[FEAT] A4 Fase 4.3 — Matrice RACI + link m2m: raci_assignments + procedure_inventory/procedure_risk/inventory_risk/risk_measure (mig.043), RaciController org-scoped (anti-IDOR, validazione object/measure), raci.html+raci.js (Bootstrap Italia/AGID), routing+sidebar+api+help+i18n. Build+review adversariale via workflow (0 finding critical/major). Cache-buster ?v=20260619.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
DevEnv nis2-agile
2026-06-15 22:44:08 +02:00
co-authored by Claude Opus 4.8
parent 05dfba6fcd
commit b4d47d58a2
44 changed files with 1154 additions and 111 deletions
+16
View File
@@ -254,6 +254,22 @@ class NIS2API {
compGapGrid() { return this._acn(this.get('/competences/gap-grid')); }
compOpenAction(roleSkillId) { return this._acn(this.post('/competences/open-action', { role_skill_id: roleSkillId })); }
// ═══════════════════════════════════════════════════════════════════
// Matrice RACI (A4 Fase 4.3) — hub ruoli↔oggetti (R/A/C/I) + link m2m
// (procedura↔inventario, procedura↔rischio, inventario↔rischio, rischio↔misura).
// Stesso contratto _acn: ritornano `data`, lanciano su success=false.
// NB: i DELETE non hanno body (del() in request() invia body solo per POST/PUT),
// quindi i parametri compositi vanno passati come query string → il backend
// li legge da getParam() ($_REQUEST).
// ═══════════════════════════════════════════════════════════════════
raciMatrix() { return this._acn(this.get('/raci/matrix')); }
raciAssign(d) { return this._acn(this.post('/raci/assign', d)); }
raciUnassign(d) { return this._acn(this.del('/raci/assign?role_id=' + encodeURIComponent(d.role_id) + '&object_type=' + encodeURIComponent(d.object_type) + '&object_id=' + encodeURIComponent(d.object_id))); }
raciObjects(type) { return this._acn(this.get('/raci/objects?type=' + encodeURIComponent(type))); }
raciLinks(linkType, id) { return this._acn(this.get('/raci/links?link_type=' + encodeURIComponent(linkType) + '&id=' + encodeURIComponent(id))); }
raciLink(d) { return this._acn(this.post('/raci/link', d)); }
raciUnlink(d) { return this._acn(this.del('/raci/link?link_type=' + encodeURIComponent(d.link_type) + '&a_id=' + encodeURIComponent(d.a_id) + '&b_id=' + encodeURIComponent(d.b_id))); }
// ═══════════════════════════════════════════════════════════════════
// Dashboard
// ═══════════════════════════════════════════════════════════════════