以下代码使用
Azure Active Directory Authentication Library (ADAL) for Node.js
和
request
要与之交互的包
the Azure AD Graph API
.
1) 获取用于Azure AD Graph API的访问令牌:
const AuthenticationContext = require("adal-node").AuthenticationContext;
const tenant = "myb2cdomain.onmicrosoft.com";
const authority = `https://login.microsoftonline.com/{tenant}`;
const authenticationContext = new AuthenticationContext(authority);
function acquireTokenForApplication(clientId, clientSecret, callback) {
authenticationContext.acquireTokenWithClientCredentials("https://graph.windows.net/", clientId, clientSecret, function(err, tokenResponse) {
if (err) {
callback(err);
return;
}
callback(null, tokenResponse.access_token);
});
}
2) 创建用户对象:
const userToBeCreated = {
accountEnabled: true,
creationType: "LocalAccount",
displayName: "Alex Wu",
passwordPolicies: "DisablePasswordExpiration",
passwordProfile: {
forceChangePasswordNextLogin: false,
password: "Test1234"
},
signInNames: [
{
type: "emailAddress",
value: "alexw@example.com"
}
],
"extension_xxx_<customAttributeName>": <customAttributeValue>
};
其中,“xxx”必须替换为
b2c-extensions-app
应用
例如。:
"extension_ab603c56068041afb2f6832e2a17e237_SkypeId": "alexw.skype"
3) 将用户对象发送到
the Azure AD Graph API
:
function createUser(tenantId, accessToken, userToBeCreated, callback) {
request.post({
url: `https://graph.windows.net/${encodeURIComponent(tenantId)}/users?api-version=1.6`,
auth: {
bearer: accessToken
},
body: userToBeCreated,
json: true
}, (err, response, responseBody) => {
if (err) {
callback(err);
return;
}
if (!isSuccessStatusCode(response.statusCode)) {
const errorResult = responseBody;
callback({
code: errorResult["odata.error"].code,
message: errorResult["odata.error"].message.value
});
return;
}
const createdUser = responseBody;
callback(null, createdUser);
});
}