Accounts people can create, and photos on a server with no bucket

A tenant had exactly the users somebody had created with a command on the
server. That is not a missing screen: a shop with an owner and four staff
either shared one password or raised a ticket per person, and a phone app
for the shop floor could not exist while there was one account to sign in
as.

Registration is by invitation, never open signup - the same line already
drawn around creating a company. The code carries the address and the role
and the request carries only a password, so a code that gets forwarded
cannot become somebody else's account, and a staff invitation cannot be
redeemed as an owner. Single use lives in the UPDATE and the account is
created in the same transaction.

Deactivating a member revokes their sessions in that transaction too. An
access token lives twelve hours, so without it "remove their access"
removed it sometime tomorrow. The session list and revoke that go with it
are the benefit of opaque tokens the product had been paying for and never
collecting: nothing could say what was signed in, let alone stop one.

Face images now work on a deployment with no object storage, which was
every local install and every self-hosted site - the arrivals feed said
"not storing customer photos" for every customer forever, on the screen
whose whole job is to show a face. Bounded to one row per visitor, so it
grows with the customer base and not with footfall; the bucket stays
primary wherever one exists.

Image.auth says whether a URL needs the session, because a browser img
cannot load one that does, a mobile image view can, and a webview can do
neither - the desktop client resolves those to a data URI in Go.

Found by running it, not by tests:

  * UPDATE ... RETURNING gives the value AFTER the update, so the prune
    read back empty keys, deleted nothing, and the table grew with
    footfall exactly as if it were not there. The fake agreed with either
    version; only the live Postgres test caught it.
  * Trusting only the auth flag broke every shop card, because Sites.jsx
    rebuilt a partial snapshot object and dropped it. A relative URL is
    now sufficient on its own.
  * ago() renders a future time as "just now", so a code valid for a week
    read "expires just now".

Verified live against real Postgres: invite, preview, escalation refused,
register into a session, replay 404, staff forbidden, device revoked and
401 at once, last owner refused, and a 92,405-byte camera JPEG stored,
served to its owner, 401 with no session, 404 to another tenant, and
rendered in a browser.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
This commit is contained in:
2026-09-05 11:45:42 +05:30
parent ffae7e45d5
commit 3f9fb33b24
38 changed files with 4125 additions and 106 deletions

