A mobile developer builds against this file, so a gap in it is a gap in
the app. Checked route by route against the mux: nineteen routes had no
entry at all, including the ENTIRE platform-admin surface, adding and
checking cameras, issuing shop-PC installation codes, the assistant, and
the face bytes endpoint. Most of what was documented had no response
shape - a client had to guess the field names for shops, cameras, team,
customers, history and both reports.
Every shape here is now taken from the server's own types, and the
uncertain claims were checked against the handlers rather than written
from memory: check requests return 202, history is newest first, the
visitor list is most-recently-seen first and excludes the erased, an
admin slug is derived from the company name when omitted.
Restructured by audience, because "who may call this" was scattered:
- three callers named up front - merchant, platform admin, shop PC -
and what each one signs in with and sees
- the three merchant roles and what each adds, taken from
CanWriteProfiles / CanManageSites rather than paraphrased
- a permission matrix: every route and the least role that may call it
- quick starts for the three clients that will actually be written:
a floor app for staff, a console for owners, and admin
- /api/agent/* listed once as "not for you", so nobody wonders
The prose that explained WHY - refresh rules, the cursor, photos as data
not errors, the report arithmetic - is kept; that is the part a client
developer cannot get from the code.
Also recorded plainly: the admin API is two endpoints. There is no way
to suspend a company, delete one, or reset an owner's password over
HTTP. Written down rather than left for someone to discover.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
68 lines
2.4 KiB
Plaintext
68 lines
2.4 KiB
Plaintext
__pycache__/
|
|
*.pyc
|
|
.venv/
|
|
venv/
|
|
.pytest_cache/
|
|
*.log
|
|
# macOS Finder metadata and rotated engine logs.
|
|
.DS_Store
|
|
*.log.[0-9]
|
|
node_modules/
|
|
|
|
# --------------------------------------------------------------------------
|
|
# Everything below is ANCHORED with a leading slash on purpose.
|
|
#
|
|
# An unanchored pattern matches at every level, and `spool/` therefore excluded
|
|
# `agent/pkg/spool/` - the durable queue, source code - so a fresh clone did not
|
|
# compile at all. Found by cloning the repository and building it, which is the
|
|
# only way this class of mistake is ever found. `data/` and `agent.json` have
|
|
# exactly the same shape and are anchored for the same reason.
|
|
# --------------------------------------------------------------------------
|
|
|
|
# Camera credentials. Copied between machines by hand, never committed.
|
|
/.env
|
|
|
|
# The engine's writable state: the biometric database, the camera list, logs.
|
|
/data/
|
|
|
|
# Downloaded models, ~200 MB, fetched by `setup-models`.
|
|
/models/*.onnx
|
|
/models/*.caffemodel
|
|
/models/*.prototxt
|
|
|
|
# run-local.sh's working directory: the built binary, the encryption key and
|
|
# the broker's password file. Nothing here belongs in a repository.
|
|
/.local/
|
|
|
|
# The agent's local state when BEHAVISION_DATA_DIR points at a checkout.
|
|
# agent.json holds this PC's broker password and its API token.
|
|
/agent.json
|
|
/spool/
|
|
|
|
# Build output. The Windows package is ~400 MB unpacked and is rebuilt from
|
|
# source by installer/build.ps1; the WebView2 bootstrapper is Microsoft's
|
|
# redistributable, fetched at build time rather than vendored into history.
|
|
/dist/
|
|
/build/
|
|
/desktop/build/bin/
|
|
/installer/vendor/
|
|
|
|
# NOT ignored, deliberately: server/internal/web/dist and
|
|
# desktop/frontend/dist. Both are `go:embed`ed at COMPILE time, so without them
|
|
# in the tree `go build ./...` fails on a fresh checkout - on a machine that may
|
|
# have no npm at all. They are ~200 KB and regenerating them is one command; a
|
|
# repository that does not compile is the more expensive problem.
|
|
|
|
# Backups of .env made when editing camera credentials.
|
|
/.env.bak-*
|
|
|
|
# Generated by the wails CLI on every dev run and build, not source.
|
|
# NOT /desktop/build/ as a whole: appicon.png, darwin/ and windows/ under it
|
|
# are the Wails project scaffolding (icon, Info.plist, manifest) that a
|
|
# reproducible Windows build needs. Only the compiled output is ignored.
|
|
/desktop/frontend/wailsjs/
|
|
/desktop/frontend/package.json.md5
|
|
|
|
# Left behind by `pip install .` of the engine (setuptools metadata), not source.
|
|
/behavision.egg-info/
|