Every id in the schema is a uuid and stays one. What was wrong was putting one in front of a person: RecordVisit named every new customer 'Visitor ' || left(id::text, 8), so the arrivals feed, the shop PC and the mobile app all read "Visitor 3446ec35" - the string a shop assistant reads to a colleague and types into a search box. label is a stored column staff can overwrite and SearchVisitors matches on, so formatting around it in a front end would have left the data wrong on three surfaces. Migration 012 adds a per-client visitors.number, taken from a counter on clients with UPDATE ... RETURNING inside the visit transaction. Per client rather than global: a global sequence would tell any customer who signs up how many people the whole platform has ever seen, from their own first visitor number. The backfill numbers existing rows by first_seen_at and relabels only the eight-hex pattern the old statement produced, so a human-typed name is never overwritten. Three of the four things anyone addresses by URL already had a human name and the API simply refused it - a site has a slug, a camera has the id the engine knows it by. refs.go accepts either form anywhere an id is taken; a uuid resolves with no lookup, so every URL a client already stored keeps working. - An ambiguous camera name resolves to nothing, never to a guess: two shops may each have an "Office1" and acting on the first row would edit the wrong shop's camera. - 404 on a path, 400 on a query filter. /api/visits answered fine and it was the filter that was wrong. - site and site_id are both accepted everywhere now. They differed per endpoint, and an unknown query parameter is silently ignored, so getting it the wrong way round returned the whole estate. - The search matches V-13, which is what the product now shows. Two bugs found by running it rather than testing it: - 'Visitor ' || $2::text beside number = $2 makes Postgres deduce two types for one parameter and refuse the insert. It compiled and passed every in-memory test; the first real database rejected it, along with the existing face tests that share the path. - The fallback avatar said "V1" for Visitor 13, Visitor 10 and Visitor 15 alike, and read as the V-1 reference for a fourth person. It shows the number now. The prop is customerRef, not ref - React reserves that name and it would never have arrived. Verified on the live database and through the running API: 13 hex labels became Visitor 1-13 in first-seen order, two typed names left alone, and the same customer reachable by uuid, V-13 and 13. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
373 lines
12 KiB
Go
373 lines
12 KiB
Go
package store
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"strings"
|
|
"time"
|
|
|
|
"github.com/jackc/pgx/v5"
|
|
|
|
"github.com/loyaly/behavision-server/internal/api"
|
|
"github.com/loyaly/behavision-server/internal/secret"
|
|
)
|
|
|
|
// Secrets decrypts values the server must hand back out - today, each site's
|
|
// broker password. Nil until configured, and every path that needs it says so
|
|
// rather than silently returning an empty credential.
|
|
func (s *Store) UseSecrets(b *secret.Box) { s.secrets = b }
|
|
|
|
// likePattern escapes the wildcards so a customer searching for "50%" finds
|
|
// the person called "50%" instead of matching everybody.
|
|
func likePattern(q string) string {
|
|
r := strings.NewReplacer(`\`, `\\`, `%`, `\%`, `_`, `\_`)
|
|
return "%" + r.Replace(q) + "%"
|
|
}
|
|
|
|
// searchNumber is the customer number behind a query, or 0 for a query that is
|
|
// not one.
|
|
//
|
|
// The reference is what staff now READ on screen - "V-13" - so it is what they
|
|
// paste into the search box, and matching only `label ILIKE '%V-13%'` finds
|
|
// nothing at all, because the stored label says "Visitor 13". A search that
|
|
// comes back empty for the identifier the product just showed you is worse
|
|
// than no search at all.
