Simon C3: l'analisi gap ACN non è un artefatto normativo e va eliminata; la conformità emerge da C1 (elenco Misure/Requisiti + valutazione per requisito in org_requisito_state). Ricognizione → migrazione → backup → rimozione (sicuro, 0 perdite): - Tabelle acn_assessments/acn_assessment_responses VUOTE (0 righe) -> droppate (mig.049, guard anti-drop se >0 righe). Ricreabili da 036. Nessun dato utente perso. - Integrazione lg231: /api/services/gap-analysis legge 'assessments' generale, NON il modulo ACN -> intatta. Verificato. - RaciController ripuntato su cfg_nis2_misure (fonte canonica) al posto di acn_measures.json (rimosso); validazione measure_code verificata (/raci/objects?type=measure -> 43 misure). Rimossi: AcnAssessmentController, public/acn-gap.html, application/data/acn_measures.json, routing acn-gap, voci sidebar (common.js + common-bi.js), metodi api.js acn*, sezione help 'acn', chiavi i18n acn.*, mapping demo-selectors. Tour demo step 3 RIPUNTATO su misure-requisiti (no step rotto, 10 step). Sidebar BI ora mostra 'Misure e Requisiti' (gap di common-bi.js sanato). Verifiche prod: /acn-gap.html 404, /api/acn-gap/* 404, /misure-requisiti 200, RaciController OK. Cache-buster ?v=20260624, version 1.18.3, SW v1.18.3. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
63 lines
3.4 KiB
JavaScript
63 lines
3.4 KiB
JavaScript
/*
|
|
* NIS2 Agile — Avatar di prodotto: WHITELIST selettori/azioni demo (product-demo-protocol v1.0.1).
|
|
*
|
|
* Fonte di verità (regola 3-way): DOM ↔ questo file ↔ docs/mappa-logica/SELETTORI_DEMO.md
|
|
* devono restare allineati. Se cambi un selettore qui o nel DOM → avvisa AgileHub per il re-ingest RAG.
|
|
*
|
|
* - VIEWS: nomi-vista del manifest → URL pagina reale (NIS2 è multi-page: navigate = cambio pagina,
|
|
* con ?demo=<id> preservato da demo-mode.js).
|
|
* - ACTIONS: SOLO azioni read-only sicure lanciabili dal tour (trigger_action). Ogni azione mappa a un
|
|
* anchor data-demo-action="<nome>" nel DOM. In demo:read-only le scritture sono già bloccate server-side
|
|
* (guard DEMO_READ_ONLY); qui restano solo azioni di consultazione (apri tab/dettaglio/pannello).
|
|
*/
|
|
(function (w) {
|
|
'use strict';
|
|
|
|
// vista (manifest view_target) → pagina reale
|
|
var VIEWS = {
|
|
'dashboard': '/dashboard.html',
|
|
'assessment': '/assessment.html',
|
|
'misure-requisiti': '/misure-requisiti.html',
|
|
'risks': '/risks.html',
|
|
'incidents': '/incidents.html',
|
|
'policies': '/policies.html',
|
|
'supply-chain': '/supply-chain.html',
|
|
'assets': '/assets.html',
|
|
'training': '/training.html',
|
|
'reports': '/reports.html',
|
|
'isms': '/isms.html',
|
|
'normative': '/normative.html',
|
|
'whistleblowing': '/whistleblowing.html',
|
|
'kb': '/kb.html',
|
|
'cross-analysis': '/cross-analysis.html',
|
|
'settings': '/settings.html',
|
|
'companies': '/companies.html'
|
|
};
|
|
|
|
// azioni read-only sicure (whitelist). value = come eseguirle in pagina.
|
|
// { type:'click', selector } | { type:'tab', selector } | { type:'anchor', action }
|
|
// NB: anchor = clicca l'elemento [data-demo-action="<action>"] (da cablare nel DOM).
|
|
var ACTIONS = {
|
|
// navigazione interna sicura (apertura tab di una vista)
|
|
'open-tab-matrix': { type: 'anchor', action: 'open-tab-matrix' }, // risks: vista Matrice 5x5
|
|
'open-tab-fair': { type: 'anchor', action: 'open-tab-fair' }, // risks: vista FAIR
|
|
'open-tab-controls': { type: 'anchor', action: 'open-tab-controls' }, // reports: tab Controlli
|
|
'open-tab-iso': { type: 'anchor', action: 'open-tab-iso' }, // reports: tab ISO 27001
|
|
'open-tab-audit': { type: 'anchor', action: 'open-tab-audit' }, // reports: tab Audit Log
|
|
'open-tab-acn': { type: 'anchor', action: 'open-tab-acn' }, // reports: tab Requisiti ACN
|
|
// pannelli/consultazione (read-only)
|
|
'open-ai-panel': { type: 'anchor', action: 'open-ai-panel' }, // cross-analysis: chat ARIA
|
|
'open-first-detail': { type: 'anchor', action: 'open-first-detail' } // apre il primo dettaglio di una lista
|
|
};
|
|
|
|
w.NIS2_DEMO_SELECTORS = {
|
|
version: '1.0',
|
|
// protocollo: queste sono le UNICHE viste/azioni eseguibili dal canale demo
|
|
views: VIEWS,
|
|
actions: ACTIONS,
|
|
viewUrl: function (view) { return VIEWS[view] || null; },
|
|
isAllowedAction: function (name) { return Object.prototype.hasOwnProperty.call(ACTIONS, name); },
|
|
action: function (name) { return ACTIONS[name] || null; }
|
|
};
|
|
})(window);
|