The camera tiles put a password in the page, and loaded nothing
StreamURL built http://user:pass@127.0.0.1:8010/api/cameras/<id>/ stream.mjpeg and handed it to an <img>, with a comment saying the credentials were inline "so an <img> tag can load it". It cannot. Chromium strips credentials from subresource URLs and has since M59, and WebView2 is Chromium - so on the one platform this product ships to, every camera tile on a shop counter was a broken image. Measured against a running engine: the app's Go-side calls returned stats and people while an <img> on that very URL failed, and curl proved the URL answered 200. The engine was never the problem. The password now stays on this side of the process boundary. A loopback relay attaches Basic auth and streams the engine's bytes back unchanged - the same reasoning Shot.jsx already follows at head office, where an <img> equally cannot carry a session. What the relay is careful about, since it is a door onto the biometric API with a credential attached: - loopback only, on a port the OS picks; a fixed one would collide with whatever else a shop PC runs and read as "the cameras broke" - a per-run random token in the path. The engine's own credential exists so the live face feed is never served open; an unauthenticated relay would hand that feed to any other process on the PC. Compared in constant time, and a wrong one is 404, not 403 - an allow-list of stream.mjpeg and frame.jpg. Holding the token does not reach the identity list, the gallery, or erasure - camera ids validated, not interpolated - every chunk flushed; a buffered MJPEG stream is a tile that never paints, which looks identical to the bug being fixed Two of those were written after a test failed, not before: - `..` MATCHES the id pattern, because real camera ids contain dots. `/api/cameras/../stream.mjpeg` is not the endpoint anyone intended. The id can never hold a slash, so `.` and `..` are the whole remaining traversal surface and are now refused by name. - the serve goroutine read p.srv off the struct while stop() was nilling it, so a quick start/stop dereferenced nil and took the process down. Captured before launching now. FrameURL is deliberately not added. No screen asks for a still, and a bound method nothing calls is the same defect as a capability the UI cannot reach, only pointing the other way. Verified: nine unit tests, plus a live test against the real engine and the real office camera - two MJPEG frames, 90,793 bytes, no credential in the URL. Windows and darwin both build; vet clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pcn9asw19WGBfCEaHvNug6
This commit is contained in:
@@ -43,6 +43,9 @@ type App struct {
|
||||
broker *agentmqtt.Client
|
||||
stopBridge func()
|
||||
hookURL string
|
||||
// Relays camera feeds to the webview so the engine's credential never has
|
||||
// to travel in an <img> src, which a Chromium webview would strip anyway.
|
||||
proxy *streamProxy
|
||||
// Set once the operator logs in. Until then the UI shows the login sheet
|
||||
// and nothing else is reachable.
|
||||
onSessionChange func(bool)
|
||||
@@ -63,6 +66,7 @@ func NewApp() *App {
|
||||
cfg: cfg,
|
||||
cloud: cloud.New(envOr("BEHAVISION_CLOUD", "https://mcp.loyaly.ai")),
|
||||
local: local.New(base, cfg.APIUser, cfg.APIPassword),
|
||||
proxy: newStreamProxy(),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -70,6 +74,14 @@ func (a *App) startup(ctx context.Context) {
|
||||
a.ctx = ctx
|
||||
_ = agentpaths.EnsureState()
|
||||
|
||||
// Before any screen asks for a camera URL. A failure here is logged and
|
||||
// not fatal: the rest of the app - people, cameras, the engine controls -
|
||||
// works without a picture, and refusing to start over a broken tile would
|
||||
// take a working shop offline.
|
||||
if err := a.proxy.start(a.local.Base, a.local.User, a.local.Password); err != nil {
|
||||
log.Printf("camera relay unavailable, tiles will not load: %v", err)
|
||||
}
|
||||
|
||||
// A saved session means a shop PC that rebooted overnight comes back
|
||||
// working instead of waiting for someone to log in.
|
||||
if a.cfg.SessionToken != "" {
|
||||
@@ -273,8 +285,8 @@ type PipelineStatus struct {
|
||||
// Standalone separates "nothing is being sent because this PC is set up on
|
||||
// its own" from "nothing is being sent and something is wrong". They look
|
||||
// identical from the counters alone, and only one of them is a fault.
|
||||
Standalone bool `json:"standalone"`
|
||||
BrokerUp bool `json:"broker_up"`
|
||||
Standalone bool `json:"standalone"`
|
||||
BrokerUp bool `json:"broker_up"`
|
||||
Accepted uint64 `json:"accepted"`
|
||||
}
|
||||
|
||||
@@ -549,15 +561,25 @@ func (a *App) PlacementResult(id string) (map[string]any, error) {
|
||||
return a.local.PlacementResult(ctx, id)
|
||||
}
|
||||
|
||||
// StreamURL is the MJPEG endpoint for a camera, with credentials inline so an
|
||||
// <img> tag can load it. Loopback only - it never leaves this machine.
|
||||
// StreamURL is the MJPEG endpoint for a camera tile.
|
||||
//
|
||||
// It points at this app's own loopback relay, not at the engine directly. The
|
||||
// previous version put the engine's Basic credentials inline in the URL, with
|
||||
// a comment saying they were there "so an <img> tag can load it" - which a
|
||||
// browser will not do. Chromium strips credentials from subresource URLs, and
|
||||
// WebView2 is Chromium, so every camera tile on a shop PC was a broken image.
|
||||
// See stream_proxy.go for the measurement.
|
||||
//
|
||||
// The relay is also why no password appears in the page any more. If it is not
|
||||
// running the fallback is the bare engine URL with no credential: correct for
|
||||
// an engine configured without auth, and for one with auth a tile that fails
|
||||
// to load rather than a password sitting in the DOM.
|
||||
func (a *App) StreamURL(cameraID string) string {
|
||||
base := strings.TrimPrefix(strings.TrimPrefix(a.local.Base, "http://"), "https://")
|
||||
if a.local.User == "" {
|
||||
return fmt.Sprintf("http://%s/api/cameras/%s/stream.mjpeg", base, cameraID)
|
||||
if u := a.proxy.urlFor(cameraID, "stream.mjpeg"); u != "" {
|
||||
return u
|
||||
}
|
||||
return fmt.Sprintf("http://%s:%s@%s/api/cameras/%s/stream.mjpeg",
|
||||
a.local.User, a.local.Password, base, cameraID)
|
||||
base := strings.TrimPrefix(strings.TrimPrefix(a.local.Base, "http://"), "https://")
|
||||
return fmt.Sprintf("http://%s/api/cameras/%s/stream.mjpeg", base, cameraID)
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------- live --
|
||||
|
||||
Reference in New Issue
Block a user