Behavision: face recognition for retail, edge to head office
Five components that ship as one product:
- behavision/ the recognition engine. RTSP ingest, YuNet detection, IoU
tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
FastAPI dashboard. Identity is decided once per TRACK from an
average of at least three embeddings, never per frame.
- agent/ the Go edge agent: supervises the engine, holds a durable
spool, and drains it to MQTT. Nothing is acked before the
broker confirms.
- desktop/ the shop PC application (Wails + React + tray).
- server/ the cloud API, MQTT consumer, reports and assistant.
- web/ platform.loyaly.ai, the head-office app, embedded in the
server binary.
The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.
CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
This commit is contained in:
106
server/internal/secret/secret.go
Normal file
106
server/internal/secret/secret.go
Normal file
@@ -0,0 +1,106 @@
|
||||
// Package secret encrypts the few values the server must be able to hand back
|
||||
// out again — today, each site's broker password.
|
||||
//
|
||||
// A password that gets given to an enrolling PC cannot be hashed, so the
|
||||
// choice is plaintext in a column or encrypted with a key that lives outside
|
||||
// the database. Encrypted means a stolen dump is not a set of live broker
|
||||
// logins, which is exactly what the plaintext column would be.
|
||||
package secret
|
||||
|
||||
import (
|
||||
"crypto/aes"
|
||||
"crypto/cipher"
|
||||
"crypto/rand"
|
||||
"encoding/base64"
|
||||
"errors"
|
||||
"fmt"
|
||||
"os"
|
||||
)
|
||||
|
||||
// Box seals and opens values with AES-256-GCM.
|
||||
type Box struct{ aead cipher.AEAD }
|
||||
|
||||
var ErrNoKey = errors.New("BEHAVISION_SECRET_KEY is not set")
|
||||
|
||||
// FromEnv builds a Box from a base64 32-byte key.
|
||||
//
|
||||
// Refuses a short key outright rather than stretching it. A key derived from
|
||||
// whatever someone typed into an env var is a key with unknown entropy, and
|
||||
// "it worked" would hide that permanently.
|
||||
func FromEnv(name string) (*Box, error) {
|
||||
raw := os.Getenv(name)
|
||||
if raw == "" {
|
||||
return nil, ErrNoKey
|
||||
}
|
||||
key, err := base64.StdEncoding.DecodeString(raw)
|
||||
if err != nil {
|
||||
key, err = base64.RawURLEncoding.DecodeString(raw)
|
||||
}
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s must be base64: %w", name, err)
|
||||
}
|
||||
return New(key)
|
||||
}
|
||||
|
||||
func New(key []byte) (*Box, error) {
|
||||
if len(key) != 32 {
|
||||
return nil, fmt.Errorf("key must be 32 bytes, got %d "+
|
||||
"(generate one with: openssl rand -base64 32)", len(key))
|
||||
}
|
||||
blk, err := aes.NewCipher(key)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
aead, err := cipher.NewGCM(blk)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &Box{aead: aead}, nil
|
||||
}
|
||||
|
||||
// NewKey generates a key for provisioning.
|
||||
func NewKey() (string, error) {
|
||||
var k [32]byte
|
||||
if _, err := rand.Read(k[:]); err != nil {
|
||||
return "", err
|
||||
}
|
||||
return base64.StdEncoding.EncodeToString(k[:]), nil
|
||||
}
|
||||
|
||||
// Seal returns nonce||ciphertext.
|
||||
//
|
||||
// `aad` binds the ciphertext to where it is stored — the agent id for a broker
|
||||
// password. Without it a row copied from one agent to another decrypts happily,
|
||||
// so a database write becomes a way to hand one site another site's
|
||||
// credentials.
|
||||
func (b *Box) Seal(plain []byte, aad string) ([]byte, error) {
|
||||
nonce := make([]byte, b.aead.NonceSize())
|
||||
if _, err := rand.Read(nonce); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return b.aead.Seal(nonce, nonce, plain, []byte(aad)), nil
|
||||
}
|
||||
|
||||
func (b *Box) Open(sealed []byte, aad string) ([]byte, error) {
|
||||
n := b.aead.NonceSize()
|
||||
if len(sealed) < n {
|
||||
return nil, errors.New("ciphertext is truncated")
|
||||
}
|
||||
out, err := b.aead.Open(nil, sealed[:n], sealed[n:], []byte(aad))
|
||||
if err != nil {
|
||||
// Deliberately vague to the caller's caller: whether a value failed to
|
||||
// decrypt because of the key or because of tampering is not something
|
||||
// to report over HTTP.
