From d06e2cfd98f5bf8a6e3cbc039f01f6d0c3bdba35 Mon Sep 17 00:00:00 2001 From: Shivam Mishra Date: Mon, 25 Aug 2025 13:43:43 +0530 Subject: [PATCH] feat: add saml settings controller --- config/routes.rb | 1 + .../v1/accounts/saml_settings_controller.rb | 50 +++++++++++++++++++ 2 files changed, 51 insertions(+) create mode 100644 enterprise/app/controllers/api/v1/accounts/saml_settings_controller.rb diff --git a/config/routes.rb b/config/routes.rb index 1409b11fd..b524a2ac6 100644 --- a/config/routes.rb +++ b/config/routes.rb @@ -69,6 +69,7 @@ Rails.application.routes.draw do end resources :documents, only: [:index, :show, :create, :destroy] end + resource :saml_settings, only: [:show, :create, :update, :destroy] resources :agent_bots, only: [:index, :create, :show, :update, :destroy] do delete :avatar, on: :member post :reset_access_token, on: :member diff --git a/enterprise/app/controllers/api/v1/accounts/saml_settings_controller.rb b/enterprise/app/controllers/api/v1/accounts/saml_settings_controller.rb new file mode 100644 index 000000000..1e06919a4 --- /dev/null +++ b/enterprise/app/controllers/api/v1/accounts/saml_settings_controller.rb @@ -0,0 +1,50 @@ +class Api::V1::Accounts::SamlSettingsController < Api::V1::Accounts::BaseController + before_action :check_saml_feature_enabled + before_action :check_authorization + before_action :set_saml_settings + + def show; end + + def create + @saml_settings = Current.account.build_saml_settings(saml_settings_params) + @saml_settings.save! + end + + def update + @saml_settings.update!(saml_settings_params) + end + + def destroy + @saml_settings.destroy! + head :no_content + end + + private + + def set_saml_settings + @saml_settings = Current.account.saml_settings || Current.account.build_saml_settings + end + + def saml_settings_params + params.require(:saml_settings).permit( + :enabled, + :sso_url, + :certificate_fingerprint, + :certificate, + :sp_entity_id, + :enforced_sso, + attribute_mappings: {}, + role_mappings: {} + ) + end + + def check_authorization + authorize(AccountSamlSettings) + end + + def check_saml_feature_enabled + return if Current.account.feature_enabled?('saml') + + render json: { error: 'SAML feature not enabled for this account' }, status: :forbidden + end +end