AE session is open, so an
  artist's project is never taken over.

AE panel: Queue Export with live status polling, urgent flag, retry, and the
VFX Scope / Submission Note fields. Every existing panel action is unchanged.

Preview chaining ships disabled behind SystemConfig preview.enabled.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 15:46:53 +02:00

23 lines
961 B
TypeScript

import { auth } from "@/auth";
import { PipelineError } from "./errors";
export type SessionUser = { id: string; role: string; name?: string | null; email?: string | null };
/** Any signed-in studio user (clients never see pipeline pages). */
export async function requirePipelineUser(): Promise<SessionUser> {
const session = await auth();
const user = session?.user as (SessionUser & { role?: string }) | undefined;
if (!user?.id) throw new PipelineError(401, "Unauthorized");
if (user.role === "CLIENT") throw new PipelineError(403, "Forbidden");
return user as SessionUser;
}
/** Admin-level pipeline actions (machine kill-switch, manual mark-done). */
export async function requirePipelineAdmin(): Promise<SessionUser> {
const user = await requirePipelineUser();
if (!["ADMIN", "PRODUCER", "SUPERVISOR"].includes(user.role)) {
throw new PipelineError(403, "Forbidden — requires admin/producer/supervisor role");
}
return user;
}