Files
Behavision/server/internal/store/api_snapshots.go
Suriyakumarvijayanayagam e0ceb14589 Camera pictures without an object-storage bucket
Head office shows a camera's latest frame rather than live video, for a
reason that has not changed: the engine serves MJPEG on 127.0.0.1 on a PC
behind a shop's router with no inbound route, and relaying it needs
WebRTC/TURN. Pointing a browser straight at the shop PC is not the escape
either - the engine's API is Basic-authenticated with a credential it
generates locally and never sends anywhere, and shipping that to the
cloud so a web page could use it would put the key to the biometric API
and the live face feed in the server's database.

But that picture only worked if you had an S3 bucket. Without one,
attachSnapshots reported "This system is not storing images" for every
camera forever - on the two screens whose whole job is to show the
camera. Making them picture-led turned a missing feature into a wall of
empty tiles, on every local install and any self-hosted customer who does
not want a bucket.

migrations/009 adds camera_snapshots and the agent falls back to
PUT /api/agent/cameras/{camera}/snapshot when the presigned route answers
images_disabled - chosen by sentinel, never by matching the message, since
it picks between two routes. One row per camera is what makes this safe in
the database when face images are not: the key IS the camera, so storage
is (cameras x ~100 KB) and does not grow with footfall.

The read is session-authenticated rather than a signed link, which an
<img> cannot use - hence Shot.jsx and useAuthedImage, keyed on the URL
string rather than the snapshot object so a poll does not re-fetch 90 KB
per camera every few seconds, and revoking the object URL on cleanup.

Verified against the real office camera with no bucket configured: 90,587
bytes stored in Postgres, served as image/jpeg to a signed-in user, 401
without a session, rendered on both the Cameras and Shops cards.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
2026-09-04 12:53:18 +05:30

85 lines
2.8 KiB
Go

package store
import (
"context"
"errors"
"fmt"
"time"
"github.com/jackc/pgx/v5"
)
// ErrNoSnapshot means this camera has no stored picture. It is an ordinary
// state - a camera added a minute ago has none - so callers report it as
// absence rather than as a failure.
var ErrNoSnapshot = errors.New("no snapshot for this camera")
// PutCameraSnapshot stores the latest frame from one of a site's cameras.
//
// The camera is resolved by (site_id, camera_id) IN THE INSERT, so an agent
// physically cannot store a picture against another site's camera even if it
// sends one - the same rule as every other agent-authenticated write here.
// `camera_id` is what the ENGINE knows the camera by, because that is the only
// name the shop PC has.
func (s *Store) PutCameraSnapshot(ctx context.Context,
clientID, siteID, cameraID string, jpeg []byte) error {
tx, err := s.pool.Begin(ctx)
if err != nil {
return err
}
defer func() { _ = tx.Rollback(context.WithoutCancel(ctx)) }()
var id string
err = tx.QueryRow(ctx, `
SELECT id::text FROM site_cameras
WHERE site_id = $1::uuid AND camera_id = $2 AND deleted_at IS NULL`,
siteID, cameraID).Scan(&id)
if errors.Is(err, pgx.ErrNoRows) {
// Head office has not been told about this camera yet, or it was
// removed. Neither is an error the agent can act on: the next sync
// adopts it and the snapshot after that lands.
return ErrNoSnapshot
}
if err != nil {
return err
}
if _, err := tx.Exec(ctx, `
INSERT INTO camera_snapshots (camera_id, client_id, site_id, image, bytes, captured_at)
VALUES ($1::uuid, $2::uuid, $3::uuid, $4, $5, now())
ON CONFLICT (camera_id) DO UPDATE
SET image = EXCLUDED.image, bytes = EXCLUDED.bytes,
captured_at = EXCLUDED.captured_at`,
id, clientID, siteID, jpeg, len(jpeg)); err != nil {
return fmt.Errorf("store snapshot: %w", err)
}
// snapshot_at is what tells the camera list a picture exists at all, and it
// is written in the SAME transaction as the bytes. Set apart, a camera
// could advertise a picture that is not there - which renders as a broken
// image on the one screen whose job is to show the camera.
if _, err := tx.Exec(ctx, `
UPDATE site_cameras SET snapshot_at = now() WHERE id = $1::uuid`,
id); err != nil {
return err
}
return tx.Commit(ctx)
}
// CameraSnapshot returns a camera's stored picture, scoped to the tenant.
func (s *Store) CameraSnapshot(ctx context.Context, clientID, cameraID string) (
[]byte, time.Time, error) {
var img []byte
var at time.Time
err := s.pool.QueryRow(ctx, `
SELECT image, captured_at FROM camera_snapshots
WHERE camera_id = $1::uuid AND client_id = $2::uuid`,
cameraID, clientID).Scan(&img, &at)
if errors.Is(err, pgx.ErrNoRows) {
return nil, time.Time{}, ErrNoSnapshot
}
return img, at, err
}