Five components that ship as one product:
- behavision/ the recognition engine. RTSP ingest, YuNet detection, IoU
tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
FastAPI dashboard. Identity is decided once per TRACK from an
average of at least three embeddings, never per frame.
- agent/ the Go edge agent: supervises the engine, holds a durable
spool, and drains it to MQTT. Nothing is acked before the
broker confirms.
- desktop/ the shop PC application (Wails + React + tray).
- server/ the cloud API, MQTT consumer, reports and assistant.
- web/ platform.loyaly.ai, the head-office app, embedded in the
server binary.
The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.
CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
203 lines
6.3 KiB
Go
203 lines
6.3 KiB
Go
package bridge
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"errors"
|
|
"io"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func writeImage(t *testing.T, dir, name string, body []byte) string {
|
|
t.Helper()
|
|
path := filepath.Join(dir, name)
|
|
if err := os.WriteFile(path, body, 0o600); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return path
|
|
}
|
|
|
|
// fakeServer plays both halves: the API that mints an upload URL and the
|
|
// bucket that receives the PUT.
|
|
func fakeServer(t *testing.T, uploaded *[]byte, sentACL *string) *httptest.Server {
|
|
t.Helper()
|
|
mux := http.NewServeMux()
|
|
srv := httptest.NewServer(mux)
|
|
t.Cleanup(srv.Close)
|
|
|
|
mux.HandleFunc("/api/agent/upload-url", func(w http.ResponseWriter, r *http.Request) {
|
|
if r.Header.Get("Authorization") != "Bearer agent-token" {
|
|
w.WriteHeader(http.StatusUnauthorized)
|
|
return
|
|
}
|
|
json.NewEncoder(w).Encode(uploadTarget{ //nolint:errcheck
|
|
Key: "behavision/acme/store1/2026/08/31/abc.jpg",
|
|
URL: srv.URL + "/bucket/abc.jpg",
|
|
Headers: map[string]string{
|
|
"x-amz-acl": "private", "content-type": "image/jpeg",
|
|
},
|
|
ExpiresIn: 600,
|
|
})
|
|
})
|
|
mux.HandleFunc("/bucket/", func(w http.ResponseWriter, r *http.Request) {
|
|
body, _ := io.ReadAll(r.Body)
|
|
*uploaded = body
|
|
*sentACL = r.Header.Get("x-amz-acl")
|
|
w.WriteHeader(http.StatusOK)
|
|
})
|
|
return srv
|
|
}
|
|
|
|
func TestUploadSendsTheFileAndTheSignedACL(t *testing.T) {
|
|
var got []byte
|
|
var acl string
|
|
srv := fakeServer(t, &got, &acl)
|
|
dir := t.TempDir()
|
|
path := writeImage(t, dir, "face.jpg", []byte("jpeg bytes"))
|
|
|
|
u := &SpacesUploader{BaseURL: srv.URL, Token: "agent-token"}
|
|
key, err := u.Upload(context.Background(), path)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if key != "behavision/acme/store1/2026/08/31/abc.jpg" {
|
|
t.Fatalf("key = %q", key)
|
|
}
|
|
if string(got) != "jpeg bytes" {
|
|
t.Fatalf("uploaded %q", got)
|
|
}
|
|
// The ACL is inside the server's signature. Sending it exactly as handed
|
|
// back is what keeps the shop PC from deciding to publish the image.
|
|
if acl != "private" {
|
|
t.Fatalf("x-amz-acl = %q, want private", acl)
|
|
}
|
|
}
|
|
|
|
func TestUnclaimedPCReportsImagesOffRatherThanFailing(t *testing.T) {
|
|
u := &SpacesUploader{} // no base url, no token: not enrolled yet
|
|
_, err := u.Upload(context.Background(), "/nonexistent")
|
|
if !errors.Is(err, ErrImagesOff) {
|
|
t.Fatalf("got %v, want ErrImagesOff", err)
|
|
}
|
|
}
|
|
|
|
func TestServerWithoutABucketIsNotARetryableFailure(t *testing.T) {
|
|
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
|
w.WriteHeader(http.StatusNotImplemented)
|
|
}))
|
|
defer srv.Close()
|
|
dir := t.TempDir()
|
|
path := writeImage(t, dir, "face.jpg", []byte("x"))
|
|
|
|
u := &SpacesUploader{BaseURL: srv.URL, Token: "agent-token"}
|
|
// 501 means "this deployment stores no images". The agent must stop trying
|
|
// rather than retry every visitor forever.
