From d3a37f3f64a77de8e1592174c7cd7d4aede630c8 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 11 May 2026 14:39:57 -0400 Subject: [PATCH] Use customer=my_customer to list users across all domains --- lambda/index.js | 15 +++++---------- lib/google-user-sync-stack.js | 1 - 2 files changed, 5 insertions(+), 11 deletions(-) diff --git a/lambda/index.js b/lambda/index.js index d133ce4..7212742 100644 --- a/lambda/index.js +++ b/lambda/index.js @@ -8,7 +8,6 @@ * GOOGLE_SECRET_NAME - Secrets Manager name for Google service account JSON key * FRONT_SECRET_NAME - Secrets Manager name for Front API token * GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate - * GOOGLE_DOMAIN - Domain to list users for (e.g. seahaven.com) * GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations) */ @@ -77,13 +76,13 @@ async function getGoogleAccessToken(serviceAccountKey, adminEmail) { // Google Admin Directory: list users for a specific OU // --------------------------------------------------------------------------- -async function listGoogleUsersInOU(accessToken, domain, orgUnitPath) { +async function listGoogleUsersInOU(accessToken, orgUnitPath) { const users = []; let pageToken = null; do { const params = new URLSearchParams({ - domain, + customer: "my_customer", maxResults: "500", projection: "full", orderBy: "email", @@ -111,13 +110,13 @@ async function listGoogleUsersInOU(accessToken, domain, orgUnitPath) { return users; } -async function listGoogleUsers(accessToken, domain, orgUnits) { +async function listGoogleUsers(accessToken, orgUnits) { const allUsers = []; const seen = new Set(); for (const ou of orgUnits) { console.log(`Fetching users from OU: ${ou}`); - const users = await listGoogleUsersInOU(accessToken, domain, ou); + const users = await listGoogleUsersInOU(accessToken, ou); console.log(` Found ${users.length} users in ${ou}`); for (const user of users) { @@ -222,11 +221,7 @@ exports.handler = async (event) => { .filter(Boolean); console.log(`Syncing OUs: ${orgUnits.join(", ")}`); - const googleUsers = await listGoogleUsers( - accessToken, - process.env.GOOGLE_DOMAIN, - orgUnits - ); + const googleUsers = await listGoogleUsers(accessToken, orgUnits); console.log(`Found ${googleUsers.length} total users across ${orgUnits.length} OUs`); // 4. Sync each user to Front diff --git a/lib/google-user-sync-stack.js b/lib/google-user-sync-stack.js index be757a7..c8b461d 100644 --- a/lib/google-user-sync-stack.js +++ b/lib/google-user-sync-stack.js @@ -40,7 +40,6 @@ class GoogleUserSyncStack extends Stack { GOOGLE_SECRET_NAME: "google-user-sync/google-service-account", FRONT_SECRET_NAME: "google-user-sync/front-api-token", GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com", - GOOGLE_DOMAIN: "seahavenind.com", GOOGLE_OUS: "/Office/Scheduling,/Office/Operations", }, logRetention: logs.RetentionDays.TWO_MONTHS,