Five components that ship as one product:
- behavision/ the recognition engine. RTSP ingest, YuNet detection, IoU
tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
FastAPI dashboard. Identity is decided once per TRACK from an
average of at least three embeddings, never per frame.
- agent/ the Go edge agent: supervises the engine, holds a durable
spool, and drains it to MQTT. Nothing is acked before the
broker confirms.
- desktop/ the shop PC application (Wails + React + tray).
- server/ the cloud API, MQTT consumer, reports and assistant.
- web/ platform.loyaly.ai, the head-office app, embedded in the
server binary.
The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.
CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
59 lines
1.9 KiB
Go
59 lines
1.9 KiB
Go
package config
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
func writeCreds(t *testing.T, body string) string {
|
|
t.Helper()
|
|
p := filepath.Join(t.TempDir(), "api_credentials.txt")
|
|
if err := os.WriteFile(p, []byte(body), 0o600); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return p
|
|
}
|
|
|
|
// The shape the engine actually writes. This is the whole point of the file:
|
|
// on a stock install it is the ONLY place the credential exists.
|
|
func TestItReadsWhatTheEngineWrites(t *testing.T) {
|
|
p := writeCreds(t, "username=behavision\npassword=qQTGFpetJ5Py613XwcbARQ\n")
|
|
u, pw := EngineCredentials(p)
|
|
if u != "behavision" || pw != "qQTGFpetJ5Py613XwcbARQ" {
|
|
t.Fatalf("got %q / %q", u, pw)
|
|
}
|
|
}
|
|
|
|
func TestColonSeparatedIsReadToo(t *testing.T) {
|
|
p := writeCreds(t, " username: behavision\n password: hunter2\n")
|
|
if u, pw := EngineCredentials(p); u != "behavision" || pw != "hunter2" {
|
|
t.Fatalf("got %q / %q", u, pw)
|
|
}
|
|
}
|
|
|
|
// A missing file is normal - an operator who set BEHAVISION_API_USER has none.
|
|
func TestAMissingFileIsNotAnError(t *testing.T) {
|
|
if u, pw := EngineCredentials("/nope/nothing.txt"); u != "" || pw != "" {
|
|
t.Fatalf("got %q / %q", u, pw)
|
|
}
|
|
}
|
|
|
|
// Configured values win. Reading the file over an operator's own credential
|
|
// would silently ignore what they set.
|
|
func TestAConfiguredCredentialIsNotOverwritten(t *testing.T) {
|
|
p := writeCreds(t, "username=generated\npassword=generated\n")
|
|
c := Config{APIUser: "mine", APIPassword: "secret"}.WithEngineCredentials(p)
|
|
if c.APIUser != "mine" || c.APIPassword != "secret" {
|
|
t.Fatalf("configured credential was replaced: %q / %q", c.APIUser, c.APIPassword)
|
|
}
|
|
}
|
|
|
|
func TestAnEmptyCredentialIsFilledIn(t *testing.T) {
|
|
p := writeCreds(t, "username=behavision\npassword=abc\n")
|
|
c := Config{}.WithEngineCredentials(p)
|
|
if c.APIUser != "behavision" || c.APIPassword != "abc" {
|
|
t.Fatalf("not filled in: %q / %q", c.APIUser, c.APIPassword)
|
|
}
|
|
}
|