Files
Behavision/agent/pkg/config/credentials_test.go
Suriyakumarvijayanayagam dad04e8cda Behavision: face recognition for retail, edge to head office
Five components that ship as one product:

- behavision/  the recognition engine. RTSP ingest, YuNet detection, IoU
               tracking, ArcFace embeddings, a FAISS/SQLite gallery, and a
               FastAPI dashboard. Identity is decided once per TRACK from an
               average of at least three embeddings, never per frame.
- agent/       the Go edge agent: supervises the engine, holds a durable
               spool, and drains it to MQTT. Nothing is acked before the
               broker confirms.
- desktop/     the shop PC application (Wails + React + tray).
- server/      the cloud API, MQTT consumer, reports and assistant.
- web/         platform.loyaly.ai, the head-office app, embedded in the
               server binary.

The gallery stores 512-float embeddings and timestamps - no images unless
`app.store_faces` is switched on. Those embeddings are biometric personal
data under GDPR and India's DPDP: template inversion reconstructs a
recognisable face from an ArcFace vector, so data/behavision.db is treated
as a biometric database and DELETE /api/visitors/{id} is a real erasure.

CLAUDE.md carries the reasoning behind every non-obvious decision here,
including the ones that were measured and the ones that were wrong first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
2026-09-04 11:14:18 +05:30

59 lines
1.9 KiB
Go

package config
import (
"os"
"path/filepath"
"testing"
)
func writeCreds(t *testing.T, body string) string {
t.Helper()
p := filepath.Join(t.TempDir(), "api_credentials.txt")
if err := os.WriteFile(p, []byte(body), 0o600); err != nil {
t.Fatal(err)
}
return p
}
// The shape the engine actually writes. This is the whole point of the file:
// on a stock install it is the ONLY place the credential exists.
func TestItReadsWhatTheEngineWrites(t *testing.T) {
p := writeCreds(t, "username=behavision\npassword=qQTGFpetJ5Py613XwcbARQ\n")
u, pw := EngineCredentials(p)
if u != "behavision" || pw != "qQTGFpetJ5Py613XwcbARQ" {
t.Fatalf("got %q / %q", u, pw)
}
}
func TestColonSeparatedIsReadToo(t *testing.T) {
p := writeCreds(t, " username: behavision\n password: hunter2\n")
if u, pw := EngineCredentials(p); u != "behavision" || pw != "hunter2" {
t.Fatalf("got %q / %q", u, pw)
}
}
// A missing file is normal - an operator who set BEHAVISION_API_USER has none.
func TestAMissingFileIsNotAnError(t *testing.T) {
if u, pw := EngineCredentials("/nope/nothing.txt"); u != "" || pw != "" {
t.Fatalf("got %q / %q", u, pw)
}
}
// Configured values win. Reading the file over an operator's own credential
// would silently ignore what they set.
func TestAConfiguredCredentialIsNotOverwritten(t *testing.T) {
p := writeCreds(t, "username=generated\npassword=generated\n")
c := Config{APIUser: "mine", APIPassword: "secret"}.WithEngineCredentials(p)
if c.APIUser != "mine" || c.APIPassword != "secret" {
t.Fatalf("configured credential was replaced: %q / %q", c.APIUser, c.APIPassword)
}
}
func TestAnEmptyCredentialIsFilledIn(t *testing.T) {
p := writeCreds(t, "username=behavision\npassword=abc\n")
c := Config{}.WithEngineCredentials(p)
if c.APIUser != "behavision" || c.APIPassword != "abc" {
t.Fatalf("not filled in: %q / %q", c.APIUser, c.APIPassword)
}
}