如何在Alfresco中通过自定义Java WebScript修改审计追踪存储外部用户信息
在Alfresco审计日志中添加外部用户名的解决方案
你完全可以修改Alfresco的审计追踪逻辑,把传入的外部用户名和文档访问信息一起记录下来。这里有两种可行的实现方式,你可以根据自己的需求选择:
方法一:在WebScript代码中手动写入审计数据
这是最直接的方案,你可以在自定义WebScript的业务逻辑里,调用Alfresco的AuditService主动记录包含外部用户名的审计条目。
步骤1:注入所需服务到WebScript类
首先,确保你的WebScript类中注入了AuditService以及其他依赖服务:
import org.alfresco.repo.audit.AuditService; import org.alfresco.repo.security.authentication.AuthenticationUtil; import org.alfresco.service.cmr.repository.NodeRef; import org.alfresco.service.cmr.repository.NodeService; import org.alfresco.service.namespace.NamespaceService; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.extensions.webscripts.DeclarativeWebScript; import org.springframework.extensions.webscripts.WebScriptRequest; import org.springframework.extensions.webscripts.Status; import org.springframework.extensions.webscripts.Cache; import java.util.HashMap; import java.util.Map; import java.io.Serializable; public class CustomDocAccessWebScript extends DeclarativeWebScript { @Autowired private AuditService auditService; @Autowired private NodeService nodeService; @Autowired private NamespaceService namespaceService; // 核心请求处理逻辑 @Override protected Map<String, Object> executeImpl(WebScriptRequest req, Status status, Cache cache) { // 从URL模板中提取参数 String noderefStr = req.getServiceMatch().getTemplateVars().get("noderef"); String externalUsername = req.getServiceMatch().getTemplateVars().get("user"); NodeRef targetNode = new NodeRef(noderefStr); // 执行你的文档访问业务逻辑(比如读取文档内容) // ... // 构建审计数据:包含原有访问信息 + 自定义外部用户名 Map<String, Serializable> auditData = new HashMap<>(); auditData.put("/alfresco-access/transaction/action", "READ"); auditData.put("/alfresco-access/transaction/sub-actions", "readContent"); auditData.put("/alfresco-access/transaction/node", targetNode.toString()); auditData.put("/alfresco-access/transaction/type", "cm:content"); // 获取文档的完整路径 String nodePath = nodeService.getPath(targetNode).toPrefixString(namespaceService); auditData.put("/alfresco-access/transaction/path", nodePath); // 保留系统认证的用户(比如admin) auditData.put("/alfresco-access/transaction/user", AuthenticationUtil.getFullyAuthenticatedUser()); // 添加自定义的外部用户名字段 auditData.put("/alfresco-access/transaction/external-user", externalUsername); // 提交审计条目 auditService.recordAuditEntry("alfresco-access", auditData); // 返回响应结果 Map<String, Object> model = new HashMap<>(); model.put("status", "success"); return model; } }
步骤2:验证效果
调用你的WebScript后,审计日志中会新增包含/alfresco-access/transaction/external-user的条目,显示你传入的外部用户名。
方法二:扩展Alfresco审计配置,自动捕获字段
如果你希望通过Alfresco的审计数据提取器自动处理外部用户名,可以扩展alfresco-access审计应用的配置:
步骤1:修改审计配置文件
找到Alfresco的audit-services-context.xml配置文件,定位到audit.application.alfresco-access的Bean定义,添加自定义路径映射:
<bean id="audit.application.alfresco-access" class="org.alfresco.repo.audit.model.AuditApplication" parent="audit.application.base"> <property name="name" value="alfresco-access"/> <property name="dataExtractors"> <list> <ref bean="audit.extractor.node"/> <ref bean="audit.extractor.path"/> <ref bean="audit.extractor.authentication"/> <ref bean="audit.extractor.action"/> </list> </property> <property name="auditPathMappings"> <map> <!-- 原有路径映射 --> <entry key="/alfresco-access/transaction/node" value="node"/> <entry key="/alfresco-access/transaction/path" value="path"/> <entry key="/alfresco-access/transaction/user" value="user"/> <!-- 添加外部用户名的映射 --> <entry key="/alfresco-access/transaction/external-user" value="externalUser"/> </map> </property> <!-- 确保该路径未被禁用 --> <property name="disabledPaths"> <set> <!-- 保留原有禁用路径,不要添加external-user --> </set> </property> </bean>
步骤2:在WebScript中写入字段
完成配置后,你就可以像方法一中那样,在代码中写入external-user字段,审计系统会自动处理并记录该数据。
注意事项
- 确保运行WebScript的用户(比如admin)拥有
AuditService的访问权限,默认admin已经具备该权限。 - 如果需要保留系统自动生成的原有审计条目,你可以在手动记录额外字段时,确保使用相同的事务ID关联数据,或者直接在原有条目基础上追加字段。
内容的提问来源于stack exchange,提问作者Rohit
相关产品推荐
相关产品推荐

