148c17327b87cdaa0e3eadf497b539f7e0eb9a2e
[motion2.git] / server / api / cloudProvider / cloudProvider.oauth.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x6344=['audience','isAfter','resolve','then','data3','CloudProvider','refresh_token','data6','POST','access_token','update','data5','error','Failed\x20to\x20refresh\x20access\x20token\x20for\x20cloud\x20provider\x20#%s,\x20-\x20err:%s','authorization_code','decryptString','intervals','bind','findAll','all','catch','[CLOUD_PROVIDER]\x20Error\x20while\x20refreshing\x20the\x20tokens\x20after\x20service\x20restart\x20error:%s','exports','lodash','crypto','moment','ioredis','request-promise','util','../../components/encryptor','../../config/environment','../../config/logger','../../config/schedule/cloud-provider','../../mysqldb','redis','defaults','localhost','https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0','openid','profile','https://outlook.office365.com/IMAP.AccessAsUser.All','https://outlook.office.com/POP.AccessAsUser.All','https://outlook.office.com/SMTP.Send','offline_access','/authorize','map','type','Dynamics365','push','data7','/.default','join','replace','{TENANT_ID}','data2','code','id_token','from','randomBytes','hex','client_id','redirect_uri','data4','response_mode','form_post','scope','nonce','prompt','login','key','value','data1','stringify','decode','payload','issuer','aud'];(function(_0xc6e78e,_0x1fbd19){var _0x1dac61=function(_0x137f2e){while(--_0x137f2e){_0xc6e78e['push'](_0xc6e78e['shift']());}};_0x1dac61(++_0x1fbd19);}(_0x6344,0x1e5));var _0x4634=function(_0x21549c,_0x6d64d1){_0x21549c=_0x21549c-0x0;var _0x426cbd=_0x6344[_0x21549c];return _0x426cbd;};'use strict';var _=require(_0x4634('0x0'));var crypto=require(_0x4634('0x1'));var jwt=require('jsonwebtoken');var moment=require(_0x4634('0x2'));var Redis=require(_0x4634('0x3'));var rp=require(_0x4634('0x4'));var util=require(_0x4634('0x5'));var encryptor=require(_0x4634('0x6'));var config=require(_0x4634('0x7'));var logger=require(_0x4634('0x8'))('api');var schedule=require(_0x4634('0x9'));var db=require(_0x4634('0xa'))['db'];config[_0x4634('0xb')]=_[_0x4634('0xc')](config['redis'],{'host':_0x4634('0xd'),'port':0x18eb});var redis=new Redis(config[_0x4634('0xb')]);var MICROSOFT_AUTH_URL=_0x4634('0xe');var AZURE_AUTH_SCOPES={'Outlook365':[_0x4634('0xf'),_0x4634('0x10'),'email','offline_access',_0x4634('0x11'),_0x4634('0x12'),_0x4634('0x13')],'Dynamics365':['openid',_0x4634('0x14')]};var MICROSOFT_AUTH_ENDPOINT=_0x4634('0x15');var MICROSOFT_TOKEN_ENDPOINT='/token';var OAUTH_REFRESH_INTERVAL=0xfa;function getAuthorizationScopes(_0x4a83e6){var _0xd238fa=_[_0x4634('0x16')](AZURE_AUTH_SCOPES[_0x4a83e6['type']]);if(_0x4a83e6[_0x4634('0x17')]===_0x4634('0x18'))_0xd238fa[_0x4634('0x19')](_0x4a83e6[_0x4634('0x1a')]+_0x4634('0x1b'));return _0xd238fa[_0x4634('0x1c')]('\x20');}function getAccessTokenScope(_0x15c1bf){if(_0x15c1bf[_0x4634('0x17')]==='Outlook365')return _0x4634('0x11');if(_0x15c1bf[_0x4634('0x17')]===_0x4634('0x18'))return _0x15c1bf[_0x4634('0x1a')]+_0x4634('0x1b');}function generateMicrosoftAuthorizationUrl(_0xa4f597,_0x577ea1){var _0x3e21e3=MICROSOFT_AUTH_URL[_0x4634('0x1d')](_0x4634('0x1e'),_0xa4f597[_0x4634('0x1f')]);var _0x1bc0f7=[_0x4634('0x20'),_0x4634('0x21')];var _0x32205a=Buffer[_0x4634('0x22')](JSON['stringify']({'id':_0x577ea1}))['toString']('base64');var _0x3d8453=crypto[_0x4634('0x23')](0x10)['toString'](_0x4634('0x24'));var _0x156b45=getAuthorizationScopes(_0xa4f597);var _0x17cdbb=[{'key':_0x4634('0x25'),'value':_0xa4f597['data1']},{'key':'response_type','value':encodeURIComponent(_0x1bc0f7[_0x4634('0x1c')]('\x20'))},{'key':_0x4634('0x26'),'value':_0xa4f597[_0x4634('0x27')]},{'key':_0x4634('0x28'),'value':_0x4634('0x29')},{'key':_0x4634('0x2a'),'value':encodeURIComponent(_0x156b45)},{'key':'state','value':_0x32205a},{'key':_0x4634('0x2b'),'value':_0x3d8453},{'key':_0x4634('0x2c'),'value':_0x4634('0x2d')}];var _0x3c31d3=_0x3e21e3+MICROSOFT_AUTH_ENDPOINT+'?'