Every id in the schema is a uuid and stays one. What was wrong was putting one in front of a person: RecordVisit named every new customer 'Visitor ' || left(id::text, 8), so the arrivals feed, the shop PC and the mobile app all read "Visitor 3446ec35" - the string a shop assistant reads to a colleague and types into a search box. label is a stored column staff can overwrite and SearchVisitors matches on, so formatting around it in a front end would have left the data wrong on three surfaces. Migration 012 adds a per-client visitors.number, taken from a counter on clients with UPDATE ... RETURNING inside the visit transaction. Per client rather than global: a global sequence would tell any customer who signs up how many people the whole platform has ever seen, from their own first visitor number. The backfill numbers existing rows by first_seen_at and relabels only the eight-hex pattern the old statement produced, so a human-typed name is never overwritten. Three of the four things anyone addresses by URL already had a human name and the API simply refused it - a site has a slug, a camera has the id the engine knows it by. refs.go accepts either form anywhere an id is taken; a uuid resolves with no lookup, so every URL a client already stored keeps working. - An ambiguous camera name resolves to nothing, never to a guess: two shops may each have an "Office1" and acting on the first row would edit the wrong shop's camera. - 404 on a path, 400 on a query filter. /api/visits answered fine and it was the filter that was wrong. - site and site_id are both accepted everywhere now. They differed per endpoint, and an unknown query parameter is silently ignored, so getting it the wrong way round returned the whole estate. - The search matches V-13, which is what the product now shows. Two bugs found by running it rather than testing it: - 'Visitor ' || $2::text beside number = $2 makes Postgres deduce two types for one parameter and refuse the insert. It compiled and passed every in-memory test; the first real database rejected it, along with the existing face tests that share the path. - The fallback avatar said "V1" for Visitor 13, Visitor 10 and Visitor 15 alike, and read as the V-1 reference for a fourth person. It shows the number now. The prop is customerRef, not ref - React reserves that name and it would never have arrived. Verified on the live database and through the running API: 13 hex labels became Visitor 1-13 in first-seen order, two typed names left alone, and the same customer reachable by uuid, V-13 and 13. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
138 lines
5.2 KiB
Go
138 lines
5.2 KiB
Go
package store
|
|
|
|
import (
|
|
"context"
|
|
"time"
|
|
|
|
"github.com/loyaly/behavision-server/internal/api"
|
|
)
|
|
|
|
// arrivalColumns is shared by both directions of the query below so the two
|
|
// cannot drift apart - a column present in one and missing from the other would
|
|
// mean the first poll of a feed and every poll after it returned different
|
|
// shapes, which is the kind of bug that only shows up under load.
|
|
const arrivalColumns = `
|
|
vi.id::text, vi.seq, vi.occurred_at, vi.site_id::text, si.name, vi.camera_id,
|
|
vi.is_new_visitor, vi.similarity, vi.quality, vi.attributes, vi.image_key,
|
|
COALESCE(vi.visitor_id::text, ''),
|
|
COALESCE(vs.number, 0),
|
|
COALESCE(vs.label, ''),
|
|
COALESCE(p.full_name, '')`
|
|
|
|
const arrivalFrom = `
|
|
FROM visits vi
|
|
JOIN sites si ON si.id = vi.site_id
|
|
-- LEFT, not INNER, three times over. A visit with no visitor_id is a site
|
|
-- reporting footfall without templates; an erased customer has their
|
|
-- visitor row flagged deleted. Both are real arrivals and an inner join
|
|
-- would silently drop them, making the feed disagree with the footfall
|
|
-- report about how many people came in.
|
|
LEFT JOIN visitors vs
|
|
ON vs.id = vi.visitor_id AND vs.deleted_at IS NULL
|
|
LEFT JOIN visitor_profiles p
|
|
ON p.visitor_id = vi.visitor_id AND p.client_id = vi.client_id
|
|
WHERE vi.client_id = $1
|
|
AND ($2 = '' OR vi.site_id = $2::uuid)`
|
|
|
|
// Arrivals reads a window of the live feed, oldest first.
|
|
//
|
|
// Ordered by `seq` - the server-assigned position - and never by occurred_at.
|
|
// That is the whole correctness argument for this endpoint and it is not
|
|
// obvious, so:
|
|
//
|
|
// - occurred_at is the CAMERA's clock. Four people through one door share it
|
|
// to the microsecond, so it cannot order them; and a site that was offline
|
|
// for a day floods in carrying yesterday's timestamps, which a reader whose
|
|
// cursor has passed them would skip entirely.