|
||||
return nil, errors.New("cannot decrypt: wrong key or altered data")
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
func (b *Box) SealString(plain, aad string) ([]byte, error) {
|
||||
return b.Seal([]byte(plain), aad)
|
||||
}
|
||||
|
||||
func (b *Box) OpenString(sealed []byte, aad string) (string, error) {
|
||||
out, err := b.Open(sealed, aad)
|
||||
return string(out), err
|
||||
}
|
||||
107
server/internal/secret/secret_test.go
Normal file
107
server/internal/secret/secret_test.go
Normal file
@@ -0,0 +1,107 @@
|
||||
package secret
|
||||
|
||||
import (
|
||||
"encoding/base64"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func newBox(t *testing.T) *Box {
|
||||
t.Helper()
|
||||
k, err := NewKey()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
raw, _ := base64.StdEncoding.DecodeString(k)
|
||||
b, err := New(raw)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
return b
|
||||
}
|
||||
|
||||
func TestRoundTrip(t *testing.T) {
|
||||
b := newBox(t)
|
||||
sealed, err := b.SealString("broker-password", "agent-1")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if strings.Contains(string(sealed), "broker-password") {
|
||||
t.Fatal("the plaintext is visible in the ciphertext")
|
||||
}
|
||||
got, err := b.OpenString(sealed, "agent-1")
|
||||
if err != nil || got != "broker-password" {
|
||||
t.Fatalf("got %q, %v", got, err)
|
||||
}
|
||||
}
|
||||
|
||||
// The aad binds the ciphertext to the row it lives in. Without it a value
|
||||
// copied from one agent's row to another decrypts happily, so a database write
|
||||
// becomes a way to hand one site another site's broker credentials.
|
||||
func TestCiphertextIsBoundToItsOwner(t *testing.T) {
|
||||
b := newBox(t)
|
||||
sealed, _ := b.SealString("broker-password", "agent-1")
|
||||
if _, err := b.OpenString(sealed, "agent-2"); err == nil {
|
||||
t.Fatal("a secret decrypted under the wrong agent id")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnotherKeyCannotOpenIt(t *testing.T) {
|
||||
sealed, _ := newBox(t).SealString("broker-password", "agent-1")
|
||||
if _, err := newBox(t).OpenString(sealed, "agent-1"); err == nil {
|
||||
t.Fatal("a different key opened the ciphertext")
|
||||
}
|
||||
}
|
||||
|
||||
func TestTamperingIsDetected(t *testing.T) {
|
||||
b := newBox(t)
|
||||
sealed, _ := b.SealString("broker-password", "agent-1")
|
||||
sealed[len(sealed)-1] ^= 0x01
|
||||
if _, err := b.OpenString(sealed, "agent-1"); err == nil {
|
||||
t.Fatal("a modified ciphertext was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func TestNonceIsFreshEachTime(t *testing.T) {
|
||||
b := newBox(t)
|
||||
// Identical plaintexts must not produce identical ciphertexts, or the
|
||||
// database shows at a glance which sites share a password.
|
||||
a, _ := b.SealString("same", "agent-1")
|
||||
c, _ := b.SealString("same", "agent-1")
|
||||
if string(a) == string(c) {
|
||||
t.Fatal("the nonce is being reused")
|
||||
}
|
||||
}
|
||||
|
||||
func TestShortKeysAreRefusedRatherThanStretched(t *testing.T) {
|
||||
// A key derived from whatever somebody typed into an env var has unknown
|
||||
// entropy, and "it worked" would hide that permanently.
|
||||
if _, err := New([]byte("too short")); err == nil {
|
||||
t.Fatal("a 9-byte key was accepted")
|
||||
}
|
||||
if _, err := New(nil); err == nil {
|
||||
t.Fatal("an empty key was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func TestTruncatedCiphertextDoesNotPanic(t *testing.T) {
|
||||
b := newBox(t)
|
||||
if _, err := b.Open([]byte{1, 2, 3}, "agent-1"); err == nil {
|
||||
t.Fatal("a three-byte ciphertext was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func TestFromEnvReportsAMissingKeyByName(t *testing.T) {
|
||||
if _, err := FromEnv("BEHAVISION_SECRET_KEY_NOT_SET_IN_TESTS"); err != ErrNoKey {
|
||||
t.Fatalf("got %v", err)
|
||||
}
|
||||
t.Setenv("TEST_KEY", "not base64 !!!")
|
||||
if _, err := FromEnv("TEST_KEY"); err == nil {
|
||||
t.Fatal("garbage was accepted as a key")
|
||||
}
|
||||
k, _ := NewKey()
|
||||
t.Setenv("TEST_KEY", k)
|
||||
if _, err := FromEnv("TEST_KEY"); err != nil {
|
||||
t.Fatalf("a generated key was refused: %v", err)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user