|
|
func searchNumber(query string) int64 {
|
|
n, ok := api.ParseVisitorRef(query)
|
|
if !ok {
|
|
return 0
|
|
}
|
|
return n
|
|
}
|
|
|
|
func (s *Store) SearchVisitors(ctx context.Context, clientID, query string, limit int) (
|
|
[]api.Customer, error) {
|
|
|
|
rows, err := s.pool.Query(ctx, `
|
|
SELECT v.id::text, v.number, v.label,
|
|
COALESCE(p.full_name, ''), COALESCE(p.phone, ''), COALESCE(p.email, ''),
|
|
v.visit_count, v.first_seen_at, v.last_seen_at,
|
|
(p.id IS NOT NULL),
|
|
EXISTS (SELECT 1 FROM consents c
|
|
WHERE c.visitor_id = v.id AND c.revoked_at IS NULL)
|
|
FROM visitors v
|
|
LEFT JOIN visitor_profiles p
|
|
ON p.visitor_id = v.id AND p.client_id = v.client_id
|
|
WHERE v.client_id = $1 AND v.deleted_at IS NULL
|
|
AND ($2 = '' OR v.number = $5
|
|
OR v.label ILIKE $3 ESCAPE '\'
|
|
OR p.full_name ILIKE $3 ESCAPE '\'
|
|
OR p.phone ILIKE $3 ESCAPE '\'
|
|
OR p.email ILIKE $3 ESCAPE '\')
|
|
ORDER BY v.last_seen_at DESC NULLS LAST, v.first_seen_at DESC
|
|
LIMIT $4`,
|
|
clientID, strings.TrimSpace(query), likePattern(strings.TrimSpace(query)),
|
|
limit, searchNumber(query))
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
defer rows.Close()
|
|
|
|
var out []api.Customer
|
|
for rows.Next() {
|
|
var c api.Customer
|
|
var first time.Time
|
|
var last *time.Time
|
|
var number int64
|
|
if err := rows.Scan(&c.ID, &number, &c.Label, &c.FullName, &c.Phone, &c.Email,
|
|
&c.VisitCount, &first, &last, &c.HasProfile, &c.HasConsent); err != nil {
|
|
return nil, err
|
|
}
|
|
c.Ref = api.VisitorRef(number)
|
|
c.FirstSeenAt = first.UTC().Format(time.RFC3339)
|
|
if last != nil {
|
|
c.LastSeenAt = last.UTC().Format(time.RFC3339)
|
|
}
|
|
out = append(out, c)
|
|
}
|
|
return out, rows.Err()
|
|
}
|
|
|
|
func (s *Store) VisitorHistory(ctx context.Context, clientID, visitorID string, limit int) (
|
|
[]api.VisitRow, error) {
|
|
|
|
rows, err := s.pool.Query(ctx, `
|
|
SELECT vi.id::text, vi.occurred_at, si.name, vi.camera_id,
|
|
vi.is_new_visitor, vi.similarity, vi.quality, vi.attributes
|
|
FROM visits vi
|
|
JOIN sites si ON si.id = vi.site_id
|
|
WHERE vi.client_id = $1 AND vi.visitor_id = $2::uuid
|
|
ORDER BY vi.occurred_at DESC
|
|
LIMIT $3`, clientID, visitorID, limit)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
defer rows.Close()
|
|
|
|
var out []api.VisitRow
|
|
for rows.Next() {
|
|
var v api.VisitRow
|
|
var at time.Time
|
|
var sim, qual *float64
|
|
if err := rows.Scan(&v.ID, &at, &v.Site, &v.CameraID, &v.IsNew,
|
|
&sim, &qual, &v.Attributes); err != nil {
|
|
return nil, err
|
|
}
|
|
v.OccurredAt = at.UTC().Format(time.RFC3339)
|
|
if sim != nil {
|
|
v.Similarity = *sim
|
|
}
|
|
if qual != nil {
|
|
v.Quality = *qual
|
|
}
|
|
out = append(out, v)
|
|
}
|
|
return out, rows.Err()
|
|
}
|
|
|
|
// SaveProfile writes the in-store form, and the consent record with it.
|
|
//
|
|
// One transaction: a name saved without its consent row is a customer whose
|
|
// personal data we hold with no record of being allowed to, which is the exact
|
|
// state the consents table exists to make impossible.
|
|
func (s *Store) SaveProfile(ctx context.Context, clientID string, p api.Profile,
|
|
actor string) error {
|
|
|
|
tx, err := s.pool.Begin(ctx)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer tx.Rollback(ctx) //nolint:errcheck // no-op once committed
|
|
|
|
// Scoped to the client, so an id from another tenant is simply not found -
|
|
// the same answer as a typo, which is what it should look like.
|
|
var exists bool
|
|
err = tx.QueryRow(ctx, `
|
|
SELECT true FROM visitors
|
|
WHERE id = $1::uuid AND client_id = $2 AND deleted_at IS NULL`,
|
|
p.VisitorID, clientID).Scan(&exists)
|
|
if errors.Is(err, pgx.ErrNoRows) {
|
|
return errors.New("no such visitor")
|
|
}
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
var dob any
|
|
if p.DateOfBirth != "" {
|
|
dob = p.DateOfBirth
|
|
}
|
|
if _, err := tx.Exec(ctx, `
|
|
INSERT INTO visitor_profiles (visitor_id, client_id, full_name, phone,
|
|
email, gender, date_of_birth, notes,
|
|
collected_by)
|
|
VALUES ($1::uuid, $2, $3, $4, $5, $6, $7::date, $8, NULLIF($9, '')::uuid)
|
|
ON CONFLICT (visitor_id) DO UPDATE SET
|
|
full_name = EXCLUDED.full_name,
|
|
phone = EXCLUDED.phone,
|
|
email = EXCLUDED.email,
|
|
gender = EXCLUDED.gender,
|
|
date_of_birth = EXCLUDED.date_of_birth,
|
|
notes = EXCLUDED.notes,
|
|
collected_by = EXCLUDED.collected_by,
|
|
updated_at = now()`,
|
|
p.VisitorID, clientID, p.FullName, p.Phone, p.Email, p.Gender,
|
|
dob, p.Notes, actor); err != nil {
|
|
return fmt.Errorf("save profile: %w", err)
|
|
}
|
|
|
|
if p.Consent {
|
|
// Only if there is not already a live one. Re-saving the form must not
|
|
// stack up consent records, or the audit trail stops being readable.
