Behavision: face recognition for retail, edge to head office
Five components that ship as one product:
- behavision/ the recognition engine. RTSP ingest, YuNet detection, IoU
tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
FastAPI dashboard. Identity is decided once per TRACK from an
average of at least three embeddings, never per frame.
- agent/ the Go edge agent: supervises the engine, holds a durable
spool, and drains it to MQTT. Nothing is acked before the
broker confirms.
- desktop/ the shop PC application (Wails + React + tray).
- server/ the cloud API, MQTT consumer, reports and assistant.
- web/ platform.loyaly.ai, the head-office app, embedded in the
server binary.
The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.
CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
This commit is contained in:
79
server/internal/api/throttle_test.go
Normal file
79
server/internal/api/throttle_test.go
Normal file
@@ -0,0 +1,79 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
"time"
|
||||
)
|
||||
|
||||
func TestThrottleBlocksAfterMaxAndForgetsAfterTheWindow(t *testing.T) {
|
||||
now := time.Unix(1_000_000, 0)
|
||||
th := NewThrottle(3, time.Minute)
|
||||
th.now = func() time.Time { return now }
|
||||
|
||||
for i := 0; i < 3; i++ {
|
||||
if !th.Allow("k") {
|
||||
t.Fatalf("blocked after %d failures, max is 3", i)
|
||||
}
|
||||
th.Fail("k")
|
||||
}
|
||||
if th.Allow("k") {
|
||||
t.Fatal("still allowed after hitting the maximum")
|
||||
}
|
||||
// A different key is a different attacker.
|
||||
if !th.Allow("other") {
|
||||
t.Fatal("one key's failures blocked another")
|
||||
}
|
||||
|
||||
now = now.Add(time.Minute + time.Second)
|
||||
if !th.Allow("k") {
|
||||
t.Fatal("the window never expired")
|
||||
}
|
||||
}
|
||||
|
||||
func TestThrottleResetClearsAKey(t *testing.T) {
|
||||
th := NewThrottle(2, time.Minute)
|
||||
th.Fail("k")
|
||||
th.Fail("k")
|
||||
if th.Allow("k") {
|
||||
t.Fatal("not blocked")
|
||||
}
|
||||
th.Reset("k")
|
||||
if !th.Allow("k") {
|
||||
t.Fatal("a successful sign-in did not clear the counter")
|
||||
}
|
||||
}
|
||||
|
||||
// Pruning happens on read, so a key nobody touches again must not survive a
|
||||
// sweep. Otherwise an attacker spraying distinct addresses grows the map
|
||||
// without bound.
|
||||
func TestThrottleDoesNotGrowForever(t *testing.T) {
|
||||
now := time.Unix(1_000_000, 0)
|
||||
th := NewThrottle(5, time.Minute)
|
||||
th.now = func() time.Time { return now }
|
||||
for i := 0; i < 1000; i++ {
|
||||
th.Fail("key" + itoa(i))
|
||||
}
|
||||
if len(th.hits) != 1000 {
|
||||
t.Fatalf("expected 1000 keys, got %d", len(th.hits))
|
||||
}
|
||||
now = now.Add(2 * time.Minute)
|
||||
th.Sweep()
|
||||
if len(th.hits) != 0 {
|
||||
t.Fatalf("%d keys survived the sweep", len(th.hits))
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientIPPrefersTheProxyHeader(t *testing.T) {
|
||||
r := httptest.NewRequest("POST", "/api/auth/login", nil)
|
||||
r.RemoteAddr = "10.0.0.5:44321"
|
||||
if got := clientIP(r); got != "10.0.0.5" {
|
||||
t.Fatalf("got %q", got)
|
||||
}
|
||||
// Traefik terminates TLS in front of this, so RemoteAddr is always the
|
||||
// proxy and the left-most forwarded address is the real client.
|
||||
r.Header.Set("X-Forwarded-For", "203.0.113.9, 10.0.0.1")
|
||||
if got := clientIP(r); got != "203.0.113.9" {
|
||||
t.Fatalf("got %q", got)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user