Add check for groups feature flag on SAML group mapping

This commit is contained in:
Carlos Monastyrski
2025-09-30 21:03:41 -03:00
parent c33eba1a91
commit 7e85d3c5a1
2 changed files with 17 additions and 3 deletions
@@ -279,6 +279,12 @@ export const samlConfigServiceFactory = ({
}); });
} }
if (enableGroupSync && !plan.groups) {
throw new BadRequestError({
message: "Failed to enable SAML group sync due to plan restriction. Upgrade plan to enable group sync."
});
}
const { encryptor } = await kmsService.createCipherPairWithDataKey({ const { encryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.Organization, type: KmsDataKey.Organization,
orgId orgId
@@ -338,6 +344,12 @@ export const samlConfigServiceFactory = ({
}); });
} }
if (enableGroupSync && !plan.groups) {
throw new BadRequestError({
message: "Failed to enable SAML group sync due to plan restriction. Upgrade plan to enable group sync."
});
}
const updateQuery: TSamlConfigsUpdate = { const updateQuery: TSamlConfigsUpdate = {
authProvider, authProvider,
isActive, isActive,
@@ -484,7 +496,9 @@ export const samlConfigServiceFactory = ({
const samlConfig = await samlConfigDAL.findOne({ orgId }); const samlConfig = await samlConfigDAL.findOne({ orgId });
const groupsMetadata = metadata?.find(({ key }) => key === "groups"); const groupsMetadata = metadata?.find(({ key }) => key === "groups");
const shouldSyncGroups = !!samlConfig?.enableGroupSync;
const plan = await licenseService.getPlan(orgId);
const shouldSyncGroups = !!samlConfig?.enableGroupSync && !!plan.groups;
let user: TUsers; let user: TUsers;
if (userAlias) { if (userAlias) {
@@ -63,7 +63,7 @@ export const OrgSSOSection = (): JSX.Element => {
try { try {
if (!currentOrg?.id) return; if (!currentOrg?.id) return;
if (!subscription?.samlSSO) { if (!subscription?.samlSSO || !subscription?.groups) {
handlePopUpOpen("upgradePlan"); handlePopUpOpen("upgradePlan");
return; return;
} }
@@ -215,7 +215,7 @@ export const OrgSSOSection = (): JSX.Element => {
id="enable-saml-group-sync" id="enable-saml-group-sync"
isChecked={data?.enableGroupSync ?? false} isChecked={data?.enableGroupSync ?? false}
onCheckedChange={(value) => handleSamlGroupManagement(value)} onCheckedChange={(value) => handleSamlGroupManagement(value)}
isDisabled={!isAllowed} isDisabled={!isAllowed || !subscription?.groups}
/> />
)} )}
</OrgPermissionCan> </OrgPermissionCan>