mirror of
https://github.com/Sea-Haven-Industries/google-user-sync.git
synced 2026-05-18 20:20:17 +00:00
Use customer=my_customer to list users across all domains
This commit is contained in:
parent
4b7bb97566
commit
d3a37f3f64
2 changed files with 5 additions and 11 deletions
|
|
@ -8,7 +8,6 @@
|
||||||
* GOOGLE_SECRET_NAME - Secrets Manager name for Google service account JSON key
|
* GOOGLE_SECRET_NAME - Secrets Manager name for Google service account JSON key
|
||||||
* FRONT_SECRET_NAME - Secrets Manager name for Front API token
|
* FRONT_SECRET_NAME - Secrets Manager name for Front API token
|
||||||
* GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate
|
* GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate
|
||||||
* GOOGLE_DOMAIN - Domain to list users for (e.g. seahaven.com)
|
|
||||||
* GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations)
|
* GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations)
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
|
@ -77,13 +76,13 @@ async function getGoogleAccessToken(serviceAccountKey, adminEmail) {
|
||||||
// Google Admin Directory: list users for a specific OU
|
// Google Admin Directory: list users for a specific OU
|
||||||
// ---------------------------------------------------------------------------
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
async function listGoogleUsersInOU(accessToken, domain, orgUnitPath) {
|
async function listGoogleUsersInOU(accessToken, orgUnitPath) {
|
||||||
const users = [];
|
const users = [];
|
||||||
let pageToken = null;
|
let pageToken = null;
|
||||||
|
|
||||||
do {
|
do {
|
||||||
const params = new URLSearchParams({
|
const params = new URLSearchParams({
|
||||||
domain,
|
customer: "my_customer",
|
||||||
maxResults: "500",
|
maxResults: "500",
|
||||||
projection: "full",
|
projection: "full",
|
||||||
orderBy: "email",
|
orderBy: "email",
|
||||||
|
|
@ -111,13 +110,13 @@ async function listGoogleUsersInOU(accessToken, domain, orgUnitPath) {
|
||||||
return users;
|
return users;
|
||||||
}
|
}
|
||||||
|
|
||||||
async function listGoogleUsers(accessToken, domain, orgUnits) {
|
async function listGoogleUsers(accessToken, orgUnits) {
|
||||||
const allUsers = [];
|
const allUsers = [];
|
||||||
const seen = new Set();
|
const seen = new Set();
|
||||||
|
|
||||||
for (const ou of orgUnits) {
|
for (const ou of orgUnits) {
|
||||||
console.log(`Fetching users from OU: ${ou}`);
|
console.log(`Fetching users from OU: ${ou}`);
|
||||||
const users = await listGoogleUsersInOU(accessToken, domain, ou);
|
const users = await listGoogleUsersInOU(accessToken, ou);
|
||||||
console.log(` Found ${users.length} users in ${ou}`);
|
console.log(` Found ${users.length} users in ${ou}`);
|
||||||
|
|
||||||
for (const user of users) {
|
for (const user of users) {
|
||||||
|
|
@ -222,11 +221,7 @@ exports.handler = async (event) => {
|
||||||
.filter(Boolean);
|
.filter(Boolean);
|
||||||
console.log(`Syncing OUs: ${orgUnits.join(", ")}`);
|
console.log(`Syncing OUs: ${orgUnits.join(", ")}`);
|
||||||
|
|
||||||
const googleUsers = await listGoogleUsers(
|
const googleUsers = await listGoogleUsers(accessToken, orgUnits);
|
||||||
accessToken,
|
|
||||||
process.env.GOOGLE_DOMAIN,
|
|
||||||
orgUnits
|
|
||||||
);
|
|
||||||
console.log(`Found ${googleUsers.length} total users across ${orgUnits.length} OUs`);
|
console.log(`Found ${googleUsers.length} total users across ${orgUnits.length} OUs`);
|
||||||
|
|
||||||
// 4. Sync each user to Front
|
// 4. Sync each user to Front
|
||||||
|
|
|
||||||
|
|
@ -40,7 +40,6 @@ class GoogleUserSyncStack extends Stack {
|
||||||
GOOGLE_SECRET_NAME: "google-user-sync/google-service-account",
|
GOOGLE_SECRET_NAME: "google-user-sync/google-service-account",
|
||||||
FRONT_SECRET_NAME: "google-user-sync/front-api-token",
|
FRONT_SECRET_NAME: "google-user-sync/front-api-token",
|
||||||
GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com",
|
GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com",
|
||||||
GOOGLE_DOMAIN: "seahavenind.com",
|
|
||||||
GOOGLE_OUS: "/Office/Scheduling,/Office/Operations",
|
GOOGLE_OUS: "/Office/Scheduling,/Office/Operations",
|
||||||
},
|
},
|
||||||
logRetention: logs.RetentionDays.TWO_MONTHS,
|
logRetention: logs.RetentionDays.TWO_MONTHS,
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue