Sign inStart creating

Firefly Reels v2.4

Our Stories. Our Endless Worlds. — Creator Studio + Film Studio + Streaming Network + Distribution Hub.

Creators imagine, produce, edit, publish and distribute entire films using multiple AI models. Viewers discover and watch those creations on the same platform. A film here is a living structured object, not a folder of clips — and it ships with its own audience.


Run it

npm install
npm run setup
npm run dev

Then open <http://localhost:3000>.

npm run setup generates the Prisma client, creates the SQLite database, and seeds the Style Library (64 packs + 18 modifiers), the Cinematic Preset & VFX Library (24 + 25), the model registry, a worked demo project, a 32-title Theater catalog, the feature matrix, pricing, feature flags and policy rules.

Demo logins

Development and staging only. Refused at login in production — not merely absent from the seed — so a production database that somehow inherited these rows still cannot be entered through them.

UsernamePasswordRole
TESTTESTCreator with a sample project and credits
ADMINADMINFull admin console (SuperAdmin)

Seeded accounts

Sign in asPasswordRole
SYSOP (admin@cineforge.studio)SYSOP123!? — override with SYSOP_PASSWORD at seed timeSuperAdmin. Full back-office.
director@cineforge.studiocineforgeCreator. Owns The Ashfall Signal — a real script that parses into 4 scenes, 26 shots and 149 graph edges.
viewer@cineforge.studiocineforgeViewer with watch history, so the personalized Theater rows populate.

Nothing is required in .env to run. Every model routes to a local mock adapter that produces real, playable files. Add provider keys and the same pipeline routes to real models — see Integration status.

Verify

214 assertions across three suites:

npm run verify
SuiteAssertionsCovers
verify-pipeline44Router, character engine, prompt composition, storyboard gate, generation, credits, cascades, continuity, timeline, budget, moderation
verify-v24109New models, Cleared Content, accounts, 2FA, admin console, creator tools, presets, ideation, marketing, localization, feature matrix
verify-security61Adversarial: privilege escalation, session invalidation, consent gates, rate limits, credit integrity, ownership scoping, account deletion

The security suite is the one that matters most — every case in it asserts that something is refused. Two real bugs were found and fixed by it during development (see Bugs found by the suites).


What's here

The Media Graph (Part 1)

Every project is a graph, not a gallery. GraphEdge is a real dependency table with provenance on every asset. Say "change John's jacket from black to red" and the graph resolves Character → Wardrobe → Black Jacket → the dependent shots across N scenes, prices the work, asks for confirmation, and regenerates only the affected nodes — preserving motion, camera, lighting and performance.

Model orchestration (Part 2)

Call sites request capabilities; the Router picks the model. /studio/models shows the live decision including why each model was skipped.

The v2.4 lineup adds Luma Ray3.14 (native 16-bit HDR, scene planning), Moonvalley Marey (licensed-data training, 2D→3D camera, trajectory control, motion transfer) and Runway Aleph (conversational editing of existing footage). Sora 2 is deliberately excluded — its API shuts down 24 Sept 2026, and removing a flagship costs one registry row.

Cleared Content (Part 9.2)

Flag a project Cleared and it routes exclusively through licensed-corpus models, with no failover — a cleared render fails rather than silently degrading, because one leak invalidates the certificate. Exports carry a provenance certificate that audits what actually generated each asset and names any exception by name. There is no "mostly cleared".

Style, Preset & VFX libraries

64 styles across 5 shelves with 18 stackable modifiers and two-way incompatibility rules — every style renders the same canonical reference scene so comparison is apples-to-apples. Plus 24 camera-move presets and 25 VFX presets; those needing real spatial control declare it and grey out when no model provides it.

Film Studio (Part 4)

Character Bible with compiled Identity Packages, the Character State Machine, World/Prop/Story Bibles, Brand DNA, Script Creation Studio (Fountain, structure templates, draggable tone map, per-scene cost, Table Read), Shot Engine with a hard storyboard gate, AI-native timeline with edit-decision proposals, Continuity Engine, 11-category Film Audit, version control, branching, Budget Engine, and Ideation Boards whose nodes promote directly into the Bible.

