[FEAT] A4 Fase 4.1 — Organigramma (org_roles): ruoli/gerarchia + nodo governance Art.23
Primo modulo del modello relazionale A4 (docs/DESIGN_A4_RELATIONAL.md). Backend: - Migration 041 (docs/sql/041_org_roles.sql) + runner scripts/migrate-a4.php. Tabella org_roles additiva/idempotente: gerarchia self-FK (parent_role_id), titolare (holder_user_id), is_governance_body (organi amministrazione/direttivi Art.23 D.Lgs.138/2024), description (GV.RR-02). APPLICATA su prod (container nis2-db v8.0.45, TLSv1.3, 11 col, 4 FK). - OrgRoleController: list (flat+tree arricchiti), get, create, update, delete, assignableUsers. Multi-tenancy ancorata a getCurrentOrgId(), anti-IDOR (id+organization_id), prevenzione cicli nella gerarchia, holder = membro org, delete bloccato se ha figli (409). Route registrate in public/index.php. Frontend: - public/organigramma.html + js/organigramma.js: vista ad albero (badge governance, titolare/vacante), editor crea/modifica/elimina con select padre anti-ciclo, "crea struttura di base". Bootstrap Italia V2. - Voce sidebar "Organigramma" (common.js + common-bi.js) + nav.org_chart i18n IT/EN. - api.js: metodi orgRole* (wrapper _acn). Help/KB: - help.js: guida contestuale 'org' (cosa rappresenta, nodo Art.23, come si usa, fonti certe D.Lgs.138/2024 art.23 + GV.RR-02 best practice, disclaimer no-parere-legale). Cache-buster: bump ?v=20260617 dei 5 JS condivisi su tutte le 32 HTML referenti. version.json 1.15.2 -> 1.16.0. Smoke E2E su prod (fpm reale): login, CRUD, tree, anti-ciclo (422), delete-con-figli (409), cleanup tutti verdi. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
dcb9a14f0f
commit
8540b53cb2
@@ -224,6 +224,17 @@ class NIS2API {
|
||||
ismsReadiness() { return this._acn(this.get('/isms/readiness')); }
|
||||
ismsExport() { return this._acn(this.get('/isms/export')); }
|
||||
|
||||
// ═══════════════════════════════════════════════════════════════════
|
||||
// Organigramma (A4 Fase 4.1) — ruoli/gerarchia + nodo governance (Art.23).
|
||||
// Stesso contratto degli acn*/isms*: ritornano `data`, lanciano su success=false.
|
||||
// ═══════════════════════════════════════════════════════════════════
|
||||
orgRolesList() { return this._acn(this.get('/org-roles/list')); }
|
||||
orgRolesAssignableUsers() { return this._acn(this.get('/org-roles/assignable-users')); }
|
||||
orgRoleGet(id) { return this._acn(this.get(`/org-roles/${id}`)); }
|
||||
orgRoleCreate(data) { return this._acn(this.post('/org-roles/create', data || {})); }
|
||||
orgRoleUpdate(id, data) { return this._acn(this.put(`/org-roles/${id}`, data)); }
|
||||
orgRoleDelete(id) { return this._acn(this.del(`/org-roles/${id}`)); }
|
||||
|
||||
// ═══════════════════════════════════════════════════════════════════
|
||||
// Dashboard
|
||||
// ═══════════════════════════════════════════════════════════════════
|
||||
|
||||
@@ -37,7 +37,8 @@
|
||||
'assets.html': 'assets.html',
|
||||
'reports.html': 'reports.html',
|
||||
'settings.html': 'settings.html',
|
||||
'whistleblowing.html': 'whistleblowing.html'
|
||||
'whistleblowing.html': 'whistleblowing.html',
|
||||
