Commit Graph
14 Commits
Author SHA1 Message Date
DevEnv nis2-agileandClaude Opus 4.8 8540b53cb2 [FEAT] A4 Fase 4.1 — Organigramma (org_roles): ruoli/gerarchia + nodo governance Art.23
Primo modulo del modello relazionale A4 (docs/DESIGN_A4_RELATIONAL.md).

Backend:
- Migration 041 (docs/sql/041_org_roles.sql) + runner scripts/migrate-a4.php.
  Tabella org_roles additiva/idempotente: gerarchia self-FK (parent_role_id),
  titolare (holder_user_id), is_governance_body (organi amministrazione/direttivi
  Art.23 D.Lgs.138/2024), description (GV.RR-02). APPLICATA su prod (container
  nis2-db v8.0.45, TLSv1.3, 11 col, 4 FK).
- OrgRoleController: list (flat+tree arricchiti), get, create, update, delete,
  assignableUsers. Multi-tenancy ancorata a getCurrentOrgId(), anti-IDOR
  (id+organization_id), prevenzione cicli nella gerarchia, holder = membro org,
  delete bloccato se ha figli (409). Route registrate in public/index.php.

Frontend:
- public/organigramma.html + js/organigramma.js: vista ad albero (badge governance,
  titolare/vacante), editor crea/modifica/elimina con select padre anti-ciclo,
  "crea struttura di base". Bootstrap Italia V2.
- Voce sidebar "Organigramma" (common.js + common-bi.js) + nav.org_chart i18n IT/EN.
- api.js: metodi orgRole* (wrapper _acn).

Help/KB:
- help.js: guida contestuale 'org' (cosa rappresenta, nodo Art.23, come si usa,
  fonti certe D.Lgs.138/2024 art.23 + GV.RR-02 best practice, disclaimer no-parere-legale).

Cache-buster: bump ?v=20260617 dei 5 JS condivisi su tutte le 32 HTML referenti.
version.json 1.15.2 -> 1.16.0. Smoke E2E su prod (fpm reale): login, CRUD, tree,
anti-ciclo (422), delete-con-figli (409), cleanup tutti verdi.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 18:05:56 +02:00
DevEnv nis2-agileandClaude Opus 4.8 717f9ac396 [FEAT] A2 UI: wizard onboarding esteso (bilancio, autonomia/gruppo, categorie size-independent art.3 c.5, mission GV.OC, codice etico facoltativo, 3 criteri sotto-soglia c.9 b/c/d) + classificazione v2 lato server + disclaimer ACN 'autovalutazione preliminare'. Markup Bootstrap Italia/AGID
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:17:34 +02:00
DevEnv nis2-agileandClaude Opus 4.8 121b8c2003 [FIX] Allineamento normativo segnalazioni Fattori (A1+A3): citazioni obblighi -> D.Lgs.138/2024 art.23/24/25 (non Direttiva) + terminologia Asset -> Inventario
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 15:27:07 +02:00
DevEnv nis2-agileandClaude Opus 4.8 36513fa722 [FEAT] PWA installabile Android/iOS conforme AGID (v1.15.0)
- manifest.webmanifest + service worker (offline shell, /api network-only, asset stale-while-revalidate)
- set icone (192/512 + maskable + apple-touch + favicon), generate zero-deps (pure Node+zlib)
- tag PWA + viewport viewport-fit=cover (zoom mantenuto, WCAG 1.4.4) in 77 pagine HTML
- AGID/WCAG 2.1 AA: touch target >=44px, orientamento/zoom liberi, safe-area standalone
- generatori riproducibili: scripts/gen-pwa-icons.mjs + scripts/inject-pwa-head.mjs
- bump version 1.14.1 -> 1.15.0

