[BACKEND] Completa backend: validate-invite, lookup-piva, ruoli, SIM-06
AuthController: - register() accetta `role` diretto (compliance_manager, org_admin, auditor, board_member, consultant) - Aggiunto validateInvite() → POST /api/auth/validate-invite (no auth) OnboardingController: - Aggiunto lookupPiva() → POST /api/onboarding/lookup-piva (no auth, rate limit 10/min) usato da register.html per P.IVA lookup pre-login Router (index.php): - Aggiunto POST:validateInvite e POST:lookupPiva api.js: - register() invia sia `role` che `user_type` per retrocompatibilità simulate-nis2.php: - SIM-06: B2B provisioning via X-Provision-Secret → org + JWT + API Key - Filtro NIS2_SIM=SIM06 via goto per skip SIM-01→05 indipendenti - readEnvValue() helper per leggere PROVISION_SECRET da .env register.html: - lookupPiva usa /onboarding/lookup-piva (endpoint pubblico) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
e4e7d94043
commit
ab0e3755f4
@@ -149,6 +149,7 @@ $actionMap = [
|
||||
'GET:me' => 'me',
|
||||
'PUT:profile' => 'updateProfile',
|
||||
'POST:changePassword' => 'changePassword',
|
||||
'POST:validateInvite' => 'validateInvite', // valida invite_token (no auth)
|
||||
],
|
||||
|
||||
// ── OrganizationController ──────────────────────
|
||||
@@ -280,6 +281,7 @@ $actionMap = [
|
||||
'onboarding' => [
|
||||
'POST:uploadVisura' => 'uploadVisura',
|
||||
'POST:fetchCompany' => 'fetchCompany',
|
||||
'POST:lookupPiva' => 'lookupPiva', // lookup P.IVA pubblico (no auth, da register)
|
||||
'POST:complete' => 'complete',
|
||||
],
|
||||
|
||||
|
||||
+8
-2
@@ -82,8 +82,14 @@ class NIS2API {
|
||||
return result;
|
||||
}
|
||||
|
||||
async register(email, password, fullName, userType = 'azienda') {
|
||||
const result = await this.post('/auth/register', { email, password, full_name: fullName, user_type: userType });
|
||||
async register(email, password, fullName, roleOrType = 'azienda') {
|
||||
// Supporta sia i nuovi role NIS2 diretti (compliance_manager, org_admin, etc.)
|
||||
// che il vecchio user_type (azienda, consultant) per retrocompatibilità
|
||||
const result = await this.post('/auth/register', {
|
||||
email, password, full_name: fullName,
|
||||
role: roleOrType,
|
||||
user_type: roleOrType, // backward compat
|
||||
});
|
||||
if (result.success) {
|
||||
this.setTokens(result.data.access_token, result.data.refresh_token);
|
||||
localStorage.setItem('nis2_user_role', result.data.user.role);
|
||||
|
||||
@@ -449,12 +449,9 @@
|
||||
statusEl.innerHTML = '<i class="fas fa-spinner fa-spin"></i> Ricerca azienda...';
|
||||
pivaLookupTimer = setTimeout(async () => {
|
||||
try {
|
||||
const res = await fetch(api.baseUrl + '/onboarding/fetch-company', {
|
||||
const res = await fetch(api.baseUrl + '/onboarding/lookup-piva', {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'Authorization': 'Bearer ' + (api.getToken ? api.getToken() : '')
|
||||
},
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ vat_number: val })
|
||||
});
|
||||
const data = await res.json();
|
||||
|
||||
Reference in New Issue
Block a user