'organigramma.html': 'organigramma.html'
|
||||
};
|
||||
|
||||
function biHref(href) {
|
||||
@@ -69,6 +70,7 @@
|
||||
{
|
||||
label: 'Gestione', i18nKey: 'nav.management',
|
||||
items: [
|
||||
{ name: 'Organigramma', href: 'organigramma.html', icon: '<svg viewBox="0 0 20 20" fill="currentColor"><path d="M8 2.5h4a.5.5 0 01.5.5v2a.5.5 0 01-.5.5h-1.25v2.5H15a.5.5 0 01.5.5v1.25H17a.5.5 0 01.5.5v3a.5.5 0 01-.5.5h-4a.5.5 0 01-.5-.5v-3a.5.5 0 01.5-.5h1.25V9.5H6v1.25H7.5a.5.5 0 01.5.5v3a.5.5 0 01-.5.5h-4a.5.5 0 01-.5-.5v-3a.5.5 0 01.5-.5H4.5V9.5a.5.5 0 01.5-.5h4.75V6H8a.5.5 0 01-.5-.5V3a.5.5 0 01.5-.5z"/></svg>', i18nKey: 'nav.org_chart' },
|
||||
{ name: 'Rischi', href: 'risks.html', icon: iconShieldExclamation(), i18nKey: 'nav.risks' },
|
||||
{ name: 'Incidenti', href: 'incidents.html', icon: iconBell(), i18nKey: 'nav.incidents' },
|
||||
{ name: 'Policy', href: 'policies.html', icon: iconDocumentText(), i18nKey: 'nav.policies' },
|
||||
|
||||
@@ -195,6 +195,7 @@ function loadSidebar() {
|
||||
{
|
||||
label: 'Gestione', i18nKey: 'nav.management',
|
||||
items: [
|
||||
{ name: 'Organigramma', href: 'organigramma.html', icon: `<svg viewBox="0 0 20 20" fill="currentColor"><path d="M8 2.5h4a.5.5 0 01.5.5v2a.5.5 0 01-.5.5h-1.25v2.5H15a.5.5 0 01.5.5v1.25H17a.5.5 0 01.5.5v3a.5.5 0 01-.5.5h-4a.5.5 0 01-.5-.5v-3a.5.5 0 01.5-.5h1.25V9.5H6v1.25H7.5a.5.5 0 01.5.5v3a.5.5 0 01-.5.5h-4a.5.5 0 01-.5-.5v-3a.5.5 0 01.5-.5H4.5V9.5a.5.5 0 01.5-.5h4.75V6H8a.5.5 0 01-.5-.5V3a.5.5 0 01.5-.5z"/></svg>`, i18nKey: 'nav.org_chart' },
|
||||
{ name: 'Rischi', href: 'risks.html', icon: iconShieldExclamation(), i18nKey: 'nav.risks' },
|
||||
{ name: 'Incidenti', href: 'incidents.html', icon: iconBell(), i18nKey: 'nav.incidents' },
|
||||
{ name: 'Policy', href: 'policies.html', icon: iconDocumentText(), i18nKey: 'nav.policies' },
|
||||
|
||||
@@ -201,6 +201,43 @@ const HelpSystem = (function () {
|
||||
]
|
||||
},
|
||||
|
||||
// ─── Organigramma (A4 Fase 4.1) ──────────────────────────────
|
||||
'org': {
|
||||
title: 'Guida - Organigramma',
|
||||
intro: 'L\'Organigramma mappa chi e responsabile di cosa: i ruoli dell\'organizzazione, la loro gerarchia, il titolare di ciascun ruolo e — distinto — il nodo degli organi di amministrazione e direttivi. E\' la base del modello relazionale: nelle fasi successive i ruoli verranno collegati a competenze, procedure, inventario e rischi tramite la matrice RACI. E\' uno strumento di supporto organizzativo, non un parere legale.',
|
||||
sections: [
|
||||
{
|
||||
heading: 'Cosa rappresenta',
|
||||
items: [
|
||||
'<strong>Ruolo</strong>: una posizione organizzativa (es. CISO, Responsabile IT, DPO). Puo avere un <strong>titolare</strong> (un utente dell\'organizzazione) oppure restare vacante.',
|
||||
'<strong>Gerarchia</strong>: ogni ruolo puo avere un ruolo "padre" (a chi riporta). I ruoli senza padre sono i nodi radice dell\'organigramma.',
|
||||
'<strong>Responsabilita e poteri</strong>: il campo descrizione documenta cosa fa il ruolo, coerentemente con la buona prassi GV.RR-02 (ruoli, responsabilita e poteri stabiliti e comunicati).'