Vibe Directing (Part 4.8)

A conversational Director whose tools are graph operations. Every note becomes a versioned, auditable, reversible mutation, priced before execution. Runs on Claude with ANTHROPIC_API_KEY; otherwise a deterministic interpreter handles the defined grammar and asks rather than guesses — a wrong cascade costs real money.

The Theater (Part 5)

Netflix-style catalog with admin-curated editorial rows, personalized rows, genres, natural-language search, title pages with AI cast cards, player with an audio-language picker, playlists, My List, Kids profiles with a PIN gate, creator channels, the Film Festival, and the full Stage 0/1/2 moderation pipeline.

Localization Engine (Part 5.1)

Because we hold the full graph — script, dialogue nodes, cast voice profiles, shot boundaries — a dub is a re-render, not a re-edit. Translate → re-voice with the same cast voice → regenerate phoneme-level lip-sync → subtitles. An upload-only platform has a flat file and structurally cannot do step three.

Admin Console (Part 7.1)

A role-gated back-office at /admin: user management with moderation and audit-logged impersonation, moderation command centre, versioned pricing with effective dates, encrypted provider API-key vault with per-adapter test, model configuration (routing weights, rate limits, price overrides), feature flags with stable percentage rollout, catalog ops with DMCA tracking, finance with watch-time rev-share payouts, platform KPIs and cohorts, and an immutable audit log.

Five roles (SuperAdmin, Moderator, Finance, Support, Editor) with permissions enforced in the service layer, not the UI. Production requires 2FA on every admin account, gated in the layout so no page routes around it.

Accounts (Part 7.2)

Email/password with verification and reset, Google and X OAuth with safe account linking, TOTP two-factor, device/session list with remote sign-out, and settings for profile, security, billing, notifications, preferences and privacy (download-my-data, delete-account).

Publishing Hub (Part 6)

Encrypted OAuth token vault, six platform adapters each declaring its honest API reality, auto-format engine (subject-tracking crop, safe zones, captions, AI-disclosure flags), campaign planner, and exports carrying C2PA credentials — now including 8K and 16-bit HDR delivery tiers.

Marketing (Part 3.5)

Auto trailers (15/30/60/90s) built from the graph with a structural rule that never spends the ending, social cuts per aspect ratio, poster and thumbnail A/B variants, press kit, Pitch Package generator, Presenter Mode, and simulated AI test screening.


Integration status

The part that matters most, stated plainly.

Fully working, no keys needed

  • The entire pipeline: routing → generation → scoring → continuity → timeline → audit → moderation → publish.
  • The mock adapter produces genuinely playable files — deterministic style-accurate animated SVG and synthesized PCM WAV.
  • Credits with rollover and rate limiting, cascades, continuity, Film Audit, EDL/CMX3600/SRT export, moderation, Theater, admin console, accounts, 2FA, ideation, marketing, presets, Cleared Content certificates.

Written but not executed against live endpoints

  • Provider adapters (Seedance, Kling, Runway/Aleph, Veo, Gemini, Luma, Moonvalley, fal). Built from documented API conventions; fields needing confirmation carry VERIFY: comments. They activate only with keys, and failures degrade to the next model.
  • Social platform uploads. Each adapter states its real gating (Meta app review, TikTok audit, YouTube quota, X paid tier, Rumble has no public posting API).
  • OAuth token exchange for Google and X — the flow, PKCE, state handling and account linking are complete; the round-trip needs real client credentials.

Deliberately not faked

  • CSAM hash-matching refuses to return a clean result when unconfigured, and blocks public launch.
  • Visual/audio/copyright classifiers report "did not run", never "passed".
  • Translation is refused without a language model rather than shipping source text under a translated label. A dub that silently plays English under a "Español" badge is worse than no dub.
  • C2PA manifests attach to every asset but are unsigned without a certificate, and the export says so.
  • Stripe card entry renders no card field at all when Stripe is unconfigured. A look-alike input would train people to type card numbers into an unprotected box.
  • Quality scores are a deterministic heuristic, labelled "estimated".
  • Continuity checks reason over the graph, not pixels; anything perceptual is flagged "needs visual review".
  • Test screening is structural analysis, labelled as such — it cannot see the footage.
  • FFmpeg rendering returns a complete EDL plus rendered: false when FFmpeg is absent.

