You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Alfresco中通过自定义Java WebScript修改审计追踪存储外部用户信息

在Alfresco审计日志中添加外部用户名的解决方案

你完全可以修改Alfresco的审计追踪逻辑,把传入的外部用户名和文档访问信息一起记录下来。这里有两种可行的实现方式,你可以根据自己的需求选择:

方法一:在WebScript代码中手动写入审计数据

这是最直接的方案,你可以在自定义WebScript的业务逻辑里,调用Alfresco的AuditService主动记录包含外部用户名的审计条目。

步骤1:注入所需服务到WebScript类

首先,确保你的WebScript类中注入了AuditService以及其他依赖服务:

import org.alfresco.repo.audit.AuditService;
import org.alfresco.repo.security.authentication.AuthenticationUtil;
import org.alfresco.service.cmr.repository.NodeRef;
import org.alfresco.service.cmr.repository.NodeService;
import org.alfresco.service.namespace.NamespaceService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.extensions.webscripts.DeclarativeWebScript;
import org.springframework.extensions.webscripts.WebScriptRequest;
import org.springframework.extensions.webscripts.Status;
import org.springframework.extensions.webscripts.Cache;
import java.util.HashMap;
import java.util.Map;
import java.io.Serializable;

public class CustomDocAccessWebScript extends DeclarativeWebScript {

    @Autowired
    private AuditService auditService;
    @Autowired
    private NodeService nodeService;
    @Autowired
    private NamespaceService namespaceService;

    // 核心请求处理逻辑
    @Override
    protected Map<String, Object> executeImpl(WebScriptRequest req, Status status, Cache cache) {
        // 从URL模板中提取参数
        String noderefStr = req.getServiceMatch().getTemplateVars().get("noderef");
        String externalUsername = req.getServiceMatch().getTemplateVars().get("user");
        NodeRef targetNode = new NodeRef(noderefStr);

        // 执行你的文档访问业务逻辑(比如读取文档内容)
        // ...

        // 构建审计数据:包含原有访问信息 + 自定义外部用户名
        Map<String, Serializable> auditData = new HashMap<>();
        auditData.put("/alfresco-access/transaction/action", "READ");
        auditData.put("/alfresco-access/transaction/sub-actions", "readContent");
        auditData.put("/alfresco-access/transaction/node", targetNode.toString());
        auditData.put("/alfresco-access/transaction/type", "cm:content");
        // 获取文档的完整路径
        String nodePath = nodeService.getPath(targetNode).toPrefixString(namespaceService);
        auditData.put("/alfresco-access/transaction/path", nodePath);
        // 保留系统认证的用户(比如admin)
        auditData.put("/alfresco-access/transaction/user", AuthenticationUtil.getFullyAuthenticatedUser());
        // 添加自定义的外部用户名字段
        auditData.put("/alfresco-access/transaction/external-user", externalUsername);

        // 提交审计条目
        auditService.recordAuditEntry("alfresco-access", auditData);

        // 返回响应结果
        Map<String, Object> model = new HashMap<>();
        model.put("status", "success");
        return model;
    }
}

步骤2:验证效果

调用你的WebScript后,审计日志中会新增包含/alfresco-access/transaction/external-user的条目,显示你传入的外部用户名。

方法二:扩展Alfresco审计配置,自动捕获字段

如果你希望通过Alfresco的审计数据提取器自动处理外部用户名,可以扩展alfresco-access审计应用的配置:

步骤1:修改审计配置文件

找到Alfresco的audit-services-context.xml配置文件,定位到audit.application.alfresco-access的Bean定义,添加自定义路径映射:

<bean id="audit.application.alfresco-access" class="org.alfresco.repo.audit.model.AuditApplication" parent="audit.application.base">
    <property name="name" value="alfresco-access"/>
    <property name="dataExtractors">
        <list>
            <ref bean="audit.extractor.node"/>
            <ref bean="audit.extractor.path"/>
            <ref bean="audit.extractor.authentication"/>
            <ref bean="audit.extractor.action"/>
        </list>
    </property>
    <property name="auditPathMappings">
        <map>
            <!-- 原有路径映射 -->
            <entry key="/alfresco-access/transaction/node" value="node"/>
            <entry key="/alfresco-access/transaction/path" value="path"/>
            <entry key="/alfresco-access/transaction/user" value="user"/>
            <!-- 添加外部用户名的映射 -->
            <entry key="/alfresco-access/transaction/external-user" value="externalUser"/>
        </map>
    </property>
    <!-- 确保该路径未被禁用 -->
    <property name="disabledPaths">
        <set>
            <!-- 保留原有禁用路径,不要添加external-user -->
        </set>
    </property>
</bean>

步骤2:在WebScript中写入字段

完成配置后,你就可以像方法一中那样,在代码中写入external-user字段,审计系统会自动处理并记录该数据。

注意事项

  • 确保运行WebScript的用户(比如admin)拥有AuditService的访问权限,默认admin已经具备该权限。
  • 如果需要保留系统自动生成的原有审计条目,你可以在手动记录额外字段时,确保使用相同的事务ID关联数据,或者直接在原有条目基础上追加字段。

内容的提问来源于stack exchange,提问作者Rohit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:25:34