|
||||
]
|
||||
},
|
||||
{
|
||||
heading: 'Il nodo "Organi di amministrazione e direttivi" (Art. 23)',
|
||||
items: [
|
||||
'Marca come <strong>organo di governance</strong> il ruolo che rappresenta gli organi di amministrazione e direttivi: l\'<strong>art. 23 del D.Lgs. 138/2024</strong> ne stabilisce la responsabilita nell\'approvare le misure di gestione del rischio e nel sovrintendere alla loro attuazione.',
|
||||
'Tenere questo nodo distinto rende dimostrabile in audit "chi approva" le misure e su chi ricade la responsabilita di vigilanza.',
|
||||
'Gli organi di gestione sono inoltre tenuti a seguire una <strong>formazione</strong> specifica in materia di sicurezza informatica (gestita nel modulo Formazione).'
|
||||
]
|
||||
},
|
||||
{
|
||||
heading: 'Come si usa',
|
||||
items: [
|
||||
'<strong>Nuovo ruolo</strong>: indica il nome, l\'eventuale ruolo padre, il titolare e — se pertinente — la spunta "organo di governance".',
|
||||
'Puoi modificare un ruolo o spostarlo nella gerarchia cambiandone il padre (il sistema impedisce di creare cicli).',
|
||||
'Un ruolo non puo essere eliminato se ha ruoli subordinati: riassegna prima i figli a un altro ruolo.'
|
||||
]
|
||||
}
|
||||
],
|
||||
references: [
|
||||
'D.Lgs. 138/2024, art. 23 - Responsabilita degli organi di amministrazione e direttivi (governance)',
|
||||
'NIST CSF 2.0 / GV.RR-02 (best practice) - Ruoli, responsabilita e poteri stabiliti e comunicati',
|
||||
'NOTA: gli obblighi normativi in Italia derivano da NIS2 (Dir. UE 2022/2555) e dal D.Lgs. 138/2024; framework e organigrammi sono strumenti di supporto, non un parere legale.'
|
||||
]
|
||||
},
|
||||
|
||||
// ─── Risk Management ─────────────────────────────────────────
|
||||
'risks': {
|
||||
title: 'Guida - Gestione Rischi',
|
||||
@@ -1039,6 +1076,8 @@ const HelpSystem = (function () {
|
||||
'acn': 'acn',
|
||||
'isms.html': 'isms',
|
||||
'isms': 'isms',
|
||||
'organigramma.html': 'org',
|
||||
'organigramma': 'org',
|
||||
'risks.html': 'risks',
|
||||
'risks': 'risks',
|
||||
'incidents.html': 'incidents',
|
||||
|
||||
@@ -78,6 +78,10 @@ const I18n = (function () {
|
||||
'isms.s6.hint': { it: 'Gli audit interni e le non conformità si gestiscono nei moduli esistenti: Audit & Report e NCR/CAPA.', en: 'Internal audits and non-conformities are managed in the existing modules: Audit & Reports and NCR/CAPA.' },
|
||||
'isms.s6.readiness': { it: 'Completamento del SGSI', en: 'ISMS completion' },
|
||||
'nav.management': { it: 'Gestione', en: 'Management' },
|
||||
'nav.org_chart': { it: 'Organigramma', en: 'Org Chart' },
|
||||
'org.title': { it: 'Organigramma', en: 'Org Chart' },
|
||||
'org.subtitle': { it: 'Ruoli, responsabilità e organi di governance', en: 'Roles, responsibilities and governance bodies' },
|
||||
'org.new_role': { it: 'Nuovo ruolo', en: 'New role' },
|
||||
'nav.risks': { it: 'Rischi', en: 'Risks' },
|
||||
'nav.incidents': { it: 'Incidenti', en: 'Incidents' },
|
||||
'nav.policies': { it: 'Policy', en: 'Policies' },
|
||||
|
||||
@@ -0,0 +1,209 @@
|
||||
/**
|
||||
* NIS2 Agile - Organigramma (A4 Fase 4.1)
|
||||
* Vista ad albero dei ruoli organizzativi + editor (crea/modifica/elimina).
