StreamURL built http://user:pass@127.0.0.1:8010/api/cameras/<id>/ stream.mjpeg and handed it to an <img>, with a comment saying the credentials were inline "so an <img> tag can load it". It cannot. Chromium strips credentials from subresource URLs and has since M59, and WebView2 is Chromium - so on the one platform this product ships to, every camera tile on a shop counter was a broken image. Measured against a running engine: the app's Go-side calls returned stats and people while an <img> on that very URL failed, and curl proved the URL answered 200. The engine was never the problem. The password now stays on this side of the process boundary. A loopback relay attaches Basic auth and streams the engine's bytes back unchanged - the same reasoning Shot.jsx already follows at head office, where an <img> equally cannot carry a session. What the relay is careful about, since it is a door onto the biometric API with a credential attached: - loopback only, on a port the OS picks; a fixed one would collide with whatever else a shop PC runs and read as "the cameras broke" - a per-run random token in the path. The engine's own credential exists so the live face feed is never served open; an unauthenticated relay would hand that feed to any other process on the PC. Compared in constant time, and a wrong one is 404, not 403 - an allow-list of stream.mjpeg and frame.jpg. Holding the token does not reach the identity list, the gallery, or erasure - camera ids validated, not interpolated - every chunk flushed; a buffered MJPEG stream is a tile that never paints, which looks identical to the bug being fixed Two of those were written after a test failed, not before: - `..` MATCHES the id pattern, because real camera ids contain dots. `/api/cameras/../stream.mjpeg` is not the endpoint anyone intended. The id can never hold a slash, so `.` and `..` are the whole remaining traversal surface and are now refused by name. - the serve goroutine read p.srv off the struct while stop() was nilling it, so a quick start/stop dereferenced nil and took the process down. Captured before launching now. FrameURL is deliberately not added. No screen asks for a still, and a bound method nothing calls is the same defect as a capability the UI cannot reach, only pointing the other way. Verified: nine unit tests, plus a live test against the real engine and the real office camera - two MJPEG frames, 90,793 bytes, no credential in the URL. Windows and darwin both build; vet clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pcn9asw19WGBfCEaHvNug6
68 lines
2.0 KiB
Go
68 lines
2.0 KiB
Go
// Command behavision-desktop is the store-facing application: a tray icon, a
|
|
// window, and the supervisor for the recognition engine.
|
|
//
|
|
// It is one process rather than three because the tray, the window and the
|
|
// supervisor all need the same state, and because a user who quits the tray
|
|
// expects recognition to stop. It is deliberately NOT a Windows service: a
|
|
// service runs in session 0 and cannot draw a tray icon, and spawning a child
|
|
// process needs no elevation while controlling a service does.
|
|
package main
|
|
|
|
import (
|
|
"context"
|
|
"embed"
|
|
"log"
|
|
|
|
"github.com/wailsapp/wails/v2"
|
|
"github.com/wailsapp/wails/v2/pkg/options"
|
|
"github.com/wailsapp/wails/v2/pkg/options/assetserver"
|
|
"github.com/wailsapp/wails/v2/pkg/options/windows"
|
|
"github.com/wailsapp/wails/v2/pkg/runtime"
|
|
)
|
|
|
|
//go:embed all:frontend/dist
|
|
var assets embed.FS
|
|
|
|
func main() {
|
|
app := NewApp()
|
|
tray := newTray(app)
|
|
|
|
err := wails.Run(&options.App{
|
|
Title: "Behavision",
|
|
Width: 1280,
|
|
Height: 820,
|
|
// Small enough to still be usable on a cramped shop-counter monitor.
|
|
MinWidth: 1024,
|
|
MinHeight: 640,
|
|
AssetServer: &assetserver.Options{Assets: assets},
|
|
// Closing the window hides it rather than quitting: the engine must
|
|
// keep recognising after a shop assistant clicks the X, and the tray
|
|
// is where they get the window back.
|
|
HideWindowOnClose: true,
|
|
OnStartup: func(ctx context.Context) {
|
|
app.startup(ctx)
|
|
tray.start(ctx)
|
|
},
|
|
OnBeforeClose: func(ctx context.Context) bool {
|
|
runtime.Hide(ctx)
|
|
return true // prevent the close
|
|
},
|
|
OnShutdown: func(ctx context.Context) {
|
|
tray.stop()
|
|
app.proxy.stop()
|
|
app.StopEngine()
|
|
},
|
|
Bind: []any{app},
|
|
Windows: &windows.Options{
|
|
WebviewIsTransparent: false,
|
|
WindowIsTranslucent: false,
|
|
// A shop PC is not a developer machine; a stray right-click that
|
|
// opens devtools looks like the software is broken.
|
|
DisableWindowIcon: false,
|
|
},
|
|
})
|
|
if err != nil {
|
|
log.Fatalf("behavision-desktop: %v", err)
|
|
}
|
|
}
|