View File

@@ -42,6 +42,27 @@ type Store interface {
SessionByRefresh(ctx context.Context, hash []byte) (auth.Principal, time.Time, error)
RotateSession(ctx context.Context, sessionID string, s NewSession) error
RevokeSession(ctx context.Context, sessionID string) error
// Which devices are signed in, and signing one of them out. This is what
// an opaque-token session table buys over a JWT, and until these existed
// the product paid the cost of that choice without the benefit.
UserSessions(ctx context.Context, userID string) ([]DeviceSession, error)
RevokeUserSession(ctx context.Context, userID, sessionID string) error
RevokeOtherSessions(ctx context.Context, userID, keepSessionID string) (int, error)
// --- team and invitations ---
// Registration is by invitation: the code carries the address and the role
// so neither can be chosen by whoever redeems it.
CreateInvitation(ctx context.Context, in NewInvitation) (Invitation, error)
PendingInvitations(ctx context.Context, clientID string) ([]Invitation, error)
RevokeInvitation(ctx context.Context, clientID, id string) error
InvitationByCode(ctx context.Context, hash []byte) (InvitationPreview, error)
// RedeemInvitation spends the code and creates the account in ONE
// transaction: a spent invitation with no user behind it is unusable, and a
// user with the invitation still open is a second account waiting for
// whoever else was forwarded the code.
RedeemInvitation(ctx context.Context, hash []byte, fullName, passwordHash string) (UserRecord, error)
Team(ctx context.Context, clientID string) ([]TeamMember, error)
UpdateTeamMember(ctx context.Context, clientID, userID string, up TeamUpdate) (TeamMember, error)
// --- reports ---
Footfall(ctx context.Context, q ReportQuery) ([]FootfallPoint, Totals, error)
@@ -98,6 +119,11 @@ type Store interface {
AgentByToken(ctx context.Context, hash []byte) (AgentPrincipal, error)
// --- images ---
// Face images held by this server, for a deployment with no object
// storage. Where a bucket is configured none of these three is called.
PutVisitFace(ctx context.Context, clientID, siteID string, jpeg []byte) (string, error)
VisitFace(ctx context.Context, clientID, key string) ([]byte, error)
DeleteVisitFaces(ctx context.Context, clientID string, keys []string) error
VisitorImageKey(ctx context.Context, clientID, visitorID string) (string, error)
VisitorImageKeys(ctx context.Context, clientID, visitorID string) ([]string, error)
ForgetVisitor(ctx context.Context, clientID, visitorID string) error
@@ -196,6 +222,26 @@ func (s *Server) Routes() *http.ServeMux {
mux.HandleFunc("POST /api/auth/refresh", s.handleRefresh)
mux.HandleFunc("POST /api/auth/logout", s.authed(s.handleLogout))
mux.HandleFunc("GET /api/auth/me", s.authed(s.handleMe))
// Registration. Unauthenticated for the same reason agent enrolment is:
// whoever is doing this has no account yet, and requiring one first would
// mean shipping a password to everybody who needs one.
mux.HandleFunc("GET /api/auth/invitation", s.handleInvitationPreview)
mux.HandleFunc("POST /api/auth/register", s.handleRegister)
// Devices. A person may list and revoke their own sessions; removing a
// colleague's access is a different question, answered by deactivating them
// on the team endpoint below.
mux.HandleFunc("GET /api/auth/sessions", s.authed(s.handleSessions))
mux.HandleFunc("DELETE /api/auth/sessions/{id}", s.authed(s.handleRevokeSession))
mux.HandleFunc("POST /api/auth/sessions/revoke-others",
s.authed(s.handleRevokeOtherSessions))
// --- the people who work here ---
mux.HandleFunc("GET /api/team", s.authed(s.handleTeam))
mux.HandleFunc("PATCH /api/team/{id}", s.authed(s.handleUpdateTeamMember))
mux.HandleFunc("GET /api/team/invitations", s.authed(s.handleInvitations))
mux.HandleFunc("POST /api/team/invitations", s.authed(s.handleInvite))
mux.HandleFunc("DELETE /api/team/invitations/{id}",
s.authed(s.handleRevokeInvitation))
mux.HandleFunc("GET /api/reports/footfall", s.authed(s.handleFootfall))
mux.HandleFunc("GET /api/reports/conversion", s.authed(s.handleConversion))
@@ -250,6 +296,8 @@ func (s *Server) Routes() *http.ServeMux {
mux.HandleFunc("POST /api/agent/enrol", s.handleEnrol)
// Authenticated by the agent's own API token, not a user session.
mux.HandleFunc("POST /api/agent/upload-url", s.agentAuthed(s.handleUploadURL))
// The fallback the agent takes when upload-url answers images_disabled.
mux.HandleFunc("POST /api/agent/faces", s.agentAuthed(s.handlePutFace))
// What this shop PC should be running, and what it reports back.
mux.HandleFunc("GET /api/agent/cameras", s.agentAuthed(s.handleAgentCameras))
mux.HandleFunc("POST /api/agent/cameras", s.agentAuthed(s.handleAgentCameraReport))
@@ -262,6 +310,11 @@ func (s *Server) Routes() *http.ServeMux {
mux.HandleFunc("POST /api/agent/checks", s.agentAuthed(s.handleAgentCheckResult))
mux.HandleFunc("GET /api/visitors/{id}/image", s.authed(s.handleVisitorImage))
// The bytes of a face this server holds itself. Session-authenticated
// rather than a signed link: there is no third party to delegate to, and an
// unauthenticated URL would be a way to reach a customer's photograph with
// no session at all.
mux.HandleFunc("GET /api/faces/{id}", s.authed(s.handleGetFace))
// The erasure path. Destroys the template and the photo; keeps the
// anonymous visit counts, which are legitimate aggregate data.
mux.HandleFunc("DELETE /api/visitors/{id}", s.authed(s.handleForgetVisitor))