|
||||
* Client api.orgRole*: ritorna `data`, lancia su success=false (vedi api.js _acn).
|
||||
* Nodo "organo di governance" = Art. 23 D.Lgs. 138/2024.
|
||||
*/
|
||||
'use strict';
|
||||
|
||||
let ORG = { roles: [], users: [], tree: [] };
|
||||
|
||||
function el(id) { return document.getElementById(id); }
|
||||
function esc(s) { const d = document.createElement('div'); d.textContent = (s == null ? '' : String(s)); return d.innerHTML; }
|
||||
|
||||
document.addEventListener('DOMContentLoaded', async function () {
|
||||
if (typeof checkAuth === 'function' && !checkAuth()) return;
|
||||
if (window.I18n && I18n.init) I18n.init('it');
|
||||
if (typeof loadSidebar === 'function') loadSidebar();
|
||||
if (window.HelpSystem && HelpSystem.init) HelpSystem.init();
|
||||
|
||||
// Chiudi la modale con ESC e con click sull'overlay.
|
||||
document.addEventListener('keydown', function (e) { if (e.key === 'Escape') orgCloseModal(); });
|
||||
const ov = el('org-modal');
|
||||
if (ov) ov.addEventListener('click', function (e) { if (e.target === ov) orgCloseModal(); });
|
||||
|
||||
await orgLoadAll();
|
||||
});
|
||||
|
||||
async function orgLoadAll() {
|
||||
try {
|
||||
const [data, users] = await Promise.all([
|
||||
api.orgRolesList(),
|
||||
api.orgRolesAssignableUsers()
|
||||
]);
|
||||
ORG.roles = data.roles || [];
|
||||
ORG.tree = data.tree || [];
|
||||
ORG.users = Array.isArray(users) ? users : [];
|
||||
orgRender();
|
||||
} catch (e) {
|
||||
showNotification('Errore nel caricamento dell\'organigramma: ' + (e.message || e), 'error');
|
||||
}
|
||||
}
|
||||
|
||||
function orgRender() {
|
||||
const tree = el('org-tree');
|
||||
const empty = el('org-empty');
|
||||
const stats = el('org-stats');
|
||||
|
||||
if (!ORG.roles.length) {
|
||||
tree.innerHTML = '';
|
||||
empty.style.display = 'block';
|
||||
stats.style.display = 'none';
|
||||
return;
|
||||
}
|
||||
empty.style.display = 'none';
|
||||
|
||||
// Statistiche
|
||||
const gov = ORG.roles.filter(r => r.is_governance_body).length;
|
||||
const vacant = ORG.roles.filter(r => !r.holder_user_id).length;
|
||||
el('org-stat-total').textContent = ORG.roles.length;
|
||||
el('org-stat-gov').textContent = gov;
|
||||
el('org-stat-vacant').textContent = vacant;
|
||||
stats.style.display = 'flex';
|
||||
|
||||
tree.innerHTML = ORG.tree.map(orgNodeHtml).join('');
|
||||
}
|
||||
|
||||
function orgNodeHtml(node) {
|
||||
const gov = node.is_governance_body;
|
||||
const holder = node.holder_name
