
DevEnv nis2-agileandClaude Opus 4.8
de09af6d7e
[FEAT] Fase 3 backend: portale fornitore OTP/magic-link (SupplierPortalController)
Auth fornitore SEPARATA dagli utenti interni (supplier_users/otp/sessions, mig 034):
- SUPPLIER_JWT_SECRET dedicato, aud=supplier-portal, claim sp_uid/supplier_id/org_id
(mai user_id); requireSupplierSession() verifica jti in supplier_sessions
(revocabile), non tocca users/active_sessions.
- OTP 8 cifre SHA-256, 15min, lockout persistente (attempts+locked_until),
invalidazione OTP precedenti, hash_equals, rate-limit email+IP.
- magic-link 32B hashed single-use (consumo atomico solo su verify).
- request-otp risposta opaca anti-enumerazione.
- OTP via EmailService::sendViaTemplate (/api/emails/send, fuori da email_log).
- Endpoint: requestOtp/verifyOtp (no auth) + me/getQuestionnaire/saveAnswers
(PATCH autosave)/submitQuestionnaire. Ownership campaign.supplier_id==session (no IDOR).
- Scoring per-vulnerabilita (Art.21.3), snapshot domande immutabile.
- config: SUPPLIER_JWT_SECRET + PATCH in CORS_ALLOWED_METHODS.
- routes: controllerMap + actionMap supplier-portal.
php -l OK su tutti. Tabelle 034 gia' applicate su host.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-31 17:40:20 +02:00
..
2026-02-17 17:50:18 +01:00
2026-05-29 18:55:44 +02:00
2026-02-17 17:50:18 +01:00
2026-05-30 11:45:17 +02:00
2026-05-31 08:07:38 +02:00
2026-05-31 15:01:22 +02:00
2026-05-29 13:18:35 +02:00
2026-05-29 13:18:35 +02:00
2026-03-09 12:19:21 +01:00
2026-03-09 08:17:53 +01:00
2026-05-31 14:56:10 +02:00
2026-03-10 08:56:19 +01:00
2026-05-31 16:13:21 +02:00
2026-03-17 15:16:00 +01:00
2026-03-10 15:54:16 +01:00
2026-05-29 15:44:13 +02:00
2026-05-29 15:42:05 +02:00
2026-03-09 10:22:40 +01:00
2026-03-07 16:49:58 +01:00
2026-03-10 15:54:16 +01:00
2026-05-30 11:37:25 +02:00
2026-05-30 11:39:38 +02:00
2026-05-30 12:15:13 +02:00
2026-05-30 11:40:50 +02:00
2026-05-31 17:40:20 +02:00
2026-05-31 17:14:24 +02:00
2026-02-17 17:50:18 +01:00
2026-03-07 16:49:58 +01:00
2026-03-07 16:49:58 +01:00