Sicurezza e GDPR
Conformita'
- Audit log centralizzato (
audit_log) - GDPR Art. 32-33
- SoftDeletes su
corsista, esaminatore, deliberante, partner - Art. 17
- Password bcrypt con dual-hash legacy migration
- Documenti utente serviti via controller auth+ruolo (
/secure-download)
- Email senza password in chiaro
- Retention cron
audit-log:retention --days=90
Autenticazione
- Password + rate limit 10/min IP
- Magic link (passwordless) con TTL 15 min
- 2FA TOTP per amministratori (RFC 6238)
- Recovery codes one-shot
Header HTTP
- X-Frame-Options: SAMEORIGIN
- X-Content-Type-Options: nosniff
- Referrer-Policy: strict-origin-when-cross-origin
- Permissions-Policy: restrittiva
- HSTS su HTTPS
← Indice docs · Home