|
||||
? '<div class="org-holder">👤 ' + esc(node.holder_name) + '</div>'
|
||||
: '<div class="org-holder vacant">Ruolo vacante</div>';
|
||||
const desc = node.description ? '<div class="org-desc">' + esc(node.description) + '</div>' : '';
|
||||
const govBadge = gov ? '<span class="org-badge gov" title="Organo di amministrazione/direttivo (art. 23 D.Lgs. 138/2024)">Governance · Art. 23</span>' : '';
|
||||
const children = (node.children && node.children.length)
|
||||
? '<div class="org-children">' + node.children.map(orgNodeHtml).join('') + '</div>'
|
||||
: '';
|
||||
|
||||
return '' +
|
||||
'<div class="org-node">' +
|
||||
'<div class="org-card' + (gov ? ' gov' : '') + '">' +
|
||||
'<div class="org-card-main">' +
|
||||
'<div class="org-role-name">' + esc(node.role_name) + govBadge + '</div>' +
|
||||
holder + desc +
|
||||
'</div>' +
|
||||
'<div class="org-actions">' +
|
||||
'<button class="btn btn-outline" onclick="orgOpenModal(' + node.id + ')" title="Modifica">Modifica</button>' +
|
||||
'<button class="btn btn-outline" onclick="orgOpenModal(null,' + node.id + ')" title="Aggiungi subordinato">+ Subordinato</button>' +
|
||||
'<button class="btn btn-outline" onclick="orgDeleteRole(' + node.id + ')" title="Elimina">Elimina</button>' +
|
||||
'</div>' +
|
||||
'</div>' +
|
||||
children +
|
||||
'</div>';
|
||||
}
|
||||
|
||||
/** Insieme degli id discendenti di un ruolo (per escluderli dalla select padre). */
|
||||
function orgDescendants(roleId) {
|
||||
const out = new Set();
|
||||
const stack = [roleId];
|
||||
while (stack.length) {
|
||||
const cur = stack.pop();
|
||||
ORG.roles.forEach(r => {
|
||||
if (r.parent_role_id === cur && !out.has(r.id)) { out.add(r.id); stack.push(r.id); }
|
||||
});
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/**
|
||||
* Apre la modale. editId => modifica; parentId => crea un subordinato di parentId.
|
||||
*/
|
||||
function orgOpenModal(editId, parentId) {
|
||||
const role = editId ? ORG.roles.find(r => r.id === editId) : null;
|
||||
el('org-modal-title').textContent = role ? 'Modifica ruolo' : 'Nuovo ruolo';
|
||||
el('org-f-id').value = role ? role.id : '';
|
||||
el('org-f-name').value = role ? role.role_name : '';
|
||||
el('org-f-desc').value = role ? (role.description || '') : '';
|
||||
el('org-f-gov').checked = role ? !!role.is_governance_body : false;
|
||||
el('org-f-err').textContent = '';
|
||||
|
||||
// Select padre — escludi se stesso e i suoi discendenti (anti-ciclo lato UI).