|
|
if _, err := u.Upload(context.Background(), path); !errors.Is(err, ErrImagesOff) {
|
|
t.Fatalf("got %v, want ErrImagesOff", err)
|
|
}
|
|
}
|
|
|
|
func TestOversizedFilesAreRefusedBeforeTheUplink(t *testing.T) {
|
|
dir := t.TempDir()
|
|
path := writeImage(t, dir, "huge.jpg", make([]byte, maxImageBytes+1))
|
|
u := &SpacesUploader{BaseURL: "http://example.invalid", Token: "t"}
|
|
// A shop uplink should not spend minutes discovering that something other
|
|
// than a face crop landed in the outbox.
|
|
if _, err := u.Upload(context.Background(), path); err == nil ||
|
|
!strings.Contains(err.Error(), "limit") {
|
|
t.Fatalf("got %v", err)
|
|
}
|
|
}
|
|
|
|
// -- the bridge's use of it -------------------------------------------------
|
|
|
|
type stubUploader struct {
|
|
key string
|
|
err error
|
|
sent []string
|
|
}
|
|
|
|
func (s *stubUploader) Upload(_ context.Context, path string) (string, error) {
|
|
s.sent = append(s.sent, path)
|
|
return s.key, s.err
|
|
}
|
|
|
|
func TestVisitCarriesTheImageKeyAndTheLocalFileIsRemoved(t *testing.T) {
|
|
q := &fakeQueue{}
|
|
up := &stubUploader{key: "behavision/acme/store1/2026/08/31/abc.jpg"}
|
|
b := &Bridge{Queue: q, TopicPrefix: "bv/acme.store1", Uploader: up}
|
|
path := writeImage(t, t.TempDir(), "face.jpg", []byte("jpeg"))
|
|
|
|
err := b.Handle(context.Background(), Event{
|
|
Type: "person.new", CameraID: "entrance", TS: 1756_000_000,
|
|
Data: map[string]any{"identity_id": float64(7), "image_path": path},
|
|
})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if len(q.payloads) != 1 {
|
|
t.Fatalf("expected one queued visit, got %d", len(q.payloads))
|
|
}
|
|
visit := q.payloads[0]
|
|
if visit["image_key"] != up.key {
|
|
t.Fatalf("image_key = %v", visit["image_key"])
|
|
}
|
|
// The outbox is transient. Leaving files behind means a shop PC slowly
|
|
// filling with pictures of its customers.
|
|
if _, err := os.Stat(path); !os.IsNotExist(err) {
|
|
t.Fatal("the local image was not removed after upload")
|
|
}
|
|
}
|
|
|
|
// A footfall count without a photo is a real visit and the number the customer
|
|
// pays for. Losing it over an optional field would be the wrong trade - the
|
|
// same rule the bridge already follows for a missing embedding.
|
|
func TestAFailedUploadStillQueuesTheVisit(t *testing.T) {
|
|
q := &fakeQueue{}
|
|
up := &stubUploader{err: errors.New("bucket unreachable")}
|
|
b := &Bridge{Queue: q, TopicPrefix: "bv/acme.store1", Uploader: up}
|
|
path := writeImage(t, t.TempDir(), "face.jpg", []byte("jpeg"))
|
|
|
|
if err := b.Handle(context.Background(), Event{
|
|
Type: "person.seen", CameraID: "entrance", TS: 1756_000_001,
|
|
Data: map[string]any{"identity_id": float64(7), "image_path": path},
|
|
}); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if len(q.payloads) != 1 {
|
|
t.Fatalf("the visit was dropped because its photo failed")
|
|
}
|
|
if _, ok := q.payloads[0]["image_key"]; ok {
|
|
t.Fatal("a key was attached despite the upload failing")
|
|
}
|
|
// Removed anyway: keeping it for a retry means an outbox that grows for as
|
|
// long as the failure lasts.
|
|
if _, err := os.Stat(path); !os.IsNotExist(err) {
|
|
t.Fatal("the local image survived a failed upload")
|
|
}
|
|
}
|
|
|
|
func TestNoUploaderMeansNoImageAndNoLeftovers(t *testing.T) {
|
|
q := &fakeQueue{}
|
|
b := &Bridge{Queue: q, TopicPrefix: "bv/acme.store1"} // images off
|
|
path := writeImage(t, t.TempDir(), "face.jpg", []byte("jpeg"))
|
|
|
|
if err := b.Handle(context.Background(), Event{
|
|
Type: "person.new", CameraID: "entrance", TS: 1756_000_002,
|
|
Data: map[string]any{"identity_id": float64(7), "image_path": path},
|
|
}); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if _, ok := q.payloads[0]["image_key"]; ok {
|
|
t.Fatal("an image key appeared with no uploader configured")
|
|
}
|
|
if _, err := os.Stat(path); !os.IsNotExist(err) {
|
|
t.Fatal("the local image was left on disk")
|
|
}
|
|
}
|