Two trigger paths into one recognition function
A physical button on the enclosure and a remote API endpoint both call the same internal routine. The local path needs no network at all, so a dropped connection degrades the system to exactly what it was before — a door you walk up to — rather than to a locked box.
Recognition on-device, at a 0.40 distance threshold
128-dimensional encodings compared locally rather than sent to a hosted model. That removes network round-trip from the critical path, removes a privacy problem, and removes an availability dependency. The threshold is deliberately tight — the consequences of the two error directions are not symmetric.
Enrollment averages several images into one encoding
Rather than storing every enrollment photo and matching against all of them, the encodings are averaged into a single vector per person. It costs some per-image precision and buys robustness across the lighting the doorway actually sees.
MJPEG in a plain <img> tag for the live feed
WebRTC would have been lower latency and would also have required a signalling server, TURN fallback and a pile of client state. A multipart JPEG stream renders in an ordinary image tag with no client-side code at all. For deciding whether to open a door, the latency difference does not matter; the complexity difference does.
Auto-lock as a deadline watched by a background thread
The unlock handler sets an expiry timestamp and returns immediately; a separate thread re-engages the lock when the deadline passes. Sleeping inside the request would have held the response open for five seconds and, worse, would have left the door open permanently if the request died mid-sleep.