Files
gochat/internal/repository/account_saml_settings_repo.go
T
2026-06-04 15:44:48 +08:00

99 lines
3.3 KiB
Go

package repository
// Reference: M13 §2 — Account SAML settings repository
// Per-account SAML configuration CRUD, following the pattern of SAMLIdPConfigRepo.
// Enables enterprise administrators to configure SAML SSO for their accounts
// without touching global IdP configuration.
import (
"encoding/json"
"gorm.io/gorm"
"github.com/gochat/gochat/internal/model"
)
// AccountSamlSettingsRepo manages per-account SAML SSO settings in the database.
type AccountSamlSettingsRepo struct {
db *gorm.DB
}
// NewAccountSamlSettingsRepo creates a new AccountSamlSettings repository.
func NewAccountSamlSettingsRepo(db *gorm.DB) *AccountSamlSettingsRepo {
return &AccountSamlSettingsRepo{db: db}
}
// GetByAccount retrieves the SAML settings for an account.
// Returns nil if no settings exist for the account.
func (r *AccountSamlSettingsRepo) GetByAccount(accountID uint) (*model.AccountSamlSettings, error) {
var settings model.AccountSamlSettings
err := r.db.Where("account_id = ?", accountID).First(&settings).Error
if err == gorm.ErrRecordNotFound {
return nil, nil
}
if err != nil {
return nil, err
}
return &settings, nil
}
// GetActiveByAccount retrieves the active SAML settings for an account.
// Returns nil if no active settings exist.
func (r *AccountSamlSettingsRepo) GetActiveByAccount(accountID uint) (*model.AccountSamlSettings, error) {
var settings model.AccountSamlSettings
err := r.db.Where("account_id = ? AND active = ?", accountID, true).First(&settings).Error
if err == gorm.ErrRecordNotFound {
return nil, nil
}
if err != nil {
return nil, err
}
return &settings, nil
}
// Create creates new SAML settings for an account.
// Returns an error if settings already exist for the account (unique constraint).
func (r *AccountSamlSettingsRepo) Create(settings *model.AccountSamlSettings) error {
return r.db.Create(settings).Error
}
// Update updates existing SAML settings for an account.
func (r *AccountSamlSettingsRepo) Update(settings *model.AccountSamlSettings) error {
return r.db.Save(settings).Error
}
// UpdateFields updates specific fields of the SAML settings.
// Only non-zero fields in the updates map will be changed.
func (r *AccountSamlSettingsRepo) UpdateFields(accountID uint, updates map[string]interface{}) error {
// Handle RoleMappings separately — it needs JSON serialization
if roleMappings, ok := updates["role_mappings"]; ok {
switch v := roleMappings.(type) {
case json.RawMessage:
updates["role_mappings"] = v
case string:
updates["role_mappings"] = json.RawMessage(v)
case map[string]interface{}:
data, err := json.Marshal(v)
if err != nil {
return err
}
updates["role_mappings"] = json.RawMessage(data)
}
}
return r.db.Model(&model.AccountSamlSettings{}).
Where("account_id = ?", accountID).
Updates(updates).Error
}
// Delete removes SAML settings for an account.
func (r *AccountSamlSettingsRepo) Delete(accountID uint) error {
return r.db.Where("account_id = ?", accountID).Delete(&model.AccountSamlSettings{}).Error
}
// SetActive toggles the active status of SAML settings for an account.
func (r *AccountSamlSettingsRepo) SetActive(accountID uint, active bool) error {
return r.db.Model(&model.AccountSamlSettings{}).
Where("account_id = ?", accountID).
Update("active", active).Error
}