[FEAT] Gestione Rischi: tabella 12 colonne (inerente+residuo) — integrazione prototipo "Modulo Azioni" (Simon)
Integra la spec di Simon per la pagina Rischi con le correzioni normative (parere nis2-expert + iso-27001-expert) applicate come eccezioni motivate: - 12 colonne: Codice (link → Misure e Requisiti), Descrizione (RISCHIO DEFAULT = cfg_nis2_rischi.risk_descr), VALUTAZIONE RISCHIO INERENTE (P/I/PxI), Alert, Rischio Inerente, VALUTAZIONE RISCHIO RESIDUO (P/I/PxI), Esito residuo, Rischio Residuo. - Editing INLINE di Probabilità/Impatto (1-5), salvataggio automatico. - Alert a bande (15-25 Prioritaria / 9-14 Critica / 3-8 Necessaria / 1-2 Suggerita) → popup azioni + "crea azione" (tabella requisito_actions, seme Modulo Azioni). - Eccezione #1: il rischio RESIDUO NON aggiorna in automatico lo STATO DI CONFORMITÀ del requisito (piani distinti). Col.11 "Esito residuo" = flag Rivalutare/Adeguato; conformità esplicita. - Eccezione #3: banda 13-14 inclusa in "Critica" (9-14). "Danno €" → "Impatto" (1-5). Soglie = metodo interno (ISO 27001 §6.1.2), non obbligo (help/UI lo dichiarano). Backend: mig 067; derivedList (+risk_descr +residuo), setState (+residuo), requisitoActions list/create. help.js + i18n IT/EN. Cache-buster api/i18n/help 20260730a. Prossima mig=068. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
cf224480cc
commit
8a0bc5ca39
@@ -0,0 +1,64 @@
|
||||
<?php
|
||||
/**
|
||||
* migrate_067_requisito_residual_and_actions.php — Integrazione "Modulo Azioni" (Simon), Fase 1.
|
||||
* (1) org_requisito_state += residual_likelihood, residual_impact (TINYINT NULL, scala 1-5).
|
||||
* (2) requisito_actions (azioni collegate al rischio-da-requisito).
|
||||
* Additiva e IDEMPOTENTE. Nessun dato esistente toccato.
|
||||
*
|
||||
* Eseguire (host): docker exec nis2-app php /var/www/nis2-agile/application/cli/migrate_067_requisito_residual_and_actions.php
|
||||
*/
|
||||
if (PHP_SAPI !== 'cli') { http_response_code(403); exit("CLI only\n"); }
|
||||
require_once __DIR__ . '/../config/env.php';
|
||||
require_once __DIR__ . '/../config/database.php';
|
||||
|
||||
$pdo = Database::getInstance();
|
||||
|
||||
function colExists(PDO $pdo, string $table, string $col): bool {
|
||||
$st = $pdo->prepare(
|
||||
"SELECT 1 FROM information_schema.COLUMNS
|
||||
WHERE TABLE_SCHEMA = DATABASE() AND TABLE_NAME = ? AND COLUMN_NAME = ?"
|
||||
);
|
||||
$st->execute([$table, $col]);
|
||||
return (bool) $st->fetchColumn();
|
||||
}
|
||||
function tblExists(PDO $pdo, string $table): bool {
|
||||
$st = $pdo->prepare(
|
||||
"SELECT 1 FROM information_schema.TABLES
|
||||
WHERE TABLE_SCHEMA = DATABASE() AND TABLE_NAME = ?"
|
||||
);
|
||||
$st->execute([$table]);
|
||||
return (bool) $st->fetchColumn();
|
||||
}
|
||||
|
||||
$adds = [
|
||||
'residual_likelihood' => "ADD COLUMN residual_likelihood TINYINT NULL COMMENT 'Probabilita residua 1-5' AFTER impact",
|
||||
'residual_impact' => "ADD COLUMN residual_impact TINYINT NULL COMMENT 'Impatto residuo 1-5' AFTER residual_likelihood",
|
||||
];
|
||||
foreach ($adds as $col => $clause) {
|
||||
if (colExists($pdo, 'org_requisito_state', $col)) { echo " - $col gia presente, skip\n"; continue; }
|
||||
$pdo->exec("ALTER TABLE org_requisito_state $clause");
|
||||
echo " + aggiunta colonna org_requisito_state.$col\n";
|
||||
}
|
||||
|
||||
if (tblExists($pdo, 'requisito_actions')) {
|
||||
echo " - tabella requisito_actions gia presente, skip\n";
|
||||
} else {
|
||||
$pdo->exec(
|
||||
"CREATE TABLE requisito_actions (
|
||||
id INT AUTO_INCREMENT PRIMARY KEY,
|
||||
organization_id INT NOT NULL,
|
||||
requisito_id INT NOT NULL,
|
||||
risk_code VARCHAR(64) NULL,
|
||||
description TEXT NOT NULL,
|
||||
status ENUM('bozza','in_corso','archiviata') NOT NULL DEFAULT 'bozza',
|
||||
created_by INT NULL,
|
||||
created_at DATETIME NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||
updated_at DATETIME NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
|
||||
INDEX idx_reqact_org_req (organization_id, requisito_id, created_at),
|
||||
INDEX idx_reqact_org (organization_id, created_at)
|
||||
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci"
|
||||
);
|
||||
echo " + creata tabella requisito_actions\n";
|
||||
}
|
||||
|
||||
echo "Migrazione 067 — residuo + requisito_actions OK. Prossima mig=068.\n";
|
||||
Reference in New Issue
Block a user