身份函式庫用於管理 Azure 通訊服務 的使用者與令牌。
開始使用
Prerequisites
- Azure 訂用帳戶。
- 現有的通訊服務資源。 如果您需要建立資源,您可以使用 Azure 入口網站、Azure PowerShell或 Azure CLI。
安裝
npm install @azure/communication-identity
瀏覽器支援
JavaScript 套件組合
若要在瀏覽器中使用此用戶端連結庫,您必須先使用配套程式。 如需如何執行這項操作的詳細資訊,請參閱我們的 組合檔。
關鍵概念
Clients
它 CommunicationIdentityClient 提供了管理用戶及其代幣的方法。
Examples
Authentication
你可以從 Azure 入口網站 的 Communication Services 資源取得金鑰和/或 連接字串。 一旦你擁有金鑰,就可以用以下任一方法來驗證:CommunicationIdentityClient
在初始化客戶端前先建立KeyCredentialAzureKeyCredential
import { AzureKeyCredential } from "@azure/core-auth";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const key = "<some-key>";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new AzureKeyCredential(key);
const client = new CommunicationIdentityClient(endpoint, credential);
使用連接字串
import { CommunicationIdentityClient } from "@azure/communication-identity";
// Example connection string
const connectionString =
"endpoint=https://contoso.eastus.communications.azure.net/;accesskey=secret";
const client = new CommunicationIdentityClient(connectionString);
使用 TokenCredential
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
如果您使用金鑰來初始化用戶端,則也需要提供適當的端點。 您可以從 Azure 入口網站中的通訊服務資源取得此端點,。
Usage
建立新使用者
使用該 createUser 方法建立新使用者。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
const user = await client.createUser();
建立與刷新使用者憑證
使用此 getToken 方法為現有使用者發行或刷新代幣。 此方法同時包含通訊令牌範圍的清單。 範圍選項包括:
-
chat(使用此功能以完整存取聊天 API) -
voip(使用此資料以完整存取呼叫 API) -
chat.join(可存取聊天 API,但無需授權建立、刪除或更新聊天串) -
chat.join.limited(chat.join 的較有限版本,不允許新增或移除參與者) -
voip.join(存取呼叫 API,但未授權開始新通話)
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
const user = await client.createUser();
const { token } = await client.getToken(user, ["chat"]);
要刷新使用者令牌,請以同一使用者發行另一個令牌。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
const user = await client.createUser();
let { token } = await client.getToken(user, ["chat"]);
// Refresh the token again
({ token } = await client.getToken(user, ["chat"]));
建立具有自訂到期期限的使用者憑證
也可以透過自訂有效期限來建立通訊身份存取權杖。 代幣的有效期必須在 [60,1440] 分鐘範圍內。 若未提供,則使用預設值1440分鐘(24小時)。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
const user = await client.createUser();
const tokenOptions = { tokenExpiresInMinutes: 60 };
const { token } = await client.getToken(user, ["chat"], tokenOptions);
在單一請求中建立使用者與權杖
為了方便起見,可以用 createUserAndToken 一個函式呼叫建立新使用者並發出一個令牌。 這代表只需一個網路請求,而不是先建立使用者再發出代幣。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
const { user, token } = await client.createUserAndToken(["chat"]);
在單一請求中建立使用者與權杖並自訂到期
也可以透過自訂有效期限來建立通訊身份存取權杖。 代幣的有效期必須在 [60,1440] 分鐘範圍內。 若未提供,則使用預設值1440分鐘(24小時)。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
const userAndTokenOptions = { tokenExpiresInMinutes: 60 };
const { user, token } = await client.createUserAndToken(["chat"], userAndTokenOptions);
為使用者撤銷代幣
使用此 revokeTokens 方法撤銷所有已發行的使用者代幣。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
// Create user
const user = await client.createUser();
// Later when you want to revoke the user's tokens
await client.revokeTokens(user);
刪除使用者
使用 deleteUser 刪除使用者的方法。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
// Create user
const user = await client.createUser();
// Later when you want to delete the user
await client.deleteUser(user);
將 Teams 使用者的 Azure AD 存取權杖換成通訊存取權杖
使用getTokenForTeamsUser方法將 Teams 使用者的 Azure AD 存取權杖換成一個有效期限相符的新CommunicationAccessToken憑證。
import { DefaultAzureCredential } from "@azure/identity";
import { CommunicationIdentityClient } from "@azure/communication-identity";
const endpoint = "https://contoso.eastus.communications.azure.net";
const credential = new DefaultAzureCredential();
const client = new CommunicationIdentityClient(endpoint, credential);
const { token, expiresOn } = await client.getTokenForTeamsUser({
teamsUserAadToken: "<aad-access-token-of-a-teams-user>",
clientId: "<cliend-id-of-an-aad-application>",
userObjectId: "<aad-object-id-of-a-teams-user>",
});
Troubleshooting
Logging
啟用記錄可能有助於找出有關失敗的實用資訊。 若要查看 HTTP 要求和回應的記錄,請將 AZURE_LOG_LEVEL 環境變數設定為 info。 或者,您可以在運行時間啟用記錄,方法是在 setLogLevel中呼叫 @azure/logger:
import { setLogLevel } from "@azure/logger";
setLogLevel("info");
下一步
如需如何使用此連結庫的詳細範例,請參閱 範例 目錄。
Contributing
如果你想為這個函式庫貢獻,請閱讀 contributing guide,了解更多如何建置與測試程式碼。