This gates API-token access and outgoing account webhooks behind the `api_and_webhooks` account feature introduced in #14972. On Chatwoot Cloud, Hacker accounts lose token-authenticated account API access and account webhook delivery, while paid accounts retain them through the billing-plan feature reconcile. Community and self-hosted installations continue to work without any upgrade-time interruption. ## What changed - Added `Account#api_and_webhooks_enabled?` as the single backend kill switch. Core returns enabled; the Enterprise override consults the account flag on Chatwoot Cloud and remains enabled off-Cloud. - Account-scoped v1 and v2 requests authenticated with a user or agent-bot API token now return `403 Forbidden` when the feature is disabled. Invalid tokens still return 401, and dashboard session requests are unaffected. - Profile responses return an empty access token when none of the user's accounts has access. The stored token is preserved, and the profile UI disables its token controls with paid-plan copy on Cloud. - Account webhook delivery stops when the feature is disabled. Webhook CRUD remains available to session-authenticated dashboard requests, API-inbox webhooks continue to be delivered, and the Cloud dashboard shows a webhook paywall instead of the webhook list. - Removed the database backfill migration. Existing paid Cloud accounts should be enabled with the one-off script below before enforcement is deployed. ## Existing paid-account rollout Run this as an ad-hoc Rails runner script on Chatwoot Cloud. It intentionally targets only the Startups, Business, and Enterprise plans and does not add `api_and_webhooks` to `manually_managed_features`, so future billing reconciles remain authoritative. ```rb paid_plan_names = %w[Startups Business Enterprise] accounts = Account.where("custom_attributes ->> 'plan_name' IN (?)", paid_plan_names) total = accounts.count enabled = 0 skipped = 0 puts "Enabling api_and_webhooks for #{total} paid account(s)..." accounts.find_each(batch_size: 500).with_index(1) do |account, processed| if account.feature_enabled?('api_and_webhooks') skipped += 1 else account.enable_features!('api_and_webhooks') enabled += 1 end puts "Processed #{processed}/#{total}..." if (processed % 1000).zero? end puts "Done! Enabled: #{enabled}, Skipped: #{skipped}, Total: #{total}" ``` For example, save the snippet outside the repository as `enable_api_and_webhooks.rb`, then run: ```sh bundle exec rails runner /path/to/enable_api_and_webhooks.rb ``` ## How to test - On Cloud, use a Hacker account and confirm token-authenticated requests to account-scoped v1 and v2 endpoints return 403, while the same dashboard actions continue to work through session authentication. - Confirm profile access-token controls are disabled with paid-plan copy when all accounts are ineligible, and remain available when at least one account has the feature. - Confirm the Webhooks settings page shows the billing paywall for a Cloud account without the feature; admins get the billing action and agents get the existing ask-an-admin message. - Confirm outgoing account webhooks stop for an ineligible Cloud account while API-inbox webhooks still deliver. - Confirm community and self-hosted installations retain API and webhook behavior after upgrading, even when an existing account does not have the stored feature bit. ### Screenshots ## Cloud <img width="2590" height="642" alt="CleanShot 2026-07-15 at 15 13 14@2x" src="https://github.com/user-attachments/assets/431a7bd8-1742-4e7a-b312-d3ad92015f9b" /> <img width="2152" height="994" alt="CleanShot 2026-07-15 at 15 14 37@2x" src="https://github.com/user-attachments/assets/475dda48-d1c5-4be5-a3c3-7a96b9713724" /> --------- Co-authored-by: Muhsin Keloth <muhsinkeramam@gmail.com>
158 lines
5.8 KiB
Ruby
158 lines
5.8 KiB
Ruby
class Api::V1::AccountsController < Api::BaseController
|
|
include AuthHelper
|
|
include CacheKeysHelper
|
|
|
|
skip_before_action :authenticate_user!, :set_current_user, :handle_with_exception,
|
|
only: [:create], raise: false
|
|
before_action :check_signup_enabled, only: [:create]
|
|
before_action :ensure_account_name, only: [:create]
|
|
before_action :validate_captcha, only: [:create]
|
|
before_action :fetch_account, except: [:create]
|
|
before_action :validate_token_api_access, if: :authenticate_by_access_token?, except: [:create]
|
|
before_action :check_authorization, except: [:create]
|
|
|
|
rescue_from CustomExceptions::Account::InvalidEmail,
|
|
CustomExceptions::Account::InvalidParams,
|
|
CustomExceptions::Account::UserExists,
|
|
CustomExceptions::Account::UserErrors,
|
|
with: :render_error_response
|
|
|
|
def show
|
|
@latest_chatwoot_version = ::Redis::Alfred.get(::Redis::Alfred::LATEST_CHATWOOT_VERSION)
|
|
render 'api/v1/accounts/show', format: :json
|
|
end
|
|
|
|
def create
|
|
@user, @account = AccountBuilder.new(
|
|
account_name: account_params[:account_name],
|
|
user_full_name: account_params[:user_full_name],
|
|
email: account_params[:email],
|
|
user_password: account_params[:password],
|
|
locale: account_params[:locale],
|
|
user: current_user
|
|
).perform
|
|
enqueue_branding_enrichment
|
|
if @user
|
|
# Authenticated users (dashboard "add account") and api_only signups
|
|
# need the full response with account_id. API-only deployments have no
|
|
# frontend to handle the email confirmation flow, so they need auth
|
|
# tokens to proceed.
|
|
# Unauthenticated web signup returns only the email — no session is
|
|
# created until the user confirms via the email link.
|
|
if current_user || api_only_signup?
