[SEC+UX] Hardening sicurezza + miglioramenti UX pre-audit
SICUREZZA: - index.php: rimosso CORS wildcard in debug mode (solo origini autorizzate) - AuthController: getClientIP() con X-Forwarded-For sicuro (proxy-aware) - AuthController: refresh token con SELECT FOR UPDATE in transazione atomica - AIService: anonimizzazione dati org nei prompt Anthropic API (no nome/fatturato) UX AUDIT-READY: - dashboard.html: gauge rinominato 'Avanzamento implementazione misure Art.21' - incidents.html: decision tree Art.23 con 5 criteri per 'Is Significant?' - policies.html: banner warning obbligatorio su bozze generate da AI - risks.html: tooltip dettagliati scala Likelihood/Impact (ISO 27005) - assessment.html: progress bar % completamento risposta domande DB: - migration 006: indici performance + audit_log immutabile (trigger) + soft delete Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
0e78ec24c1
commit
782389849f
+1
-2
@@ -19,9 +19,8 @@ $origin = $_SERVER['HTTP_ORIGIN'] ?? '';
|
||||
|
||||
if (in_array($origin, CORS_ALLOWED_ORIGINS)) {
|
||||
header("Access-Control-Allow-Origin: {$origin}");
|
||||
} elseif (APP_DEBUG) {
|
||||
header("Access-Control-Allow-Origin: *");
|
||||
}
|
||||
// NOTE: No wildcard CORS even in debug mode — use CORS_ALLOWED_ORIGINS in config
|
||||
|
||||
header("Access-Control-Allow-Methods: " . CORS_ALLOWED_METHODS);
|
||||
header("Access-Control-Allow-Headers: " . CORS_ALLOWED_HEADERS);
|
||||
|
||||
Reference in New Issue
Block a user