Files
Behavision/agent/pkg/bridge/images_test.go
Suriyakumarvijayanayagam dad04e8cda Behavision: face recognition for retail, edge to head office
Five components that ship as one product:

- behavision/  the recognition engine. RTSP ingest, YuNet detection, IoU
               tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
               FastAPI dashboard. Identity is decided once per TRACK from an
               average of at least three embeddings, never per frame.
- agent/       the Go edge agent: supervises the engine, holds a durable
               spool, and drains it to MQTT. Nothing is acked before the
               broker confirms.
- desktop/     the shop PC application (Wails + React + tray).
- server/      the cloud API, MQTT consumer, reports and assistant.
- web/         platform.loyaly.ai, the head-office app, embedded in the
               server binary.

The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.

CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
2026-09-04 11:14:18 +05:30

203 lines
6.3 KiB
Go

package bridge
import (
"context"
"encoding/json"
"errors"
"io"
"net/http"
"net/http/httptest"
"os"
"path/filepath"
"strings"
"testing"
)
func writeImage(t *testing.T, dir, name string, body []byte) string {
t.Helper()
path := filepath.Join(dir, name)
if err := os.WriteFile(path, body, 0o600); err != nil {
t.Fatal(err)
}
return path
}
// fakeServer plays both halves: the API that mints an upload URL and the
// bucket that receives the PUT.
func fakeServer(t *testing.T, uploaded *[]byte, sentACL *string) *httptest.Server {
t.Helper()
mux := http.NewServeMux()
srv := httptest.NewServer(mux)
t.Cleanup(srv.Close)
mux.HandleFunc("/api/agent/upload-url", func(w http.ResponseWriter, r *http.Request) {
if r.Header.Get("Authorization") != "Bearer agent-token" {
w.WriteHeader(http.StatusUnauthorized)
return
}
json.NewEncoder(w).Encode(uploadTarget{ //nolint:errcheck
Key: "behavision/acme/store1/2026/08/31/abc.jpg",
URL: srv.URL + "/bucket/abc.jpg",
Headers: map[string]string{
"x-amz-acl": "private", "content-type": "image/jpeg",
},
ExpiresIn: 600,
})
})
mux.HandleFunc("/bucket/", func(w http.ResponseWriter, r *http.Request) {
body, _ := io.ReadAll(r.Body)
*uploaded = body
*sentACL = r.Header.Get("x-amz-acl")
w.WriteHeader(http.StatusOK)
})
return srv
}
func TestUploadSendsTheFileAndTheSignedACL(t *testing.T) {
var got []byte
var acl string
srv := fakeServer(t, &got, &acl)
dir := t.TempDir()
path := writeImage(t, dir, "face.jpg", []byte("jpeg bytes"))
u := &SpacesUploader{BaseURL: srv.URL, Token: "agent-token"}
key, err := u.Upload(context.Background(), path)
if err != nil {
t.Fatal(err)
}
if key != "behavision/acme/store1/2026/08/31/abc.jpg" {
t.Fatalf("key = %q", key)
}
if string(got) != "jpeg bytes" {
t.Fatalf("uploaded %q", got)
}
// The ACL is inside the server's signature. Sending it exactly as handed
// back is what keeps the shop PC from deciding to publish the image.
if acl != "private" {
t.Fatalf("x-amz-acl = %q, want private", acl)
}
}
func TestUnclaimedPCReportsImagesOffRatherThanFailing(t *testing.T) {
u := &SpacesUploader{} // no base url, no token: not enrolled yet
_, err := u.Upload(context.Background(), "/nonexistent")
if !errors.Is(err, ErrImagesOff) {
t.Fatalf("got %v, want ErrImagesOff", err)
}
}
func TestServerWithoutABucketIsNotARetryableFailure(t *testing.T) {
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
w.WriteHeader(http.StatusNotImplemented)
}))
defer srv.Close()
dir := t.TempDir()
path := writeImage(t, dir, "face.jpg", []byte("x"))
u := &SpacesUploader{BaseURL: srv.URL, Token: "agent-token"}