|
|
send_auth_headers(@user)
|
|
render 'api/v1/accounts/create', format: :json, locals: { resource: @user }
|
|
else
|
|
render json: { email: @user.email }
|
|
end
|
|
else
|
|
render_error_response(CustomExceptions::Account::SignupFailed.new({}))
|
|
end
|
|
end
|
|
|
|
def cache_keys
|
|
expires_in 10.seconds, public: false, stale_while_revalidate: 5.minutes
|
|
render json: { cache_keys: cache_keys_for_account }, status: :ok
|
|
end
|
|
|
|
def update
|
|
@account.assign_attributes(account_params.slice(:name, :locale, :domain, :support_email))
|
|
@account.custom_attributes.merge!(custom_attributes_params)
|
|
@account.settings.merge!(settings_params)
|
|
@account.custom_attributes['onboarding_step'] = 'invite_team' if @account.custom_attributes['onboarding_step'] == 'account_update'
|
|
@account.save!
|
|
end
|
|
|
|
def update_active_at
|
|
@current_account_user.active_at = Time.now.utc
|
|
@current_account_user.save!
|
|
head :ok
|
|
end
|
|
|
|
private
|
|
|
|
def enqueue_branding_enrichment
|
|
email = account_params[:email].presence || @user&.email
|
|
return if email.blank?
|
|
|
|
Account::BrandingEnrichmentJob.perform_later(@account.id, email)
|
|
Redis::Alfred.set(format(Redis::Alfred::ACCOUNT_ONBOARDING_ENRICHMENT, account_id: @account.id), '1', ex: 30)
|
|
rescue StandardError => e
|
|
# Enrichment is optional — never let queue/Redis failures abort signup
|
|
ChatwootExceptionTracker.new(e).capture_exception
|
|
end
|
|
|
|
def ensure_account_name
|
|
# ensure that account_name and user_full_name is present
|
|
# this is becuase the account builder and the models validations are not triggered
|
|
# this change is to align the behaviour with the v2 accounts controller
|
|
# since these values are not required directly there
|
|
return if account_params[:account_name].present?
|
|
return if account_params[:user_full_name].present?
|
|
|
|
raise CustomExceptions::Account::InvalidParams.new({})
|
|
end
|
|
|
|
def cache_keys_for_account
|
|
{
|
|
label: fetch_value_for_key(params[:id], Label.name.underscore),
|
|
inbox: fetch_value_for_key(params[:id], Inbox.name.underscore),
|
|
team: fetch_value_for_key(params[:id], Team.name.underscore)
|
|
}
|
|
end
|
|
|
|
def fetch_account
|
|
@account = current_user.accounts.find(params[:id])
|
|
@current_account_user = @account.account_users.find_by(user_id: current_user.id)
|
|
end
|
|
|
|
def validate_token_api_access
|
|
return if @account.api_and_webhooks_enabled?
|
|
|
|
render json: { error: 'API access is not enabled for this account' }, status: :forbidden
|
|
end
|
|
|
|
def account_params
|
|
params.permit(:account_name, :email, :name, :password, :locale, :domain, :support_email, :user_full_name)
|
|
end
|
|
|
|
def custom_attributes_params
|
|
params.permit(:industry, :company_size, :timezone, :referral_source, :user_role, :website)
|
|
end
|
|
|
|
def settings_params
|
|
params.permit(*permitted_settings_attributes)
|
|
end
|
|
|
|
def permitted_settings_attributes
|
|
[:auto_resolve_after, :auto_resolve_message, :auto_resolve_ignore_waiting, :audio_transcriptions, :auto_resolve_label]
|
|
end
|
|
|
|
def check_signup_enabled
|
|
raise ActionController::RoutingError, 'Not Found' unless GlobalConfigService.account_signup_enabled?
|
|
end
|
|
|
|
def api_only_signup?
|
|
# CW_API_ONLY_SERVER is the canonical flag for API-only deployments.
|
|
# ENABLE_ACCOUNT_SIGNUP='api_only' is a legacy sentinel for the same purpose.
|
|
# Read ENABLE_ACCOUNT_SIGNUP raw from InstallationConfig because GlobalConfig.get
|
|
# typecasts it to boolean, coercing 'api_only' to true.
|
|
ActiveModel::Type::Boolean.new.cast(ENV.fetch('CW_API_ONLY_SERVER', false)) ||
|
|
InstallationConfig.find_by(name: 'ENABLE_ACCOUNT_SIGNUP')&.value.to_s == 'api_only'
|
|
end
|
|
|
|
def validate_captcha
|
|
raise ActionController::InvalidAuthenticityToken, 'Invalid Captcha' unless ChatwootCaptcha.new(params[:h_captcha_client_response]).valid?
|
|
end
|
|
|
|
def pundit_user
|
|
{
|
|
user: current_user,
|
|
account: @account,
|
|
account_user: @current_account_user
|
|
}
|
|
end
|
|
end
|
|
|
|
Api::V1::AccountsController.prepend_mod_with('Api::V1::AccountsSettings')
|