3 Commits
Author SHA1 Message Date
DevEnv nis2-agileandClaude Opus 4.8 6900d942a4 [DEMO] resetDataset cablato a DemoSeedService (reset reale dataset demo/sandbox)
- application/services/DemoSeedService.php: logica seed/clone golden #151 -> 996001/996002 (riusabile)
- DemoController::resetDataset: re-seed reale via service (?scope=demo|sandbox|default both), non piu stub
- scripts/seed-demo-dataset.php: thin CLI wrapper sul service
Testato prod: POST /api/demo/reset-dataset (X-Internal-Key) scope=sandbox -> 200, 996002 ri-seedata.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 08:47:09 +02:00
DevEnv nis2-agile e0204dbaa7 [DEMO] fix seeder: utente demo via Database::insert (must_change_password default) + must_change_password=0
Eseguito su prod: org 996001 (DataCore Demo) + 996002 (sandbox) seedate. Guard deployato (USR2) e
testato end-to-end: read demo 200 (score 75), write demo 403 DEMO_READ_ONLY, auth reale intatta.
2026-06-13 08:39:32 +02:00
DevEnv nis2-agileandClaude Opus 4.8 e04eba62c1 [DEMO] Avatar prodotto: read-only guard (BaseController) + seeder dataset demo 996001/996002
Increment backend formazione-first (product-demo-protocol v1.0.1):
- BaseController::applyDemoGuard() — SAFE-BY-CONSTRUCTION (flusso auth normale invariato):
  riconosce demo_jwt scope=demo:read-only (blocca scritture 403 DEMO_READ_ONLY) e
  training:sandbox (scritture solo su org sandbox); contesto sintetico user=0 ruolo
  compliance_manager su org range 996xxx; mai super_admin. Short-circuit in requireAuth/
  requireOrgAccess/requireOrgRole. php -l OK. DA DEPLOYARE (USR2) + testare quando host disponibile.
- scripts/seed-demo-dataset.php — clona golden DataCore #151 in 996001 (demo RO) + 996002
  (sandbox scrivibile), idempotente, richiamabile da resetDataset. php -l OK. DA ESEGUIRE su host.

NB: chiave ssh host revocata a meta-sessione → seed/USR2/push in attesa di ri-provisioning.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 08:19:53 +02:00