Skip to content

v0.22.2 — One history row per person, and a script-injection fix

Choose a tag to compare

@NerdyHank NerdyHank released this 07 Sep 06:34
· 36 commits to main since this release
  • Security: a person's name could execute JavaScript in the web UI. Captions were
    spliced into a single-quoted JS string inside an onclick attribute. The HTML escaper
    does not escape apostrophes — and even if it did, the browser decodes them before the JS
    parser runs — so a name like O'Brien, or a camera name from Frigate containing one,
    terminated the string and ran arbitrary script. It affected four places: the history
    card, the unknown queue (twice, fed by Frigate camera names) and the person cards. All of
    them now pass the value through a data- attribute, where escaping is correct for the
    context. Found while reviewing this release; it predates it.
  • The history shows one row per event and named person again (unknown faces keep one row
    each — several strangers in a single frame all carry that label, and merging them would
    swap their pictures against each other). It is titled "What FaceID
    reported", but only the first match per person and event is ever reported — the
    announced set suppresses the rest. Every further row therefore claimed a notification
    that never happened, and pushed genuine older entries out: 27 such rows out of 200 slots
    on the reference instance, so the history reached 13% less far back than it should.
  • Later matches are not discarded, they improve the row. Checking the stored crops
    first showed why that matters: all ten sampled duplicate pairs held different pictures,
    sometimes drastically so — 8 KB against 94 KB of the same person, a distant crop against
    a close one. Those later pictures are exactly what makes a wrong recognition checkable.
    So a later match now improves the existing row instead of adding one: it replaces the
    picture when its score is higher, and the card shows "best view 0.687" beside the
    reported score. Independently of that, the first match that is actually published takes
    over the row's score and timestamp even when it scores lower — it is the one somebody
    received, and the card is headed "What FaceID reported".
  • Picture and embedding are always replaced together. Keeping them apart would let the
    "was wrong" analysis run on a different face than the row displays.