trigger-user-save.js 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255
  1. // https://docs.authing.co/v2/reference/sdk-for-node/management/UsersManagementClient.html
  2. const { ManagementClient } = require('authing-node-sdk')
  3. const managementClient = new ManagementClient({
  4. accessKeyId: '6686bffb373d06911e24a969',
  5. accessKeySecret: "4e978331675938d1bc81fb109e67d59a",
  6. host: 'https://textbook.u2-dev.hep.com.cn', // 应用的认证地址
  7. })
  8. /**
  9. * 用户创建前,创建用户至Authing
  10. * @desc 仅同步注册信息及密码,资料在afterSave中同步
  11. */
  12. export function defineUserBeforeSave(){
  13. Parse.Cloud.beforeSave("_User", async (request) => {
  14. request.object = appendUserACL(request.object)
  15. let user = request.object;
  16. // 仅首次注册/创建用户/修改密码有password属性,同步Authing账号
  17. let password = user?.get("password");
  18. if(password){
  19. let mobile = user?.get("mobile");
  20. let email = user?.get("email");
  21. let username = user?.get("username");
  22. let externalId = user?.id;
  23. let authingUserExists = await findUserByMobileEmailUserName(user)
  24. if(authingUserExists?.statusCode==404){ // 创建用户
  25. let newuser = {
  26. status:"Activated",
  27. }
  28. if(mobile){newuser.phone = mobile}
  29. if(email){newuser.email = email}
  30. if(username){newuser.username = username}
  31. if(externalId){newuser.externalId = externalId}
  32. result = await managementClient.createUser(newuser)
  33. }
  34. if(authingUserExists?.statusCode==200){
  35. let existsUser = authingUserExists?.data;
  36. try{
  37. let updateRes = await managementClient.updateUser({
  38. userId:existsUser?.userId,
  39. password:password,
  40. })
  41. // console.log(result)
  42. }catch(err){console.log(err)}
  43. }
  44. }
  45. });
  46. }
  47. function appendUserACL(user){
  48. let acl = user?.getACL();
  49. if(!acl) acl = new Parse.ACL();
  50. // 添加superadmin用户的可读可写权限
  51. acl.setRoleWriteAccess("superadmin", true);
  52. acl.setRoleReadAccess("superadmin", true);
  53. // 添加admin用户的可读可写权限
  54. acl.setRoleWriteAccess("admin", true);
  55. acl.setRoleReadAccess("admin", true);
  56. // 添加manager用户的可读可写权限
  57. acl.setRoleWriteAccess("manager", true);
  58. acl.setRoleReadAccess("manager", true);
  59. // 添加公共可读权限
  60. acl.setPublicReadAccess(true);
  61. user.setACL(acl);
  62. return user
  63. }
  64. /**
  65. * 用户删除前,删除用户从Authing
  66. */
  67. export function defineUserBeforeDelete(){
  68. Parse.Cloud.beforeDelete("_User", async (request) => {
  69. let user = request.object;
  70. // console.log(user.toJSON());
  71. // console.log(user?.get("password"))
  72. try{
  73. let authingUserExists = await findUserByMobileEmailUserName(user)
  74. if(authingUserExists?.statusCode==200){
  75. let existsUser = authingUserExists?.data;
  76. let deleteRes = await managementClient.deleteUsersBatch({
  77. // 替换用户 ID 数组
  78. userIds: [existsUser.userId],
  79. options: {
  80. userIdType: "user_id"
  81. }
  82. });
  83. }
  84. }catch(deleteErr){}
  85. });
  86. }
  87. /**
  88. * 用户保存后同步数据至Authing
  89. */
  90. export function defineUserAfterSave(){
  91. Parse.Cloud.afterSave("_User", async (request) => {
  92. // console.log("save _User",request?.object?.id)
  93. let query = new Parse.Query("Profile");
  94. query.equalTo("user",request?.object?.id)
  95. let profile = await query.first();
  96. syncUserProfileToAuthing(request?.object,profile)
  97. });
  98. Parse.Cloud.afterSave("Profile", async (request) => {
  99. // console.log("save Profile",request?.object?.id)
  100. let query = new Parse.Query("Profile");
  101. let userPointer = request?.object?.get("user")
  102. query.include("user");
  103. console.log(userPointer)
  104. profile = await query.get(request?.object?.id,{useMasterKey:true});
  105. syncUserProfileToAuthing(profile.get("user"),profile)
  106. appandUserToRole(profile.get("user")?.toPointer() || userPointer,profile?.get("identity"))
  107. });
  108. }
  109. // 同步Profile角色身份
  110. async function appandUserToRole(user,roleName) {
  111. console.log(user,roleName)
