Completa C5 (Epic C). Gli stakeholder rispondono in self-service tramite magic-link
(token SHA-256 per destinatario, NESSUN account/JWT); il compliance manager vede gli
esiti, i commenti e gli allegati nel dettaglio dell'attività.
- StakeholderPortalController (non-JWT, token-only): access / respond (questionario) /
acknowledge (firma di avvenuta lettura) / comment / attachment. Submit one-shot (409),
validazione risposte obbligatorie, anti-IDOR (un token = un solo destinatario),
auto-completamento attività quando tutti hanno risposto/firmato.
- StakeholderActivityController: feedback (risposte per destinatario), comments
(GET/POST), attachments (upload interno + lista; riuso evidence_files entity_type=
'stk_activity', file sotto public/uploads/stk_activity/{org}/).
- mig.053: stk_activity_responses (answers JSON / acknowledged_at), stk_activity_comments
(interni/esterni). Estende il seeder idempotente.
- Frontend: stk-portal.html (pagina pubblica dependency-free: questionario per tipo di
domanda o testo+firma, commento, upload); dettaglio attività in stakeholder-activities.html
con esiti, thread commenti e allegati.
Email disattivate (kill-switch) → i magic-link si condividono manualmente. Smoke prod OK
(access no-auth, respond+required+409, acknowledge+WRONG_TYPE, comment esterno/interno,
bad-token 404, feedback interno, auto-complete; cleanup org 151 pulita). Additivo. v1.21.0.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
52 lines
2.6 KiB
SQL
52 lines
2.6 KiB
SQL
-- =====================================================================
|
|
-- 053 — Feedback attività stakeholder: risposte + commenti (Epic C / C5.2b)
|
|
-- =====================================================================
|
|
-- Sotto-dashboard di ricezione feedback (Simon C5 §4.3): per ogni destinatario
|
|
-- (stk_activity_targets, mig.052) si raccoglie la RISPOSTA al questionario oppure
|
|
-- la FIRMA di avvenuta lettura; sull'attività si possono aggiungere COMMENTI e
|
|
-- ALLEGATI. Gli allegati RIUSANO evidence_files (entity_type='stk_activity',
|
|
-- entity_id=activity_id) — nessuna tabella nuova per i file.
|
|
--
|
|
-- Le risposte arrivano dal portale esterno self-service (token magic-link,
|
|
-- StakeholderPortalController, non-JWT) oppure registrate internamente.
|
|
--
|
|
-- Additivo, reversibile. Runner-safe: CREATE TABLE IF NOT EXISTS con FK dentro
|
|
-- il CREATE; nessun DELIMITER; nessun ';' nei commenti. DDL eseguita dal CLI
|
|
-- idempotente application/cli/seed_stakeholder_activities.php (estende C5.2a).
|
|
-- =====================================================================
|
|
|
|
-- Risposta del destinatario (una per target): answers JSON (questionario) oppure
|
|
-- acknowledged_at (firma di avvenuta lettura).
|
|
CREATE TABLE IF NOT EXISTS stk_activity_responses (
|
|
id INT NOT NULL AUTO_INCREMENT,
|
|
target_id INT NOT NULL,
|
|
answers JSON NULL,
|
|
acknowledged_at DATETIME NULL,
|
|
respondent_name VARCHAR(255) NULL,
|
|
respondent_email VARCHAR(255) NULL,
|
|
ip_address VARCHAR(45) NULL,
|
|
submitted_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
|
PRIMARY KEY (id),
|
|
UNIQUE KEY uq_stkar_target (target_id),
|
|
CONSTRAINT fk_stkar_target FOREIGN KEY (target_id) REFERENCES stk_activity_targets (id) ON DELETE CASCADE
|
|
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci;
|
|
|
|
-- Commenti append-only sull'attività (interni o esterni dal portale).
|
|
CREATE TABLE IF NOT EXISTS stk_activity_comments (
|
|
id INT NOT NULL AUTO_INCREMENT,
|
|
activity_id INT NOT NULL,
|
|
body TEXT NOT NULL,
|
|
author_kind ENUM('internal','external') NOT NULL DEFAULT 'internal',
|
|
author_user_id INT NULL,
|
|
author_label VARCHAR(255) NULL,
|
|
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
|
PRIMARY KEY (id),
|
|
KEY idx_stkac_act (activity_id),
|
|
CONSTRAINT fk_stkac_act FOREIGN KEY (activity_id) REFERENCES stk_activities (id) ON DELETE CASCADE,
|
|
CONSTRAINT fk_stkac_user FOREIGN KEY (author_user_id) REFERENCES users (id) ON DELETE SET NULL
|
|
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci;
|
|
|
|
-- ROLLBACK (manuale):
|
|
-- DROP TABLE IF EXISTS stk_activity_comments
|
|
-- DROP TABLE IF EXISTS stk_activity_responses
|