Multi-integration Webex chat/HTTP bot that unifies phone, AV, and network status for retail store support. Consolidates data from Webex Calling, Meraki, Workspace ONE (MDM), Atlas AMP, RED digital signage, and OptiSigns into rich per-store status commands. Key surfaces: - /phonestatus, /avstatus — per-store phone & AV device reports with clickable Meraki deep-links and per-port detail. - /webexhost — check/assign Webex Meetings host licenses via the Service App; adaptive-card confirmation flow, HTTP-API-gated. - /offboarduser — full Webex Admin offboarding (auth revoke, device wipe, license removal); adaptive-card confirmation. - /jirapoll — on-demand trigger for the hourly Jira poller. - /bulkavstatuscsv — bulk store CSV export with concurrency limits. Automation: - Hourly Jira poller (node-cron) with an X.AI (Grok) ticket classifier that categorizes unassigned tickets as phone/av/skip, extracts store numbers from free-text, and enriches Jira with the same detailed markdown the chat commands emit (converted to Jira ADF, preserves bold + Meraki links). Idempotent via a `bot-enriched` Jira label. Architecture: - Node.js 20+, ESM, Express 5, webex-node-bot-framework. - Layered integrations (integrations/*), services (services/*), commands (commands/*), utils (utils/*). - Shared markdown renderers (services/renderers/*) feed both chat handlers and the Jira poller so the two surfaces stay in sync. - Hand-rolled markdown-to-ADF converter (utils/markdownToAdf.js) — no new npm dependency. - Node built-in test runner (`node --test tests/*.test.js`), 30 tests covering the converter, renderers, and poller ADF assembly. Docker + docker-compose deployment. Config via .env (see .env.example for the full option surface).
71 lines
No EOL
2.1 KiB
JavaScript
71 lines
No EOL
2.1 KiB
JavaScript
// src/integrations/digicert/DigiCertClient.js
|
|
import axios from 'axios';
|
|
import { logger } from '../../utils/logger.js';
|
|
|
|
class DigiCertClient {
|
|
static #instance = null;
|
|
|
|
constructor() {
|
|
if (DigiCertClient.#instance) return DigiCertClient.#instance;
|
|
|
|
const apiKey = process.env.DIGICERT_API_KEY;
|
|
const baseURL = process.env.DIGICERT_BASE_URL || 'https://one.digicert.com';
|
|
|
|
if (!apiKey) {
|
|
logger('digicert:client', 'DIGICERT_API_KEY is missing from environment', 'error');
|
|
throw new Error('Missing DIGICERT_API_KEY');
|
|
}
|
|
|
|
this.client = axios.create({
|
|
baseURL,
|
|
headers: {
|
|
'x-api-key': apiKey,
|
|
'Content-Type': 'application/json',
|
|
'Accept': 'application/json'
|
|
},
|
|
timeout: 60000
|
|
});
|
|
|
|
DigiCertClient.#instance = this;
|
|
logger('digicert:client', 'DigiCertClient initialized');
|
|
}
|
|
|
|
async enrollCertificate(csrBase64, commonName, deviceIp) {
|
|
const seatEmail = process.env.DIGICERT_SEAT_EMAIL;
|
|
if (!seatEmail) {
|
|
// Previously this silently fell back to a hardcoded personal address,
|
|
// which both pinned every cert to one person's email and leaked the
|
|
// identity through the source. Fail loud so misconfig is obvious.
|
|
throw new Error('DIGICERT_SEAT_EMAIL is not set in environment');
|
|
}
|
|
|
|
const payload = {
|
|
profile: { id: process.env.DIGICERT_PROFILE_ID },
|
|
csr: csrBase64,
|
|
seat: {
|
|
seat_id: `${commonName}-${Date.now()}`,
|
|
seat_email: seatEmail,
|
|
},
|
|
attributes: {
|
|
subject: { common_name: commonName },
|
|
extensions: {
|
|
san: {
|
|
dns_names: [commonName],
|
|
ip_addresses: [deviceIp]
|
|
}
|
|
}
|
|
}
|
|
};
|
|
|
|
const response = await this.client.post('/mpki/api/v1/certificate', payload);
|
|
return response.data;
|
|
}
|
|
|
|
async pickupCertificate(requestId) {
|
|
const payload = { profile: { id: process.env.DIGICERT_PROFILE_ID } };
|
|
const response = await this.client.post(`/mpki/api/v1/certificate-pickup/${requestId}`, payload);
|
|
return response.data;
|
|
}
|
|
}
|
|
|
|
export default new DigiCertClient(); |