Files
Behavision/server/internal/api/handlers_auth.go
Suriyakumarvijayanayagam dad04e8cda Behavision: face recognition for retail, edge to head office
Five components that ship as one product:

- behavision/  the recognition engine. RTSP ingest, YuNet detection, IoU
               tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
               FastAPI dashboard. Identity is decided once per TRACK from an
               average of at least three embeddings, never per frame.
- agent/       the Go edge agent: supervises the engine, holds a durable
               spool, and drains it to MQTT. Nothing is acked before the
               broker confirms.
- desktop/     the shop PC application (Wails + React + tray).
- server/      the cloud API, MQTT consumer, reports and assistant.
- web/         platform.loyaly.ai, the head-office app, embedded in the
               server binary.

The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.

CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
2026-09-04 11:14:18 +05:30

207 lines
6.1 KiB
Go

package api
import (
"net/http"
"time"
"github.com/loyaly/behavision-server/internal/auth"
)
func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
var body struct {
Email string `json:"email"`
Password string `json:"password"`
Device string `json:"device"`
}
if err := decode(w, r, &body); err != nil {
badRequest(w, err.Error())
return
}
email := auth.NormalizeEmail(body.Email)
// Two limiters, at very different sizes. Per-account stops somebody working
// through a password list against one known address; per-IP is a much
// looser backstop against spraying one guess across many addresses, because
// an entire shop shares a single NAT address and a tight limit there locks
// out the whole staff when one person mistypes.
perUser, perIP := s.throttles()
ipKey, userKey := clientIP(r), email
if !perIP.Allow(ipKey) || !perUser.Allow(userKey) {
writeErr(w, http.StatusTooManyRequests, "too_many_attempts",
"Too many sign-in attempts. Wait a few minutes and try again.")
return
}
rec, err := s.Store.UserByEmail(r.Context(), email)
if err != nil {
s.serverError(w, "login lookup", err)
return
}
// Verify unconditionally, against a dummy hash when the address is unknown.
// Returning early on "no such user" makes login response time a membership
// oracle for your customer's staff directory.
hash := rec.PasswordHash
if !rec.Found || !rec.Active || hash == "" {
hash = auth.DummyHash
}
ok := auth.VerifyPassword(hash, body.Password)
if !ok || !rec.Found || !rec.Active {
perIP.Fail(ipKey)
perUser.Fail(userKey)
// One message for every failure. "No such account" and "wrong password"
// are the same answer to anyone who is not already the account holder.
writeErr(w, http.StatusUnauthorized, "bad_credentials",
"Email or password is incorrect.")
return
}
// Cleared on success, so one forgotten password in the morning does not
// lock a shop out at lunchtime.
perIP.Reset(ipKey)
perUser.Reset(userKey)
sess, err := s.mint(r, rec, body.Device)
if err != nil {
s.serverError(w, "create session", err)
return
}
if err := s.Store.TouchUserLogin(r.Context(), rec.ID); err != nil {
// Not fatal. Failing a successful login because a bookkeeping column
// would not update locks people out for nothing.
s.logf("WARN could not record last_login for %s: %v", rec.ID, err)
}
s.Store.Audit(r.Context(), AuditEntry{
ClientID: rec.ClientID, ActorID: rec.ID, ActorKind: "user",
Action: "auth.login", Entity: "session",
Detail: map[string]any{"device": trim(body.Device)},
})
writeJSON(w, http.StatusOK, sess)
}
func (s *Server) mint(r *http.Request, rec UserRecord, device string) (Session, error) {
access, err := auth.NewToken()
if err != nil {
return Session{}, err
}
refresh, err := auth.NewToken()
if err != nil {
return Session{}, err
}
now := s.now()
ns := NewSession{
UserID: rec.ID,
ClientID: rec.ClientID,
AccessHash: access.Hash,
RefreshHash: refresh.Hash,
AccessExpiry: now.Add(auth.AccessTTL),
RefreshExp: now.Add(auth.RefreshTTL),
Device: clip(trim(device), 120),
}
if err := s.Store.CreateSession(r.Context(), ns); err != nil {
return Session{}, err
}
return Session{
Token: access.Plain,
RefreshToken: refresh.Plain,
ExpiresAt: ns.AccessExpiry.UTC().Format(time.RFC3339),
User: User{
ID: rec.ID, Email: rec.Email, FullName: rec.FullName,
Role: rec.Role, ClientID: rec.ClientID, Client: rec.ClientName,
},
}, nil
}
// handleRefresh swaps a refresh token for a new pair.
//
// The old refresh token is invalidated in the same statement that issues the
// new one. Leaving it usable would mean a token copied off a resold shop PC
// keeps working forever alongside the real one.
func (s *Server) handleRefresh(w http.ResponseWriter, r *http.Request) {
var body struct {
RefreshToken string `json:"refresh_token"`
Device string `json:"device"`
}
if err := decode(w, r, &body); err != nil {
badRequest(w, err.Error())
return
}
if trim(body.RefreshToken) == "" {
badRequest(w, "refresh_token is required")
return
}
p, expires, err := s.Store.SessionByRefresh(r.Context(),
auth.HashToken(body.RefreshToken))
if err != nil {
unauthorized(w, "Please sign in again.")
return
}
if s.now().After(expires) {
unauthorized(w, "Please sign in again.")
return
}
access, err := auth.NewToken()
if err != nil {
s.serverError(w, "refresh mint", err)
return
}
refresh, err := auth.NewToken()
if err != nil {
s.serverError(w, "refresh mint", err)
return
}
now := s.now()
ns := NewSession{
UserID: p.UserID,
ClientID: p.ClientID,
AccessHash: access.Hash,
RefreshHash: refresh.Hash,
AccessExpiry: now.Add(auth.AccessTTL),
// The refresh window slides. A shop PC that is used every day never has
// to be logged in again; one left in a cupboard for two months does.
RefreshExp: now.Add(auth.RefreshTTL),
Device: clip(trim(body.Device), 120),
}
if err := s.Store.RotateSession(r.Context(), p.SessionID, ns); err != nil {
s.serverError(w, "rotate session", err)
return
}
writeJSON(w, http.StatusOK, Session{
Token: access.Plain,
RefreshToken: refresh.Plain,
ExpiresAt: ns.AccessExpiry.UTC().Format(time.RFC3339),
User: User{
ID: p.UserID, Email: p.Email, FullName: p.FullName,
Role: p.Role, ClientID: p.ClientID, Client: p.ClientName,
},
})
}
func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request) {
p := PrincipalFrom(r.Context())
if err := s.Store.RevokeSession(r.Context(), p.SessionID); err != nil {
s.serverError(w, "revoke session", err)
return
}
s.Store.Audit(r.Context(), AuditEntry{
ClientID: p.ClientID, ActorID: p.UserID, ActorKind: "user",
Action: "auth.logout", Entity: "session", EntityID: p.SessionID,
})
w.WriteHeader(http.StatusNoContent)
}
func (s *Server) handleMe(w http.ResponseWriter, r *http.Request) {
p := PrincipalFrom(r.Context())
writeJSON(w, http.StatusOK, User{
ID: p.UserID, Email: p.Email, FullName: p.FullName,
Role: p.Role, ClientID: p.ClientID, Client: p.ClientName,
})
}
func clip(s string, n int) string {
if len(s) > n {
return s[:n]
}
return s
}