[FEAT] Add EmailService, RateLimitService, ReportService + integrations
Services: - EmailService: CSIRT notifications (24h/72h/30d), training alerts, welcome email - RateLimitService: File-based rate limiting for auth and AI endpoints - ReportService: Executive HTML report, CSV exports (risks/incidents/controls/assets) Integrations: - AuthController: Rate limiting on login (5/min, 20/h) and register (3/10min) - IncidentController: Email notifications on CSIRT milestones - AuditController: Executive report and CSV export endpoints - Router: 429 rate limit error handling, new audit export routes Database: - Migration 002: email_log table for notification tracking Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -6,6 +6,7 @@
|
||||
*/
|
||||
|
||||
require_once __DIR__ . '/BaseController.php';
|
||||
require_once APP_PATH . '/services/ReportService.php';
|
||||
|
||||
class AuditController extends BaseController
|
||||
{
|
||||
@@ -193,4 +194,48 @@ class AuditController extends BaseController
|
||||
|
||||
$this->jsonSuccess($mapping);
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /api/audit/executive-report
|
||||
* Genera report esecutivo HTML (stampabile come PDF)
|
||||
*/
|
||||
public function executiveReport(): void
|
||||
{
|
||||
$this->requireOrgRole(['org_admin', 'compliance_manager', 'board_member']);
|
||||
|
||||
$reportService = new ReportService();
|
||||
$html = $reportService->generateExecutiveReport($this->getCurrentOrgId());
|
||||
|
||||
header('Content-Type: text/html; charset=utf-8');
|
||||
echo $html;
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /api/audit/export/{type}
|
||||
* Esporta dati in CSV
|
||||
*/
|
||||
public function export(int $type = 0): void
|
||||
{
|
||||
$this->requireOrgRole(['org_admin', 'compliance_manager', 'auditor']);
|
||||
|
||||
$exportType = $_GET['type'] ?? 'controls';
|
||||
$orgId = $this->getCurrentOrgId();
|
||||
$reportService = new ReportService();
|
||||
|
||||
$csv = match ($exportType) {
|
||||
'risks' => $reportService->exportRisksCSV($orgId),
|
||||
'incidents' => $reportService->exportIncidentsCSV($orgId),
|
||||
'controls' => $reportService->exportControlsCSV($orgId),
|
||||
'assets' => $reportService->exportAssetsCSV($orgId),
|
||||
default => $reportService->exportControlsCSV($orgId),
|
||||
};
|
||||
|
||||
$filename = "nis2_{$exportType}_" . date('Y-m-d') . '.csv';
|
||||
|
||||
header('Content-Type: text/csv; charset=utf-8');
|
||||
header('Content-Disposition: attachment; filename="' . $filename . '"');
|
||||
echo $csv;
|
||||
exit;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user