Use customer=my_customer to list users across all domains

This commit is contained in:
Adam Moussa 2026-05-11 14:39:57 -04:00
parent 4b7bb97566
commit d3a37f3f64
2 changed files with 5 additions and 11 deletions

View file

@ -8,7 +8,6 @@
* GOOGLE_SECRET_NAME - Secrets Manager name for Google service account JSON key * GOOGLE_SECRET_NAME - Secrets Manager name for Google service account JSON key
* FRONT_SECRET_NAME - Secrets Manager name for Front API token * FRONT_SECRET_NAME - Secrets Manager name for Front API token
* GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate * GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate
* GOOGLE_DOMAIN - Domain to list users for (e.g. seahaven.com)
* GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations) * GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations)
*/ */
@ -77,13 +76,13 @@ async function getGoogleAccessToken(serviceAccountKey, adminEmail) {
// Google Admin Directory: list users for a specific OU // Google Admin Directory: list users for a specific OU
// --------------------------------------------------------------------------- // ---------------------------------------------------------------------------
async function listGoogleUsersInOU(accessToken, domain, orgUnitPath) { async function listGoogleUsersInOU(accessToken, orgUnitPath) {
const users = []; const users = [];
let pageToken = null; let pageToken = null;
do { do {
const params = new URLSearchParams({ const params = new URLSearchParams({
domain, customer: "my_customer",
maxResults: "500", maxResults: "500",
projection: "full", projection: "full",
orderBy: "email", orderBy: "email",
@ -111,13 +110,13 @@ async function listGoogleUsersInOU(accessToken, domain, orgUnitPath) {
return users; return users;
} }
async function listGoogleUsers(accessToken, domain, orgUnits) { async function listGoogleUsers(accessToken, orgUnits) {
const allUsers = []; const allUsers = [];
const seen = new Set(); const seen = new Set();
for (const ou of orgUnits) { for (const ou of orgUnits) {
console.log(`Fetching users from OU: ${ou}`); console.log(`Fetching users from OU: ${ou}`);
const users = await listGoogleUsersInOU(accessToken, domain, ou); const users = await listGoogleUsersInOU(accessToken, ou);
console.log(` Found ${users.length} users in ${ou}`); console.log(` Found ${users.length} users in ${ou}`);
for (const user of users) { for (const user of users) {
@ -222,11 +221,7 @@ exports.handler = async (event) => {
.filter(Boolean); .filter(Boolean);
console.log(`Syncing OUs: ${orgUnits.join(", ")}`); console.log(`Syncing OUs: ${orgUnits.join(", ")}`);
const googleUsers = await listGoogleUsers( const googleUsers = await listGoogleUsers(accessToken, orgUnits);
accessToken,
process.env.GOOGLE_DOMAIN,
orgUnits
);
console.log(`Found ${googleUsers.length} total users across ${orgUnits.length} OUs`); console.log(`Found ${googleUsers.length} total users across ${orgUnits.length} OUs`);
// 4. Sync each user to Front // 4. Sync each user to Front

View file

@ -40,7 +40,6 @@ class GoogleUserSyncStack extends Stack {
GOOGLE_SECRET_NAME: "google-user-sync/google-service-account", GOOGLE_SECRET_NAME: "google-user-sync/google-service-account",
FRONT_SECRET_NAME: "google-user-sync/front-api-token", FRONT_SECRET_NAME: "google-user-sync/front-api-token",
GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com", GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com",
GOOGLE_DOMAIN: "seahavenind.com",
GOOGLE_OUS: "/Office/Scheduling,/Office/Operations", GOOGLE_OUS: "/Office/Scheduling,/Office/Operations",
}, },
logRetention: logs.RetentionDays.TWO_MONTHS, logRetention: logs.RetentionDays.TWO_MONTHS,