Files
nis2-agile/public/sw.js
T
DevEnv nis2-agileandClaude Opus 4.8 5368b0a61c [FEAT] A4 Fase 4.2 — Competenze (skill/requisiti ruolo/gap) + alert→azione NCR+CAPA
Secondo modulo del modello relazionale A4 (docs/DESIGN_A4_RELATIONAL.md).

Backend:
- Migration 042 (docs/sql/042_competences.sql) + runner aggiornato (scripts/migrate-a4.php).
  4 tabelle additive/idempotenti: skills (org-owned o globali), role_skills
  (competenze richieste dal ruolo, UNIQUE role+skill), user_skills (possedute,
  UNIQUE org+user+skill), skill_course_map. APPLICATA su prod (nis2-db v8.0.45,
  TLSv1.3).
- CompetenceController (route 'competences'): catalog, skills CRUD, roleSkills,
  userSkills, skillCourses (map/unmap), gapGrid (richiesto−posseduto per ruolo
  con titolare), openAction. Multi-tenancy + anti-IDOR + livelli 1-5; competenze
  globali in sola lettura per gli utenti org.
- alert→azione: openAction RIUSA il workflow NCR/CAPA reale (la tabella azioni è
  capa_actions figlia di non_conformities, NON 'corrective_actions' che non
  esiste): crea NCR (source='management_review', source_entity_type='competence_gap',
  source_entity_id=role_skills.id) + capa_actions figlia. Anti-duplicato sul gap.
  Zero ALTER alle tabelle esistenti. Ancoraggio PR.AT-01/02, GV.RR-04, art.24 D.Lgs.

Frontend:
- competenze.html (4 schede: Catalogo, Requisiti per ruolo, Competenze persone,
  Gap & azioni) + js/competenze.js. Bootstrap Italia V2. CTA "Assegna corso"
  (riuso /training/assign) e "Apri non conformità".
- Voce sidebar "Competenze" (common.js + common-bi.js + BI_PAGES) + nav.competences
  i18n IT/EN. api.js: metodi comp* + assignTraining.

Help/KB/PWA:
- help.js: guida contestuale 'competences' (schede, calcolo gap, PR.AT-01/02,
  GV.RR-04, art.24 D.Lgs., disclaimer no-parere-legale) + mappa pagina.
- sw.js: nome cache nis2-shell-v1.17.0 (allineamento PWA).
- Design doc corretto (rettifica capa_actions vs corrective_actions) + avanzamento 4.1/4.2.

Cache-buster: ?v=20260618 dei 5 JS condivisi su 32 HTML. version.json 1.16.0 -> 1.17.0.
Smoke E2E su prod (fpm reale): catalogo, requisito, competenza, gap=2, openAction
(NCR+CAPA), anti-dup 409, mappatura corso — tutti verdi; dati di test ripuliti.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 19:01:32 +02:00

97 lines
3.4 KiB
JavaScript

/*
* NIS2 Agile — Service Worker (PWA)
* -----------------------------------------------------------------------------
* Strategia (SaaS autenticato multi-tenant — sicurezza prima di tutto):
* - /api/* -> NETWORK-ONLY, MAI in cache. Nessun dato autenticato
* viene cacheato => zero leak cross-utente su un
* dispositivo condiviso. La sessione resta gestita da
* JWT / auth-gate.js, fuori dal service worker.
* - navigazioni HTML -> NETWORK-FIRST, fallback alla cache e infine /offline.html.
* - asset statici -> STALE-WHILE-REVALIDATE (risposta immediata dalla cache,
* aggiornamento in background).
*
* Il nome cache include la release: va BUMPATO ad ogni rilascio (vedi version.json),
* cosi' activate elimina automaticamente la shell vecchia.
*/
const CACHE = 'nis2-shell-v1.17.0';
const PRECACHE = [
'/offline.html',
'/manifest.webmanifest',
'/css/style.css',
'/js/common.js',
'/js/common-bi.js',
'/js/api.js',
'/js/i18n.js',
'/js/pwa.js',
'/vendor/bootstrap-italia/dist/css/bootstrap-italia.min.css',
'/vendor/bootstrap-italia/dist/js/bootstrap-italia.bundle.min.js',
'/vendor/bootstrap-italia/dist/svg/sprites.svg',
'/assets/icons/icon-192.png',
'/assets/icons/icon-512.png'
];
self.addEventListener('install', (event) => {
event.waitUntil((async () => {
const cache = await caches.open(CACHE);
// add uno-a-uno: un singolo asset mancante non deve far fallire l'install
await Promise.all(PRECACHE.map((url) =>
cache.add(new Request(url, { cache: 'reload' })).catch((err) =>
console.warn('[sw] precache skip', url, err && err.message))
));
await self.skipWaiting();
})());
});
self.addEventListener('activate', (event) => {
event.waitUntil((async () => {
const keys = await caches.keys();
await Promise.all(keys.filter((k) => k !== CACHE).map((k) => caches.delete(k)));
await self.clients.claim();
})());
});
self.addEventListener('fetch', (event) => {
const req = event.request;
if (req.method !== 'GET') return; // non-GET: rete normale
const url = new URL(req.url);
if (url.origin !== self.location.origin) return; // cross-origin: rete normale
// /api/* -> network-only, mai in cache
if (url.pathname.startsWith('/api/')) {
event.respondWith(
fetch(req).catch(() => new Response(
JSON.stringify({ error: 'offline', message: 'Connessione di rete assente' }),
{ status: 503, headers: { 'Content-Type': 'application/json' } }
))
);
return;
}
// navigazioni HTML -> network-first, fallback cache -> offline
if (req.mode === 'navigate') {
event.respondWith((async () => {
try {
return await fetch(req);
} catch (e) {
const cached = await caches.match(req);
return cached || (await caches.match('/offline.html'));
}
})());
return;
}
// asset statici stesso-origin -> stale-while-revalidate
event.respondWith((async () => {
const cache = await caches.open(CACHE);
const cached = await cache.match(req);
const network = fetch(req).then((res) => {
if (res && res.status === 200 && res.type === 'basic') {
cache.put(req, res.clone());
}
return res;
}).catch(() => null);
return cached || (await network) || (await caches.match('/offline.html'));
})());
});