/admin/readiness enforces Part 9 as code: five blocking checks currently fail, so public launch is correctly blocked.


Bugs found by the suites

Worth recording because both were design errors in user-facing flows, not typos.

  1. OAuth sign-in crashed on an unverified duplicate email. A provider returning an unverified address that already existed hit a unique-constraint violation. Fixed: an account only claims a provider email when the provider verified it and nobody holds it — otherwise it gets a provider-scoped synthetic address. This also closes an account-squatting path.
  2. Account deletion hit a foreign-key violation. Consent records, moderation decisions, reports, revenue events and the admin audit log all blocked deletion. Fixed with hard-delete of personal data and retain-anonymized for records with legal or audit significance, plus explicit handling of owned organizations (transfer to a remaining member, or remove if empty). Audit rows now carry a denormalized actor label so they stay attributable after the account is gone.

Earlier rounds also fixed: cascade approval detaching the old render (losing the cut), dedupe returning "reused" alongside an empty shot, and a trackless timeline.


Two engineering decisions

SQLite instead of Postgres+pgvector. So the app runs with one command and no Docker. The schema is Postgres-compatible: JSON lives in String columns behind src/server/lib/json.ts, embeddings behind src/server/lib/vector.ts, enums as string unions in src/lib/enums.ts.

One Next.js app instead of Next.js + FastAPI. Part 8.1 says "modular monolith first" — honoured with hard service boundaries in src/server/services/.

Also note: this machine is Windows on ARM64, for which Prisma ships no native query engine. The schema uses the prisma-client generator with engineType = "client", compiling queries in WASM over a better-sqlite3 driver adapter — a better production posture anyway.


Layout

src/
  app/                     Pages, server actions, API routes
    (auth)/                Sign-in, sign-up, password reset
    settings/              Profile, security, billing, preferences, privacy
    studio/                Creator + Film Studio
    theater/               Streaming network
    admin/                 Role-gated back-office
    features/              Public comparison page
  components/              UI by surface (studio / theater / admin / settings)
  lib/
    enums.ts               String-union enums, admin roles (client-safe)
    styles/catalog.ts      64 style packs + 18 modifiers
    presets/catalog.ts     24 camera + 25 VFX presets
    features/matrix.ts     Feature comparison seed data
  server/
    db.ts                  Prisma via driver adapter + WASM compiler
    models/registry.ts     Model lineup, capabilities, licensing posture
    router/                THE MODEL ROUTER — nothing upstream names a provider
    media/                 Procedural renderer + object storage
    services/              auth · accounts · oauth · totp · passkeys · admin
                           credits · graph · character · script · screenwriter
                           shots · generation · continuity · director · timeline
                           audio · workflow · tools · marketing · ideation
                           localization · cleared · moderation · community
                           economics · publishing · theater
prisma/schema.prisma       110 models
scripts/verify-*.ts        476 assertions across five suites
scripts/check-styles.ts    Design-system consistency check
scripts/smoke-routes.ts    All 59 routes render
scripts/check-content.ts   58 assertions that pages contain what they claim
docs/                      Permanent architecture docs (Part 11)
docs/DEPLOYMENT.md         How to put this on a server

Deploying

See docs/DEPLOYMENT.md — server sizing, database choice, systemd and nginx, TLS, media storage, every optional integration and what stays switched off without it.

The short version:

npm ci && npx prisma generate && npx prisma db push && npm run db:seed && npm run seed:v24 && npm run build && npm run verify

Three environment variables are load-bearing: NODE_ENV=production, DATABASE_URL (absolute path if SQLite), and APP_URL set to your exact public origin — passkeys are bound to it.


Build order from here

  1. Wire one real provider. Add FAL_API_KEY and run a Wan 2.7 generation — that converts the whole open-weight tier from "written" to "verified" in one step.
  2. Add MOONVALLEY_API_KEY. Cleared Content is the premium SKU and currently has only the mock adapter as a licensed engine.
  3. Stand up the FFmpeg render worker. The EDL is complete; this is the last gap between a finished timeline and a deliverable file.
  4. Configure the blocking safety providers. /admin/readiness lists which five and why.
  5. Turn on the LLM Director and translation. ANTHROPIC_API_KEY upgrades the Director to open-ended notes and unblocks the Localization Engine.