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-14 21:09:54 +02:00
DevEnv nis2-agile ad3532a90a [FIX] Pannello ARIA: chiusura (X+Esc) robusta + niente sovrapposizione ai pallini (stile TRPG)
Aprendo il pannello ARIA ora si nascondono nx-bar (campana/supporto) + ai-chat-fab -> niente overlap;
la X e Esc chiudono e ripristinano i pallini. Prima la X era fragile e il pannello copriva i bottoni.
Bump common.js?v=20260613d. (TRPG usa ai-assistant.js con stesso pattern toggle/hide.)
2026-06-14 08:56:08 +02:00
DevEnv nis2-agile 4341d86c4c [UI] Allineato a TRPG/AgileHub: rimosso auto-inject feedback.js (doppione) -> solo bug-reporter
NIS2 aveva DUE sistemi feedback: feedback.js (pill cyan 'Segnala/Feedback' + modale scuro) + bug-reporter
AgileHub (campana+supporto). TRPG/ALLTAX usano solo bug-reporter (verificato: trpg ha app/js/bug-reporter.js,
nessun feedback.js). Rimosso l'auto-inject di feedback.js da common.js -> resta il trittico pallini
(notifiche + supporto + ARIA) come la suite. Verificato headless: feedback-fab assente, nx-bell/nx-bug/ai-chat
presenti. Bump common.js?v=20260613c (auto-refetch). feedback.js/api restano nel repo, non iniettati.
2026-06-14 08:33:13 +02:00
DevEnv nis2-agile 959ede968d [FIX] Feedback widget: cablata X-API-Key NIS2 (nis2_ak_dev_...) in common.js + bump common.js?v=20260613b
Risolve il 401 del bug-reporter ('Header X-API-Key o Authorization Bearer richiesto'): il widget ora
manda X-API-Key -> gateway ticket AgileHub OK (tenant 7, provenance corretta). Chiave fornita da AgileHub
(full tenant-key, va nel JS pubblico = stesso compromesso TRPG/ALLTAX; debito 'token low-priv' rimandato).
Bump versione common.js -> auto-refetch senza hard-refresh.
2026-06-13 19:21:56 +02:00
DevEnv nis2-agile 3c484fe604 [FIX] Cache-buster ?v=20260613 sui JS/CSS modificati (help/common/common-bi/i18n/feedback/style/demo) + bump bug-reporter + demo assets
Risolve 'le modifiche non si vedono': /js/help.js era senza ?v -> browser serviva la versione cached
vecchia. 281 ref su 57 pagine + injection demo/bug-reporter aggiornate.
2026-06-13 19:17:59 +02:00
DevEnv nis2-agileandClaude Opus 4.8 1c64211685 [UI] SWAP V2: Bootstrap Italia ora UFFICIALE su 27 pagine app (kill della vecchia UI)
Promosse le pagine -bi a nomi ufficiali (contenuto BI), link -bi->plain, titoli '(BI)' rimossi.
La vecchia UI delle pagine app e sostituita. Backup: git (commit 36967f9) + /tmp/nis2-v1-backup.

Promosse (27): auth (login/register/onboarding/forgot/reset) + app (dashboard/assessment/
risks/incidents/policies/supply-chain/training/assets/reports/settings/isms/acn-gap/normative/
whistleblowing/kb/cross-analysis/service-continuity/guida/companies) + admin (index/orgs/users).
common-bi.js: sidebar BI ora linka le pagine ufficiali.

ESCLUSA: index.html (landing marketing 1298 righe) -> conversione dedicata a parte (la -bi
era 557 righe, rischio perdita contenuti). Pagine marketing/demo (presentation/simulate/
workflow/architecture/index-en) restano vecchio stile (fuori scope app autenticata).

Verifica produzione: 27/27 servite 200 con BI, 0 link -bi residui, 0 '(BI)' nei titoli,
auth intatta (401 su pwd errata), common-bi.js node --check OK.

