[FEAT] Add EmailService, RateLimitService, ReportService + integrations

Services:
- EmailService: CSIRT notifications (24h/72h/30d), training alerts, welcome email
- RateLimitService: File-based rate limiting for auth and AI endpoints
- ReportService: Executive HTML report, CSV exports (risks/incidents/controls/assets)

Integrations:
- AuthController: Rate limiting on login (5/min, 20/h) and register (3/10min)
- IncidentController: Email notifications on CSIRT milestones
- AuditController: Executive report and CSV export endpoints
- Router: 429 rate limit error handling, new audit export routes

Database:
- Migration 002: email_log table for notification tracking

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-02-17 19:12:46 +01:00
co-authored by Claude Opus 4.6
parent 9aa2788c68
commit 6f4b457ce0
9 changed files with 2383 additions and 0 deletions
@@ -6,6 +6,7 @@
*/
require_once __DIR__ . '/BaseController.php';
require_once APP_PATH . '/services/RateLimitService.php';
class AuthController extends BaseController
{
@@ -14,6 +15,11 @@ class AuthController extends BaseController
*/
public function register(): void
{
// Rate limiting
$ip = $_SERVER['REMOTE_ADDR'] ?? 'unknown';
RateLimitService::check("register:{$ip}", RATE_LIMIT_AUTH_REGISTER);
RateLimitService::increment("register:{$ip}");
$this->validateRequired(['email', 'password', 'full_name']);
$email = strtolower(trim($this->getParam('email')));
@@ -78,6 +84,11 @@ class AuthController extends BaseController
*/
public function login(): void
{
// Rate limiting
$ip = $_SERVER['REMOTE_ADDR'] ?? 'unknown';
RateLimitService::check("login:{$ip}", RATE_LIMIT_AUTH_LOGIN);
RateLimitService::increment("login:{$ip}");
$this->validateRequired(['email', 'password']);
$email = strtolower(trim($this->getParam('email')));