|
|
// - A (occurred_at, id) tie-break does not save it either, because id is a
|
|
// random uuid: a row that COMMITS after the reader moved its cursor but
|
|
// carries a lower uuid sorts behind that cursor and is never delivered.
|
|
// Measured live before this was fixed - four simultaneous visits, two
|
|
// delivered, and nothing downstream able to tell.
|
|
//
|
|
// So the feed is ordered by when the server LEARNED of a visit. Each row still
|
|
// carries occurred_at for display; seq is only ever a position.
|
|
//
|
|
// This depends on visits being inserted one at a time, which the MQTT consumer
|
|
// guarantees with SetOrderMatters(true) - a single ordered handler goroutine,
|
|
// so seq order is commit order. Running two server instances against one
|
|
// database would break that assumption, and the fix then is a commit-ordered
|
|
// cursor, not a bigger sequence.
|
|
//
|
|
// Keyset, never OFFSET: rows arrive into this table continuously, so an offset
|
|
// shifts under the caller between polls and a feed built on it both repeats and
|
|
// skips people.
|
|
func (s *Store) Arrivals(ctx context.Context, q api.ArrivalQuery) ([]api.Arrival, error) {
|
|
var sql string
|
|
var args []any
|
|
|
|
switch {
|
|
case q.AfterSeq != nil:
|
|
sql = `SELECT ` + arrivalColumns + arrivalFrom + `
|
|
AND vi.seq > $3
|
|
ORDER BY vi.seq ASC
|
|
LIMIT $4`
|
|
args = []any{q.ClientID, q.SiteID, *q.AfterSeq, q.Limit}
|
|
|
|
case q.Since != nil:
|
|
// "Everything I have not been told about since this instant." Resolved
|
|
// against received_at, not occurred_at, so it means the same thing as
|
|
// the cursor it turns into on the next poll - a caller must not get a
|
|
// different feed depending on which of the two it started with.
|
|
sql = `SELECT ` + arrivalColumns + arrivalFrom + `
|
|
AND vi.seq > COALESCE(
|
|
(SELECT max(v2.seq) FROM visits v2
|
|
WHERE v2.client_id = $1 AND v2.received_at < $3), 0)
|
|
ORDER BY vi.seq ASC
|
|
LIMIT $4`
|
|
args = []any{q.ClientID, q.SiteID, *q.Since, q.Limit}
|
|
|
|
default:
|
|
// No cursor: an app that has just opened. It wants the last few
|
|
// arrivals, not the first few ever recorded, so take the newest rows
|
|
// and reverse them - the response is still ascending, so the caller's
|
|
// cursor handling is identical on the first poll and every one after.
|
|
sql = `SELECT * FROM (
|
|
SELECT ` + arrivalColumns + arrivalFrom + `
|
|
ORDER BY vi.seq DESC
|
|
LIMIT $3
|
|
) t ORDER BY t.seq ASC`
|
|
args = []any{q.ClientID, q.SiteID, q.Limit}
|
|
}
|
|
|
|
rows, err := s.pool.Query(ctx, sql, args...)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
defer rows.Close()
|
|
|
|
var out []api.Arrival
|
|
for rows.Next() {
|
|
var a api.Arrival
|
|
var at time.Time
|
|
var sim, qual *float64
|
|
var imageKey string
|
|
var number int64
|
|
if err := rows.Scan(&a.VisitID, &a.Seq, &at, &a.SiteID, &a.Site, &a.CameraID,
|
|
&a.IsNew, &sim, &qual, &a.Attributes, &imageKey,
|
|
&a.VisitorID, &number, &a.Label, &a.Name); err != nil {
|
|
return nil, err
|
|
}
|
|
a.VisitorRef = api.VisitorRef(number)
|
|
a.OccurredAt = at.UTC().Format(time.RFC3339Nano)
|
|
if sim != nil {
|
|
a.Similarity = *sim
|
|
}
|
|
if qual != nil {
|
|
a.Quality = *qual
|
|
}
|
|
// The store never presigns. It has no bucket and no idea whether this
|
|
// caller is allowed to look, and a query that mints credentials is one
|
|
// refactor away from doing it on a path that never checked. ImageKey
|
|
// is json:"-", so a handler that forgets to swap it leaks nothing.
|
|
a.ImageKey = imageKey
|
|
out = append(out, a)
|
|
}
|
|
return out, rows.Err()
|
|
}
|