[SEC] EmailService: kill-switch invio email (EMAIL_SENDING_ENABLED)

Ambiente con soli dati demo: NESSUNA email deve partire. Aggiunto guard
all'inizio di sendViaRelay() e sendViaTemplate() (gli UNICI due punti che fanno
HTTP al relay -> copre tutti i canali: incidenti, training, inviti, reminder,
welcome, password reset, feedback, OTP portale fornitori).

EMAIL_SENDING_ENABLED in config: default false in sviluppo, true in produzione,
override via .env. Quando false l'invio viene loggato e scartato (return false),
nessuna chiamata di rete.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
DevEnv nis2-agile
2026-05-31 18:46:55 +02:00
co-authored by Claude Opus 4.8
parent 006f86387b
commit fe77ee8679
2 changed files with 26 additions and 0 deletions
+12
View File
@@ -66,6 +66,12 @@ class EmailService
*/
private function sendViaRelay(string $to, string $subject, string $fullHtml, string $from): bool
{
// KILL-SWITCH: in ambiente con soli dati demo nessuna email deve partire.
if (defined('EMAIL_SENDING_ENABLED') && !EMAIL_SENDING_ENABLED) {
error_log('[EmailService] invio DISABILITATO (EMAIL_SENDING_ENABLED=false): scartato "' . $subject . '" per ' . self::maskEmail($to));
return false;
}
$base = rtrim(self::env('EMAIL_MS_URL', 'https://agilehub.agile.software/api/emails'), '/');
$key = self::env('INTERNAL_EMAIL_KEY', '');
@@ -132,6 +138,12 @@ class EmailService
*/
public function sendViaTemplate(string $to, string $template, array $vars, ?string $brandName = null): bool
{
// KILL-SWITCH: in ambiente con soli dati demo nessuna email deve partire.
if (defined('EMAIL_SENDING_ENABLED') && !EMAIL_SENDING_ENABLED) {
error_log('[EmailService] invio DISABILITATO (EMAIL_SENDING_ENABLED=false): template "' . $template . '" scartato per ' . self::maskEmail($to));
return false;
}
$base = rtrim(self::env('EMAIL_MS_URL', 'https://agilehub.agile.software/api/emails'), '/');
$key = self::env('INTERNAL_EMAIL_KEY', '');