|
|
if _, err := tx.Exec(ctx, `
|
|
INSERT INTO consents (visitor_id, client_id, scope, method,
|
|
collected_by, evidence)
|
|
SELECT $1::uuid, $2, 'biometric', 'in_store_form',
|
|
NULLIF($3, '')::uuid, '{}'::jsonb
|
|
WHERE NOT EXISTS (
|
|
SELECT 1 FROM consents
|
|
WHERE visitor_id = $1::uuid AND scope = 'biometric'
|
|
AND revoked_at IS NULL)`,
|
|
p.VisitorID, clientID, actor); err != nil {
|
|
return fmt.Errorf("record consent: %w", err)
|
|
}
|
|
} else {
|
|
// Unticking the box is a withdrawal, and a withdrawal is a timestamp,
|
|
// never a delete: the fact that they withdrew is itself the thing an
|
|
// auditor asks to see.
|
|
if _, err := tx.Exec(ctx, `
|
|
UPDATE consents SET revoked_at = now()
|
|
WHERE visitor_id = $1::uuid AND client_id = $2
|
|
AND scope = 'biometric' AND revoked_at IS NULL`,
|
|
p.VisitorID, clientID); err != nil {
|
|
return fmt.Errorf("revoke consent: %w", err)
|
|
}
|
|
}
|
|
return tx.Commit(ctx)
|
|
}
|
|
|
|
// RecordPurchase books a sale against a customer.
|
|
//
|
|
// When no site is given it uses the one where this customer was most recently
|
|
// seen, which is what "the assistant on the floor just sold them something"
|
|
// means. If they have never been seen anywhere the caller is told to pass a
|
|
// site rather than being handed a foreign key error.
|
|
func (s *Store) RecordPurchase(ctx context.Context, clientID string,
|
|
p api.PurchaseInput, actor string) error {
|
|
|
|
tx, err := s.pool.Begin(ctx)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer tx.Rollback(ctx) //nolint:errcheck
|
|
|
|
var exists bool
|
|
err = tx.QueryRow(ctx, `
|
|
SELECT true FROM visitors
|
|
WHERE id = $1::uuid AND client_id = $2 AND deleted_at IS NULL`,
|
|
p.VisitorID, clientID).Scan(&exists)
|
|
if errors.Is(err, pgx.ErrNoRows) {
|
|
return errors.New("no such visitor")
|
|
}
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
siteID := p.SiteID
|
|
var visitID any
|
|
if siteID == "" {
|
|
var sid, vid *string
|
|
err = tx.QueryRow(ctx, `
|
|
SELECT site_id::text, id::text FROM visits
|
|
WHERE client_id = $1 AND visitor_id = $2::uuid
|
|
ORDER BY occurred_at DESC LIMIT 1`,
|
|
clientID, p.VisitorID).Scan(&sid, &vid)
|
|
if errors.Is(err, pgx.ErrNoRows) || sid == nil {
|
|
return errors.New("no site for this visitor")
|
|
}
|
|
if err != nil {
|
|
return err
|
|
}
|
|
siteID = *sid
|
|
// Attaching the sale to the visit it belongs to is what makes
|
|
// "did this visit convert" answerable at all, rather than only
|
|
// "did this person ever buy".
|
|
visitID = vid
|
|
} else {
|
|
// A site passed in must still belong to the caller's client.
|
|
var ok bool
|
|
err = tx.QueryRow(ctx,
|
|
`SELECT true FROM sites WHERE id = $1::uuid AND client_id = $2`,
|
|
siteID, clientID).Scan(&ok)
|
|
if errors.Is(err, pgx.ErrNoRows) {
|
|
return errors.New("no site for this visitor")
|
|
}
|
|
if err != nil {
|
|
return err
|
|
}
|
|
}
|
|
|
|
items := p.Items
|
|
if items == nil {
|
|
items = []string{}
|
|
}
|
|
if _, err := tx.Exec(ctx, `
|
|
INSERT INTO purchases (client_id, site_id, visitor_id, visit_id, amount,
|
|
currency, items, source, external_ref, recorded_by)
|
|
VALUES ($1, $2::uuid, $3::uuid, $4::uuid, $5, $6, $7, $8, $9,
|
|
NULLIF($10, '')::uuid)`,
|
|
clientID, siteID, p.VisitorID, visitID, p.Amount, p.Currency,
|
|
items, p.Source, p.Notes, actor); err != nil {
|
|
return fmt.Errorf("insert purchase: %w", err)
|
|
}
|
|
return tx.Commit(ctx)
|
|
}
|
|
|
|
// ---------------------------------------------------------------- enrolment
|
|
|
|
// RedeemEnrolment spends an installation code and returns the broker login.
