Files
Behavision/.gitignore
Suriyakumarvijayanayagam 5f83a1077d Enrolment hands out the broker CA, and now the PC keeps it
The server has always sent the broker's CA certificate in the enrolment
response, precisely so it never has to ship in an installer. Nothing on
the receiving end wrote it anywhere: the agent read the field under the
wrong name (ca_pem, the server says ca_cert) and the desktop app read it
correctly and dropped it. Every claimed PC therefore dialled
tls://mcp.loyaly.ai:8883 with the system trust store, the private CA
failed verification, and the agent reported 'the broker did not accept
this PC' - a TLS failure is indistinguishable from a refusal at that
layer. No real site could ever have published a visit.

Found by claiming this Mac as a real shop against production; fixed by
writing the CA to broker-ca.crt beside agent.json on both claim paths.
Verified: broker connected over TLS, camera pushed from head office,
engine streaming it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
2026-09-18 12:16:43 +05:30

69 lines
2.5 KiB
Plaintext

__pycache__/
*.pyc
.venv/
venv/
.pytest_cache/
*.log
# macOS Finder metadata and rotated engine logs.
.DS_Store
*.log.[0-9]
node_modules/
# --------------------------------------------------------------------------
# Everything below is ANCHORED with a leading slash on purpose.
#
# An unanchored pattern matches at every level, and `spool/` therefore excluded
# `agent/pkg/spool/` - the durable queue, source code - so a fresh clone did not
# compile at all. Found by cloning the repository and building it, which is the
# only way this class of mistake is ever found. `data/` and `agent.json` have
# exactly the same shape and are anchored for the same reason.
# --------------------------------------------------------------------------
# Camera credentials. Copied between machines by hand, never committed.
/.env
# The engine's writable state: the biometric database, the camera list, logs.
/data/
# Downloaded models, ~200 MB, fetched by `setup-models`.
/models/*.onnx
/models/*.caffemodel
/models/*.prototxt
# run-local.sh's working directory: the built binary, the encryption key and
# the broker's password file. Nothing here belongs in a repository.
/.local/
# The agent's local state when BEHAVISION_DATA_DIR points at a checkout.
# agent.json holds this PC's broker password and its API token.
/agent.json
/spool/
# Build output. The Windows package is ~400 MB unpacked and is rebuilt from
# source by installer/build.ps1; the WebView2 bootstrapper is Microsoft's
# redistributable, fetched at build time rather than vendored into history.
/dist/
/build/
/desktop/build/bin/
/installer/vendor/
# NOT ignored, deliberately: server/internal/web/dist and
# desktop/frontend/dist. Both are `go:embed`ed at COMPILE time, so without them
# in the tree `go build ./...` fails on a fresh checkout - on a machine that may
# have no npm at all. They are ~200 KB and regenerating them is one command; a
# repository that does not compile is the more expensive problem.
# Backups of .env made when editing camera credentials.
/.env.bak-*
# Generated by the wails CLI on every dev run and build, not source.
# NOT /desktop/build/ as a whole: appicon.png, darwin/ and windows/ under it
# are the Wails project scaffolding (icon, Info.plist, manifest) that a
# reproducible Windows build needs. Only the compiled output is ignored.
/desktop/frontend/wailsjs/
/desktop/frontend/package.json.md5
# Left behind by `pip install .` of the engine (setuptools metadata), not source.
/behavision.egg-info/
/.prod/