|
||||
const exclude = role ? orgDescendants(role.id) : new Set();
|
||||
if (role) exclude.add(role.id);
|
||||
const parentSel = el('org-f-parent');
|
||||
parentSel.innerHTML = '<option value="">— Nessuno (nodo radice) —</option>' +
|
||||
ORG.roles.filter(r => !exclude.has(r.id))
|
||||
.map(r => '<option value="' + r.id + '">' + esc(r.role_name) + '</option>').join('');
|
||||
const selParent = role ? role.parent_role_id : (parentId || '');
|
||||
parentSel.value = selParent ? String(selParent) : '';
|
||||
|
||||
// Select titolare
|
||||
const holderSel = el('org-f-holder');
|
||||
holderSel.innerHTML = '<option value="">— Vacante —</option>' +
|
||||
ORG.users.map(u => '<option value="' + u.id + '">' + esc(u.full_name || u.email) + '</option>').join('');
|
||||
holderSel.value = (role && role.holder_user_id) ? String(role.holder_user_id) : '';
|
||||
|
||||
el('org-modal').classList.add('open');
|
||||
setTimeout(() => el('org-f-name').focus(), 50);
|
||||
}
|
||||
|
||||
function orgCloseModal() {
|
||||
const m = el('org-modal');
|
||||
if (m) m.classList.remove('open');
|
||||
}
|
||||
|
||||
async function orgSaveRole() {
|
||||
const id = el('org-f-id').value;
|
||||
const name = el('org-f-name').value.trim();
|
||||
if (!name) { el('org-f-err').textContent = 'Il nome del ruolo è obbligatorio.'; return; }
|
||||
|
||||
const payload = {
|
||||
role_name: name,
|
||||
parent_role_id: el('org-f-parent').value || null,
|
||||
holder_user_id: el('org-f-holder').value || null,
|
||||
is_governance_body: el('org-f-gov').checked ? 1 : 0,
|
||||
description: el('org-f-desc').value.trim()
|
||||
};
|
||||
|
||||
const btn = el('org-f-save');
|
||||
btn.disabled = true;
|
||||
try {
|
||||
if (id) {
|
||||
await api.orgRoleUpdate(parseInt(id, 10), payload);
|
||||
showNotification('Ruolo aggiornato.', 'success');
|
||||
} else {
|
||||
await api.orgRoleCreate(payload);
|
||||
showNotification('Ruolo creato.', 'success');
|
||||
}
|
||||
orgCloseModal();
|
||||
await orgLoadAll();
|
||||
} catch (e) {
|
||||
el('org-f-err').textContent = e.message || 'Errore nel salvataggio.';
|
||||
} finally {
|
||||
btn.disabled = false;
|
||||
}
|
||||
}
|
||||
|
||||
async function orgDeleteRole(id) {
|
||||
const role = ORG.roles.find(r => r.id === id);
|
||||
if (!confirm('Eliminare il ruolo "' + (role ? role.role_name : '') + '"?')) return;
|
||||
try {
|
||||
await api.orgRoleDelete(id);
|
||||
showNotification('Ruolo eliminato.', 'success');
|
||||
await orgLoadAll();
|
||||
} catch (e) {
|
||||
// 409 = ha ruoli subordinati
|
||||
showNotification(e.message || 'Errore nell\'eliminazione.', 'error');
|
||||
}
|
||||
}
|
||||
|
||||
/** Crea una struttura organizzativa di base (solo se l'organigramma è vuoto). */
|
||||
async function orgScaffold() {
|
||||
if (ORG.roles.length) { showNotification('L\'organigramma non è vuoto.', 'info'); return; }
|
||||
if (!confirm('Creare una struttura di base (Organi di amministrazione, Direzione, CISO, Responsabile IT, DPO)?')) return;
|
||||
try {
|
||||
const board = await api.orgRoleCreate({
|
||||
role_name: 'Organi di amministrazione e direttivi',
|
||||
is_governance_body: 1,
|
||||
description: 'Approva le misure di gestione del rischio e ne vigila l\'attuazione (art. 23 D.Lgs. 138/2024).'
|
||||
});
|
||||
const dir = await api.orgRoleCreate({ role_name: 'Direzione / Alta Dirigenza', parent_role_id: board.id });
|
||||
await api.orgRoleCreate({ role_name: 'Responsabile Sicurezza Informatica (CISO)', parent_role_id: dir.id, description: 'Coordina le misure di sicurezza e l\'attuazione del programma NIS2.' });
|
||||
await api.orgRoleCreate({ role_name: 'Responsabile IT', parent_role_id: dir.id });
|
||||
await api.orgRoleCreate({ role_name: 'Responsabile Protezione Dati (DPO)', parent_role_id: dir.id });
|
||||
showNotification('Struttura di base creata. Personalizzala pure.', 'success');
|
||||
await orgLoadAll();
|
||||
} catch (e) {
|
||||
showNotification('Errore nella creazione della struttura: ' + (e.message || e), 'error');
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user