  112. let id = user?.id || user?.objectId
  113. if(!id || !roleName) return
  114. let userObj = new Parse.User();
  115. userObj.id = id;
  116. let query = new Parse.Query(Parse.Role);
  117. query.equalTo("name", roleName);
  118. try{
  119. let role = await query.first({ useMasterKey: true });
  120. console.log(role?.toJSON())
  121. if (role?.toJSON()?.name) {
  122. let usersRelation = role.relation("users");
  123. usersRelation.add(userObj);
  124. await role.save(null, { useMasterKey: true });
  125. let users = await usersRelation.query().find({ useMasterKey: true });
  126. console.log('Users in role after addition:', users.map(u => u.toJSON()));
  127. }
  128. }catch(err){
  129. console.error(err)
  130. }
  131. }
  132. /**
  133. * 查询用户
  134. * @param {*} user
  135. * @returns
  136. * 不存在:
  137. * {
  138. statusCode: 404,
  139. apiCode: 2004,
  140. message: '用户不存在',
  141. requestId: 'e59cb407-f2d9-4bd8-ac93-d2dbc8d6ab72'
  142. }
  143. {
  144. statusCode: 200,
  145. message: '',
  146. data: {
  147. userId: '669676e5a3a9ac870bfff2a3',
  148. createdAt: '2024-07-16T13:34:29.789Z',
  149. updatedAt: '2024-07-16T13:34:29.789Z',
  150. status: 'Activated'
  151. }
  152. }
  153. */
  154. async function findUserByMobileEmailUserName(user){
  155. let mobile = user?.get("mobile");
  156. let email = user?.get("email");
  157. let username = user?.get("username");
  158. let externalId = user?.id;
  159. let result;
  160. if(email){
  161. try{
  162. result = await managementClient.getUser({userIdType:`email`,userId:email})
  163. // console.log(email,result)
  164. }catch(err){}
  165. }
  166. if(mobile&&(!result || result?.statusCode==404)){
  167. try{
  168. result = await managementClient.getUser({userIdType:`phone`,userId:mobile})
  169. // console.log(mobile,result)
  170. }catch(err){}
  171. }
  172. if(username&&(!result || result?.statusCode==404)){
  173. try{
  174. result = await managementClient.getUser({userIdType:`username`,userId:username})
  175. // console.log("username",username,result)
  176. }catch(err){}
  177. }
  178. if(externalId&&(!result || result?.statusCode==404)){
  179. try{
  180. result = await managementClient.getUser({userIdType:`external_id`,userId:externalId})
  181. // console.log(externalId,result)
  182. }catch(err){}
  183. }
  184. return result
  185. }
  186. async function syncUserProfileToAuthing(user,profile){
  187. if(!user?.id) return
  188. let userInfo = user.toJSON();
  189. userInfo = fixJsonFileds(userInfo)
  190. if(profile?.id){
  191. let pjson = profile.toJSON();
  192. delete pjson.objectId;
  193. pjson= fixJsonFileds(pjson)
  194. Object.keys(pjson).forEach(key=>{
  195. userInfo[key] = pjson[key]
  196. })
  197. }
  198. // 映射对应字段
  199. userInfo.company = userInfo.companyName
  200. delete userInfo.companyName
  201. userInfo.userType = userInfo.identity
  202. delete userInfo.identity
  203. userInfo.userId = userInfo.objectId
  204. let authingUserExists = await findUserByMobileEmailUserName(user)
  205. if(authingUserExists?.statusCode==200){
  206. let existsUser = authingUserExists?.data;
  207. userInfo.userId = existsUser.userId
  208. }
  209. delete userInfo.objectId
  210. userInfo.identifyStatus = userInfo.accountState
  211. // 自定义数据全量同步
  212. userInfo.customData = JSON.parse(JSON.stringify(userInfo))
  213. // {
  214. // identifyStatus : userInfo.accountState
  215. // }
  216. // console.log(userInfo)
  217. // 同步数据至Authing用户池
  218. let result
  219. try{
  220. result = await managementClient.updateUser(userInfo)
  221. // console.log(result)
  222. }catch(err){console.log(err)}
  223. }
  224. function fixJsonFileds(json){
  225. // Parse独有关系数据
  226. delete json.ACL
  227. delete json.className
  228. delete json.sessionToken
  229. delete json.company
  230. delete json.user
  231. delete json.createdAt
  232. delete json.updatedAt
  233. // 来自Authing的数据
  234. delete json?.loginsCount
  235. delete json?.lastIP
  236. delete json?.lastLogin
  237. return json
  238. }