Behavision: face recognition for retail, edge to head office
Five components that ship as one product:
- behavision/ the recognition engine. RTSP ingest, YuNet detection, IoU
tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
FastAPI dashboard. Identity is decided once per TRACK from an
average of at least three embeddings, never per frame.
- agent/ the Go edge agent: supervises the engine, holds a durable
spool, and drains it to MQTT. Nothing is acked before the
broker confirms.
- desktop/ the shop PC application (Wails + React + tray).
- server/ the cloud API, MQTT consumer, reports and assistant.
- web/ platform.loyaly.ai, the head-office app, embedded in the
server binary.
The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.
CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
This commit is contained in:
68
agent/pkg/config/protect_windows.go
Normal file
68
agent/pkg/config/protect_windows.go
Normal file
@@ -0,0 +1,68 @@
|
||||
//go:build windows
|
||||
|
||||
package config
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"syscall"
|
||||
"unsafe"
|
||||
)
|
||||
|
||||
// Windows DPAPI, reached through crypt32.dll directly rather than pulling in
|
||||
// golang.org/x/sys. Machine scope, matching how the Python side already
|
||||
// protects camera passwords: the agent and the engine may run as different
|
||||
// users on the same PC, and a user-scoped blob written by one cannot be read
|
||||
// by the other.
|
||||
var (
|
||||
crypt32 = syscall.NewLazyDLL("crypt32.dll")
|
||||
kernel32 = syscall.NewLazyDLL("kernel32.dll")
|
||||
procProtectData = crypt32.NewProc("CryptProtectData")
|
||||
procUnprotectData = crypt32.NewProc("CryptUnprotectData")
|
||||
procLocalFree = kernel32.NewProc("LocalFree")
|
||||
)
|
||||
|
||||
const cryptprotectLocalMachine = 0x4
|
||||
|
||||
type dataBlob struct {
|
||||
cbData uint32
|
||||
pbData *byte
|
||||
}
|
||||
|
||||
func newBlob(d []byte) dataBlob {
|
||||
if len(d) == 0 {
|
||||
return dataBlob{}
|
||||
}
|
||||
return dataBlob{cbData: uint32(len(d)), pbData: &d[0]}
|
||||
}
|
||||
|
||||
func (b *dataBlob) bytes() []byte {
|
||||
out := make([]byte, b.cbData)
|
||||
copy(out, unsafe.Slice(b.pbData, b.cbData))
|
||||
return out
|
||||
}
|
||||
|
||||
func protect(plain []byte) ([]byte, error) {
|
||||
in, out := newBlob(plain), dataBlob{}
|
||||
r, _, err := procProtectData.Call(
|
||||
uintptr(unsafe.Pointer(&in)), 0, 0, 0, 0,
|
||||
cryptprotectLocalMachine, uintptr(unsafe.Pointer(&out)))
|
||||
if r == 0 {
|
||||
return nil, fmt.Errorf("CryptProtectData: %w", err)
|
||||
}
|
||||
defer procLocalFree.Call(uintptr(unsafe.Pointer(out.pbData)))
|
||||
return out.bytes(), nil
|
||||
}
|
||||
|
||||
func unprotect(blob []byte) ([]byte, error) {
|
||||
in, out := newBlob(blob), dataBlob{}
|
||||
r, _, err := procUnprotectData.Call(
|
||||
uintptr(unsafe.Pointer(&in)), 0, 0, 0, 0,
|
||||
cryptprotectLocalMachine, uintptr(unsafe.Pointer(&out)))
|
||||
if r == 0 {
|
||||
return nil, fmt.Errorf("CryptUnprotectData: %w", err)
|
||||
}
|
||||
defer procLocalFree.Call(uintptr(unsafe.Pointer(out.pbData)))
|
||||
return out.bytes(), nil
|
||||
}
|
||||
|
||||
func protectionAvailable() bool { return true }
|
||||
Reference in New Issue
Block a user