99 lines
3.3 KiB
Go
99 lines
3.3 KiB
Go
package repository
|
|
|
|
// Reference: M13 §2 — Account SAML settings repository
|
|
// Per-account SAML configuration CRUD, following the pattern of SAMLIdPConfigRepo.
|
|
// Enables enterprise administrators to configure SAML SSO for their accounts
|
|
// without touching global IdP configuration.
|
|
|
|
import (
|
|
"encoding/json"
|
|
|
|
"gorm.io/gorm"
|
|
|
|
"github.com/gochat/gochat/internal/model"
|
|
)
|
|
|
|
// AccountSamlSettingsRepo manages per-account SAML SSO settings in the database.
|
|
type AccountSamlSettingsRepo struct {
|
|
db *gorm.DB
|
|
}
|
|
|
|
// NewAccountSamlSettingsRepo creates a new AccountSamlSettings repository.
|
|
func NewAccountSamlSettingsRepo(db *gorm.DB) *AccountSamlSettingsRepo {
|
|
return &AccountSamlSettingsRepo{db: db}
|
|
}
|
|
|
|
// GetByAccount retrieves the SAML settings for an account.
|
|
// Returns nil if no settings exist for the account.
|
|
func (r *AccountSamlSettingsRepo) GetByAccount(accountID uint) (*model.AccountSamlSettings, error) {
|
|
var settings model.AccountSamlSettings
|
|
err := r.db.Where("account_id = ?", accountID).First(&settings).Error
|
|
if err == gorm.ErrRecordNotFound {
|
|
return nil, nil
|
|
}
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return &settings, nil
|
|
}
|
|
|
|
// GetActiveByAccount retrieves the active SAML settings for an account.
|
|
// Returns nil if no active settings exist.
|
|
func (r *AccountSamlSettingsRepo) GetActiveByAccount(accountID uint) (*model.AccountSamlSettings, error) {
|
|
var settings model.AccountSamlSettings
|
|
err := r.db.Where("account_id = ? AND active = ?", accountID, true).First(&settings).Error
|
|
if err == gorm.ErrRecordNotFound {
|
|
return nil, nil
|
|
}
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return &settings, nil
|
|
}
|
|
|
|
// Create creates new SAML settings for an account.
|
|
// Returns an error if settings already exist for the account (unique constraint).
|
|
func (r *AccountSamlSettingsRepo) Create(settings *model.AccountSamlSettings) error {
|
|
return r.db.Create(settings).Error
|
|
}
|
|
|
|
// Update updates existing SAML settings for an account.
|
|
func (r *AccountSamlSettingsRepo) Update(settings *model.AccountSamlSettings) error {
|
|
return r.db.Save(settings).Error
|
|
}
|
|
|
|
// UpdateFields updates specific fields of the SAML settings.
|
|
// Only non-zero fields in the updates map will be changed.
|
|
func (r *AccountSamlSettingsRepo) UpdateFields(accountID uint, updates map[string]interface{}) error {
|
|
// Handle RoleMappings separately — it needs JSON serialization
|
|
if roleMappings, ok := updates["role_mappings"]; ok {
|
|
switch v := roleMappings.(type) {
|
|
case json.RawMessage:
|
|
updates["role_mappings"] = v
|
|
case string:
|
|
updates["role_mappings"] = json.RawMessage(v)
|
|
case map[string]interface{}:
|
|
data, err := json.Marshal(v)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
updates["role_mappings"] = json.RawMessage(data)
|
|
}
|
|
}
|
|
|
|
return r.db.Model(&model.AccountSamlSettings{}).
|
|
Where("account_id = ?", accountID).
|
|
Updates(updates).Error
|
|
}
|
|
|
|
// Delete removes SAML settings for an account.
|
|
func (r *AccountSamlSettingsRepo) Delete(accountID uint) error {
|
|
return r.db.Where("account_id = ?", accountID).Delete(&model.AccountSamlSettings{}).Error
|
|
}
|
|
|
|
// SetActive toggles the active status of SAML settings for an account.
|
|
func (r *AccountSamlSettingsRepo) SetActive(accountID uint, active bool) error {
|
|
return r.db.Model(&model.AccountSamlSettings{}).
|
|
Where("account_id = ?", accountID).
|
|
Update("active", active).Error
|
|
} |