Rollback: git revert HEAD  (oppure ripristino da /tmp/nis2-v1-backup).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-12 14:49:15 +02:00
DevEnv nis2-agileandClaude Sonnet 4.6 e4e7d94043 [UX] Standardizzazione login/register/onboarding + Test Runner v2
login.html: eye toggle, forgot password, auth-terms footer
register.html: wizard 3-step, 5 ruoli NIS2, invite_token URL, P.IVA lookup
onboarding.html: Font Awesome, brand color cyan (#06B6D4)
test-runner.php: L1-L5 test levels, SIM-06 B2B, tab Coverage/Stats,
  DB row counts, run history (localStorage), 5 tabs totali

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-07 17:11:25 +01:00
DevEnv nis2-agileandClaude Sonnet 4.6 7080695d06 [FEAT] Ruolo Consulente + Wizard Registrazione v2
- register.html: step 0 scelta profilo (Azienda / Consulente)
- onboarding.html: wizard 4-step con P.IVA obbligatoria (auto-fetch CertiSource)
- companies.html: nuova dashboard consulente con cards aziende e compliance score
- common.js: org-switcher sidebar + role labels corretti per consulente
- login.html: routing post-login (consulente → companies.html)
- api.js: isConsultant(), setUserRole(), register con user_type
- AuthController: user_type=consultant → role=consultant in users table
- OnboardingController: multi-org per consulente, duplicate VAT check
- 005_consultant_support.sql: aggiunge 'consultant' a user_organizations.role ENUM

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-20 08:53:30 +01:00
AdminGit2026andClaude Opus 4.6 4e3408e9f6 [FEAT] Visura auto-fill, adesione volontaria, modulo NCR/CAPA
1. Fix auto-fill visura: mapping corretto suggested_sector e employees_range,
   indicatori visivi verdi sui campi auto-compilati, fatturato sempre manuale
2. Adesione volontaria: colonna voluntary_compliance, checkbox in onboarding
   step 5 quando not_applicable, toggle in settings, reset su ri-classificazione
3. Modulo NCR/CAPA: NonConformityController con 10 endpoint API,
   tabelle non_conformities + capa_actions, generazione NCR dai gap assessment,
   predisposizione integrazione SistemiG.agile (webhook + sync)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 08:12:57 +01:00
AdminGit2026andClaude Opus 4.6 bcc5a2b003 [FIX] E2E testing - fix router, EmailService, frontend data mapping
Critical fixes discovered during end-to-end testing:

Router (index.php):
- Rewrote route resolution engine to properly handle /{id}/subAction patterns
- All routes like GET /assessments/{id}/questions, POST /incidents/{id}/early-warning,
  GET /organizations/{id}/members now resolve correctly
- Routes with kebab-case sub-actions (early-warning, ai-analyze) now convert to camelCase
- Controller methods receive correct arguments via spread operator

EmailService.php:
- Fix PHP parse error: ?? operator cannot be used inside string interpolation {}
- Extract incident_code to variable before interpolation (3 occurrences)

assessment.html:
- Fix data structure handling: API returns categories with nested questions array
- Fix field names: question_code (not question_id), response_value (not compliance_level)
- Fix answer enum values: not_implemented/partial/implemented (not Italian)
- Fix question text field: question_text (not text/question/title)
- Show NIS2 article and ISO 27001 control references
- Fix response restoration from existing answers

dashboard.html:
- Fix data mapping from overview API response structure
- risks.total instead of open_risks, policies array instead of approved_policies
- Calculate training completion percentage from training object
- Load deadlines/activity from dedicated endpoints (not included in overview)

onboarding.html:
- Fix field name mismatches: annual_turnover_eur, contact_email, contact_phone,
  full_name, phone (matching OnboardingController expected params)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-17 19:40:26 +01:00
AdminGit2026andClaude Opus 4.6 9aa2788c68 [FEAT] Add onboarding wizard with visura camerale and CertiSource integration
- New 5-step onboarding wizard (onboarding.html) replacing setup-org.html
- Step 1: Choose data source (Upload Visura / CertiSource / Manual)
- Step 2: PDF upload with AI extraction or CertiSource P.IVA lookup
- Step 3: Verify/complete company data with NIS2 sector mapping
- Step 4: User profile completion
- Step 5: NIS2 classification (Essential/Important) with summary
- OnboardingController with upload-visura, fetch-company, complete endpoints
- VisuraService with Claude AI PDF extraction and ATECO-to-NIS2 mapping
- CertiSource API integration for automatic company data retrieval
- Updated login/register redirects to point to new onboarding wizard

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-17 19:01:34 +01:00