|
|
//
|
|
// Single-use is enforced by the UPDATE itself: the `used_at IS NULL` predicate
|
|
// and the write are one statement, so two PCs racing on the same code cannot
|
|
// both win. Checking first and updating after would be exactly that race.
|
|
func (s *Store) RedeemEnrolment(ctx context.Context, hash []byte) (api.Enrolment, error) {
|
|
var en api.Enrolment
|
|
err := s.pool.QueryRow(ctx, `
|
|
UPDATE site_enrolment_tokens
|
|
SET used_at = now()
|
|
WHERE token_hash = $1 AND used_at IS NULL AND expires_at > now()
|
|
RETURNING client_id::text, site_id::text`, hash).
|
|
Scan(&en.ClientID, &en.SiteID)
|
|
if errors.Is(err, pgx.ErrNoRows) {
|
|
return en, errors.New("enrolment token is unknown, expired or already used")
|
|
}
|
|
if err != nil {
|
|
return en, err
|
|
}
|
|
|
|
var sealed []byte
|
|
if err := s.pool.QueryRow(ctx, `
|
|
SELECT si.name, si.slug, a.id::text, a.mqtt_username, a.mqtt_password_enc
|
|
FROM sites si
|
|
JOIN agents a ON a.site_id = si.id
|
|
WHERE si.id = $1::uuid AND si.client_id = $2`,
|
|
en.SiteID, en.ClientID).
|
|
Scan(&en.SiteName, &en.SiteSlug, &en.AgentID, &en.MQTTUser, &sealed); err != nil {
|
|
if errors.Is(err, pgx.ErrNoRows) {
|
|
return en, errors.New("site has no agent provisioned - " +
|
|
"create the broker user before issuing an enrolment token")
|
|
}
|
|
return en, err
|
|
}
|
|
if len(sealed) == 0 {
|
|
return en, errors.New("site has no broker password stored")
|
|
}
|
|
if s.secrets == nil {
|
|
return en, errors.New("BEHAVISION_SECRET_KEY is not configured, " +
|
|
"so stored broker passwords cannot be read")
|
|
}
|
|
pass, err := s.secrets.OpenString(sealed, en.AgentID)
|
|
if err != nil {
|
|
return en, fmt.Errorf("broker password for %s: %w", en.SiteSlug, err)
|
|
}
|
|
en.MQTTPass = pass
|
|
return en, nil
|
|
}
|
|
|
|
// SetAgentSecret stores a site's broker password, sealed to that agent's id.
|
|
// Used by provisioning, never by a request handler.
|
|
func (s *Store) SetAgentSecret(ctx context.Context, agentID, password string) error {
|
|
if s.secrets == nil {
|
|
return errors.New("BEHAVISION_SECRET_KEY is not configured")
|
|
}
|
|
sealed, err := s.secrets.SealString(password, agentID)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
_, err = s.pool.Exec(ctx,
|
|
`UPDATE agents SET mqtt_password_enc = $2 WHERE id = $1::uuid`,
|
|
agentID, sealed)
|
|
return err
|
|
}
|
|
|
|
// Audit never fails a request.
|
|
//
|
|
// A refused audit write is worth knowing about, but refusing the action it was
|
|
// recording is worse: it would mean an outage in the logging table stops staff
|
|
// serving customers.
|
|
func (s *Store) Audit(ctx context.Context, e api.AuditEntry) {
|
|
detail := e.Detail
|
|
if detail == nil {
|
|
detail = map[string]any{}
|
|
}
|
|
if _, err := s.pool.Exec(ctx, `
|
|
INSERT INTO audit_log (client_id, actor_id, actor_kind, action,
|
|
entity, entity_id, detail)
|
|
VALUES (NULLIF($1, '')::uuid, NULLIF($2, '')::uuid, $3, $4, $5, $6, $7)`,
|
|
e.ClientID, e.ActorID, e.ActorKind, e.Action,
|
|
e.Entity, e.EntityID, detail); err != nil {
|
|
s.auditFailed(e.Action, err)
|
|
}
|
|
}
|