// 501 means "this deployment stores no images". The agent must stop trying
// rather than retry every visitor forever.
if _, err := u.Upload(context.Background(), path); !errors.Is(err, ErrImagesOff) {
t.Fatalf("got %v, want ErrImagesOff", err)
}
}
func TestOversizedFilesAreRefusedBeforeTheUplink(t *testing.T) {
dir := t.TempDir()
path := writeImage(t, dir, "huge.jpg", make([]byte, maxImageBytes+1))
u := &SpacesUploader{BaseURL: "http://example.invalid", Token: "t"}
// A shop uplink should not spend minutes discovering that something other
// than a face crop landed in the outbox.
if _, err := u.Upload(context.Background(), path); err == nil ||
!strings.Contains(err.Error(), "limit") {
t.Fatalf("got %v", err)
}
}
// -- the bridge's use of it -------------------------------------------------
type stubUploader struct {
key string
err error
sent []string
}
func (s *stubUploader) Upload(_ context.Context, path string) (string, error) {
s.sent = append(s.sent, path)
return s.key, s.err
}
func TestVisitCarriesTheImageKeyAndTheLocalFileIsRemoved(t *testing.T) {
q := &fakeQueue{}
up := &stubUploader{key: "behavision/acme/store1/2026/08/31/abc.jpg"}
b := &Bridge{Queue: q, TopicPrefix: "bv/acme.store1", Uploader: up}
path := writeImage(t, t.TempDir(), "face.jpg", []byte("jpeg"))
err := b.Handle(context.Background(), Event{
Type: "person.new", CameraID: "entrance", TS: 1756_000_000,
Data: map[string]any{"identity_id": float64(7), "image_path": path},
})
if err != nil {
t.Fatal(err)
}
if len(q.payloads) != 1 {
t.Fatalf("expected one queued visit, got %d", len(q.payloads))
}
visit := q.payloads[0]
if visit["image_key"] != up.key {
t.Fatalf("image_key = %v", visit["image_key"])
}
// The outbox is transient. Leaving files behind means a shop PC slowly
// filling with pictures of its customers.
if _, err := os.Stat(path); !os.IsNotExist(err) {
t.Fatal("the local image was not removed after upload")
}
}
// A footfall count without a photo is a real visit and the number the customer
// pays for. Losing it over an optional field would be the wrong trade - the
// same rule the bridge already follows for a missing embedding.
func TestAFailedUploadStillQueuesTheVisit(t *testing.T) {
q := &fakeQueue{}
up := &stubUploader{err: errors.New("bucket unreachable")}
b := &Bridge{Queue: q, TopicPrefix: "bv/acme.store1", Uploader: up}
path := writeImage(t, t.TempDir(), "face.jpg", []byte("jpeg"))
if err := b.Handle(context.Background(), Event{
Type: "person.seen", CameraID: "entrance", TS: 1756_000_001,
Data: map[string]any{"identity_id": float64(7), "image_path": path},
}); err != nil {
t.Fatal(err)
}
if len(q.payloads) != 1 {
t.Fatalf("the visit was dropped because its photo failed")
}
if _, ok := q.payloads[0]["image_key"]; ok {
t.Fatal("a key was attached despite the upload failing")
}
// Removed anyway: keeping it for a retry means an outbox that grows for as
// long as the failure lasts.
if _, err := os.Stat(path); !os.IsNotExist(err) {
t.Fatal("the local image survived a failed upload")
}
}
func TestNoUploaderMeansNoImageAndNoLeftovers(t *testing.T) {
q := &fakeQueue{}
b := &Bridge{Queue: q, TopicPrefix: "bv/acme.store1"} // images off
path := writeImage(t, t.TempDir(), "face.jpg", []byte("jpeg"))
if err := b.Handle(context.Background(), Event{
Type: "person.new", CameraID: "entrance", TS: 1756_000_002,
Data: map[string]any{"identity_id": float64(7), "image_path": path},
}); err != nil {
t.Fatal(err)
}
if _, ok := q.payloads[0]["image_key"]; ok {
t.Fatal("an image key appeared with no uploader configured")
}
if _, err := os.Stat(path); !os.IsNotExist(err) {
t.Fatal("the local image was left on disk")
}
}