[FEAT] Simulazioni Demo + Audit Trail Certificato SHA-256

- 5 scenari reali: Onboarding, Ransomware Art.23, Data Breach Supply Chain,
  Whistleblowing SCADA, Audit Hash Chain Verification
- simulate-nis2.php: 3 aziende (DataCore/MedClinic/EnerNet), 10 fasi, CLI+SSE
- AuditService.php: hash chain SHA-256 stile lg231 (prev_hash+entry_hash)
- Migration 010: prev_hash, entry_hash, severity, performed_by su audit_logs
- AuditController: GET chain-verify + GET export-certified
- reset-demo.sql: reset dati demo idempotente
- public/simulate.html: web runner SSE con console dark-theme
- Sidebar: link Simulazione Demo + Integrazioni

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
DevEnv nis2-agile
2026-03-07 13:56:53 +01:00
co-authored by Claude Sonnet 4.6
parent b23bbc55fd
commit 874eabb6fc
9 changed files with 1983 additions and 10 deletions
+18 -10
View File
@@ -7,6 +7,7 @@
*/
require_once APP_PATH . '/config/database.php';
require_once APP_PATH . '/services/AuditService.php';
class BaseController
{
@@ -533,16 +534,23 @@ class BaseController
*/
protected function logAudit(string $action, ?string $entityType = null, ?int $entityId = null, ?array $details = null): void
{
Database::insert('audit_logs', [
'user_id' => $this->getCurrentUserId(),
'organization_id' => $this->currentOrgId,
'action' => $action,
'entity_type' => $entityType,
'entity_id' => $entityId,
'details' => $details ? json_encode($details) : null,
'ip_address' => $_SERVER['REMOTE_ADDR'] ?? null,
'user_agent' => $_SERVER['HTTP_USER_AGENT'] ?? null,
]);
$orgId = $this->currentOrgId;
$userId = $this->getCurrentUserId();
$severity = AuditService::resolveSeverity($action, $details);
$email = $this->currentUser['email'] ?? null;
AuditService::log(
$orgId ?? 0,
$userId,
$action,
$entityType,
$entityId,
$details,
$_SERVER['REMOTE_ADDR'] ?? '',
$_SERVER['HTTP_USER_AGENT'] ?? null,
$severity,
$email
);
}
// ═══════════════════════════════════════════════════════════════════════