+_[_0x4634('0x16')](_0x17cdbb,function(_0x253238){return _0x253238[_0x4634('0x2e')]+'='+_0x253238[_0x4634('0x2f')];})[_0x4634('0x1c')]('&');_0xa4f597['oauth2Claims']={'issuer':_0x3e21e3[_0x4634('0x1d')]('oauth2/',''),'audience':_0xa4f597[_0x4634('0x30')],'state':_0x32205a,'nonce':_0x3d8453};redis['set'](_0x32205a,JSON[_0x4634('0x31')](_0xa4f597));return _0x3c31d3;}function isValidIdToken(_0x43481c,_0x4c0228){try{var _0x3a6c27=jwt[_0x4634('0x32')](_0x43481c,{'complete':!![]});var _0x25c30e=_0x3a6c27[_0x4634('0x33')];if(_0x25c30e['iss']!==_0x4c0228[_0x4634('0x34')])return![];if(_0x25c30e[_0x4634('0x35')]!==_0x4c0228[_0x4634('0x36')])return![];if(_0x25c30e[_0x4634('0x2b')]!==_0x4c0228[_0x4634('0x2b')])return![];if(moment()[_0x4634('0x37')](moment['unix'](_0x25c30e['exp'])))return![];return!![];}catch(_0x5c03da){throw _0x5c03da;}}function refreshOauth2MicrosoftAccessToken(_0x43dcc6){return Promise[_0x4634('0x38')]()[_0x4634('0x39')](function(){if(_0x43dcc6[_0x4634('0x3a')])return _0x43dcc6;return db[_0x4634('0x3b')]['findOne']({'where':{'id':_0x43dcc6['id']},'raw':!![]});})[_0x4634('0x39')](function(_0x13776f){var _0x5e993c={'grant_type':_0x4634('0x3c'),'refresh_token':_0x13776f[_0x4634('0x3d')],'scope':getAccessTokenScope(_0x13776f),'redirect_uri':_0x13776f[_0x4634('0x27')],'client_id':_0x13776f['data1'],'client_secret':encryptor['decryptString'](_0x13776f[_0x4634('0x3a')])};var _0x466215={'method':_0x4634('0x3e'),'uri':MICROSOFT_AUTH_URL[_0x4634('0x1d')](_0x4634('0x1e'),_0x13776f[_0x4634('0x1f')])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x5e993c,'json':!![]};return rp(_0x466215);})[_0x4634('0x39')](function(_0x11b1ad){_0x43dcc6['data5']=_0x11b1ad[_0x4634('0x3f')];_0x43dcc6[_0x4634('0x3d')]=_0x11b1ad[_0x4634('0x3c')];return db[_0x4634('0x3b')][_0x4634('0x40')]({'data5':_0x43dcc6[_0x4634('0x41')],'data6':_0x43dcc6[_0x4634('0x3d')]},{'where':{'id':_0x43dcc6['id']}});})[_0x4634('0x39')](function(){return _0x43dcc6;})['catch'](function(_0x27cff6){logger[_0x4634('0x42')](_0x4634('0x43'),_0x43dcc6['id'],_0x27cff6);});}function getOauth2MicrosoftAccessToken(_0x46e3d2,_0x5ba823){var _0x118298={'grant_type':_0x4634('0x44'),'code':_0x46e3d2,'scope':getAccessTokenScope(_0x5ba823),'redirect_uri':_0x5ba823[_0x4634('0x27')],'client_id':_0x5ba823['data1'],'client_secret':encryptor[_0x4634('0x45')](_0x5ba823[_0x4634('0x3a')])};var _0x149125={'method':_0x4634('0x3e'),'uri':MICROSOFT_AUTH_URL[_0x4634('0x1d')](_0x4634('0x1e'),_0x5ba823[_0x4634('0x1f')])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x118298,'json':!![]};return rp(_0x149125);}function startRefreshInterval(_0x12a1be){var _0x384dc5=schedule[_0x4634('0x46')];if(_0x384dc5[_0x12a1be['id']])clearInterval(_0x384dc5[_0x12a1be['id']]);_0x384dc5[_0x12a1be['id']]=setInterval(refreshOauth2MicrosoftAccessToken[_0x4634('0x47')](this,{'id':_0x12a1be['id']}),OAUTH_REFRESH_INTERVAL*0x3e8);schedule[_0x4634('0x46')]=_0x384dc5;}function startAllRefreshIntervals(){return db['CloudProvider'][_0x4634('0x48')]({'where':{'data6':{'$ne':null}},'raw':!![]})['then'](function(_0x25854e){var _0x47a92d=_0x25854e['map'](function(_0x15006d){return refreshOauth2MicrosoftAccessToken(_0x15006d)['then'](function(_0x72c988){startRefreshInterval(_0x72c988);});});return Promise[_0x4634('0x49')](_0x47a92d);})[_0x4634('0x4a')](function(_0xb63ef9){var _0x1c6e71=_0xb63ef9?util['inspect'](_0xb63ef9,{'showHidden':![],'depth':null}):'';logger[_0x4634('0x42')](_0x4634('0x4b'),_0x1c6e71);});}module[_0x4634('0x4c')]={'generateMicrosoftAuthorizationUrl':generateMicrosoftAuthorizationUrl,'getOauth2MicrosoftAccessToken':getOauth2MicrosoftAccessToken,'isValidIdToken':isValidIdToken,'startAllRefreshIntervals':startAllRefreshIntervals,'refreshOauth2MicrosoftAccessToken':refreshOauth2MicrosoftAccessToken,'startRefreshInterval':startRefreshInterval};