Asked directly: "our cameras have an rtsp url, we can use that to connect them to this software right". Yes - and that has always been the mechanism, which is the point. CameraConfig.source() builds exactly that URL from the parts, and CameraConfig.url has always accepted a whole one and taken priority over them. No form ever offered it. So an operator holding the address their camera's own app shows had to split it into five fields by eye. That is where a password containing @ or / goes wrong, and this repository has already been bitten once by unencoded @ in RTSP credentials. parseRtspUrl lives in shared/cameraMakes.js and is imported by BOTH forms, for the same reason the make picker is: two copies would be worse than not offering it, because an operator trusts a filled-in field. A test asserts both import it. Decisions worth keeping: - Split into fields, not stored whole. Everything else on the form - Test, the make picker, editing later, and the rule that a password is never returned to the browser - works on the parts. A URL kept intact would carry the password back out to every screen that reads a camera. - WHATWG splits user info at the LAST @, which is what makes an unencoded @ inside a password parse the way a person means it. An operator doing it by eye would put "p" in the password box and "ssw0rd@192.168.1.121" in the address box. - Percent-encoded credentials are DECODED, because source() encodes again when it rebuilds the URL. Keeping them encoded would double-encode and the camera would refuse a password that is correct. - The scheme is optional, structure is not. Without requiring a slash, "nonsense" parses as a perfectly good hostname and silently fills the Address field with it - a wrong answer that looks like it worked. A bare address is refused too: the Address field already takes one. - A query string stays with the path. Some cameras carry the channel there, and dropping it opens the wrong channel - which looks like a camera pointed somewhere unexpected. - A URL carrying no credentials does not wipe a password already typed. Tested through node from pytest, the same pattern test_dashboard.py uses, and skipped when node is absent so the suite stays dependency-light. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
Behavision desktop
The store-facing app: a tray icon, a window, and the supervisor for the Python recognition engine.
Why one process, not three
The tray, the window and the supervisor all need the same state, and a user who quits the tray expects recognition to stop. Splitting them means two things can disagree about whether the engine is running.
It is deliberately not a Windows service. A service runs in session 0 and cannot draw a tray icon — that is Windows session isolation, not a library limitation. Spawning a child process also needs no elevation, while controlling a service does, so this design never triggers UAC at runtime.
Layout
main.go wails.Run, window options
app.go the methods bound to the frontend
tray.go fyne.io/systray — wails v2 has no tray of its own
icons.go tray icons generated at run time, not embedded
internal/local client for the engine on 127.0.0.1:8010
internal/cloud client for https://mcp.loyaly.ai
frontend/ React + Vite
The supervisor, durable spool, broker client and path resolution come from
../agent/pkg/* — the same tested code the headless agent runs, imported
rather than copied.
Build
cd frontend && npm install && npm run build # then, from this directory:
wails build -platform windows/amd64
wails build needs the Wails CLI:
go install github.com/wailsapp/wails/v2/cmd/wails@v2.9.2
Without it, go build still type-checks everything provided
frontend/dist exists — the embed directive requires it.
What the frontend talks to
Nothing is imported from generated bindings. src/bridge.js calls
window.go.main.App.* directly, so npm run build works without running
wails generate, and there is one place that handles "the engine is not
running yet" — the state every screen has to survive on a fresh install.