145278d506e5bf769dcc083ab0f0bafc7b3b48d6
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xd065=['status','disposition','json','Unmanaged.','catch','use','headers','authorization','startsWith','Basic','User','name','then','authenticate','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blockedAt','Invalid\x20API\x20access\x20key','User\x20not\x20found.','canUpdate','getLicense','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyNonce','generateApiKey','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','ValidationError','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','Sequelize','updatePasswordsHistory','length','splice','unshift','encryptString','join','promisify','sign','payload','randomBytes','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','crypto','moment','secrets','session','role','email','userpic','permissions','md5secret','voicePause','mailPause','faxPause','smsPause','openchannelPause','showWebBar','lastPauseAt','crudPermissions','passwordResetAt','alias','phoneBarAutoAnswerDelay','phoneBarEnableDtmfTone','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','userProfileId','privacyEnabled','isChatInteractionAuthorized','isAuthenticated','user','findOne','params','closed'];(function(_0x340e2d,_0x563dbe){var _0x369125=function(_0x508b26){while(--_0x508b26){_0x340e2d['push'](_0x340e2d['shift']());}};_0x369125(++_0x563dbe);}(_0xd065,0xba));var _0x5d06=function(_0x5cc7a3,_0xddb353){_0x5cc7a3=_0x5cc7a3-0x0;var _0x4312a7=_0xd065[_0x5cc7a3];return _0x4312a7;};'use strict';var db=require(_0x5d06('0x0'))['db'];var config=require(_0x5d06('0x1'));var hardwareConf=require(_0x5d06('0x2'));var licenseUtil=require(_0x5d06('0x3'));var encryptor=require(_0x5d06('0x4'));var _=require(_0x5d06('0x5'));var jwt=require(_0x5d06('0x6'));var expressJwt=require(_0x5d06('0x7'));var compose=require('composable-middleware');var basicAuth=require('basic-auth');var crypto=require(_0x5d06('0x8'));var BPromise=require('bluebird');var util=require('util');var moment=require(_0x5d06('0x9'));var validateJwt=expressJwt({'secret':config[_0x5d06('0xa')][_0x5d06('0xb')]});var userAttributes=['id',_0x5d06('0xc'),'fullname','name','internal',_0x5d06('0xd'),_0x5d06('0xe'),_0x5d06('0xf'),_0x5d06('0x10'),_0x5d06('0x11'),'chatPause',_0x5d06('0x12'),_0x5d06('0x13'),_0x5d06('0x14'),_0x5d06('0x15'),'pauseType',_0x5d06('0x16'),'lastLoginAt',_0x5d06('0x17'),_0x5d06('0x18'),'allowmessenger',_0x5d06('0x19'),_0x5d06('0x1a'),'phoneBarAutoAnswer',_0x5d06('0x1b'),'phoneBarDnd','phoneBarEnableRecording',_0x5d06('0x1c'),'phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired',_0x5d06('0x1d'),_0x5d06('0x1e'),_0x5d06('0x1f'),'interface',_0x5d06('0x20'),_0x5d06('0x21'),'settingsEnabled'];exports[_0x5d06('0x22')]=function(){return this[_0x5d06('0x23')](!![])['use'](function(_0x9d8c7d,_0x1d88eb,_0x18041a){if(_0x9d8c7d[_0x5d06('0x24')]){_0x18041a();}else{return db['ChatInteraction'][_0x5d06('0x25')]({'where':{'id':_0x9d8c7d[_0x5d06('0x26')]['id']},'attributes':['id',_0x5d06('0x27'),'disposition'],'raw':!![]})['then'](function(_0x54d955){if(_0x54d955&&_0x54d955[_0x5d06('0x27')]){return _0x1d88eb[_0x5d06('0x28')](_0x54d955[_0x5d06('0x29')]==='unmanaged'?0x195:0x193)[_0x5d06('0x2a')]({'message':_0x54d955[_0x5d06('0x29')]==='unmanaged'?_0x5d06('0x2b'):'Forbidden.'});}else{_0x18041a();}})[_0x5d06('0x2c')](function(_0x529c9b){_0x18041a(_0x529c9b);});}});};exports[_0x5d06('0x23')]=function isAuthenticated(_0x83826b){return compose()[_0x5d06('0x2d')](function(_0x4d29a6,_0x2d4c0c,_0x485611){var _0x1762c0;if(_0x4d29a6[_0x5d06('0x2e')][_0x5d06('0x2f')]){if(_[_0x5d06('0x30')](_0x4d29a6[_0x5d06('0x2e')][_0x5d06('0x2f')],_0x5d06('0x31'))){var _0x3a09bf=basicAuth(_0x4d29a6);db[_0x5d06('0x32')]['find']({'where':{'name':_0x3a09bf[_0x5d06('0x33')]}})[_0x5d06('0x34')](function(_0x6fa4d8){if(!_0x6fa4d8||!_0x6fa4d8[_0x5d06('0x35')](_0x3a09bf['pass'])){return _0x2d4c0c['status'](0x191)[_0x5d06('0x2a')]({'message':_0x5d06('0x36')});}_0x4d29a6['user']={'id':_0x6fa4d8['id']};_0x485611();})[_0x5d06('0x2c')](function(_0x25bb78){_0x485611(_0x25bb78);});}else if(_[_0x5d06('0x30')](_0x4d29a6['headers'][_0x5d06('0x2f')],_0x5d06('0x37'))){validateJwt(_0x4d29a6,_0x2d4c0c,_0x485611);}else{if(_0x83826b){_0x485611();}else{return _0x2d4c0c['status'](0x193)[_0x5d06('0x2a')]({'message':_0x5d06('0x38')});}}}else if(_0x4d29a6[_0x5d06('0x39')]['apikey']){try{var _0x382e2e={'audience':hardwareConf[_0x5d06('0x3a')](),'issuer':hardwareConf[_0x5d06('0x3a')]()};verifyJwt(_0x4d29a6[_0x5d06('0x39')][_0x5d06('0x3b')],_0x382e2e)[_0x5d06('0x34')](function(_0x192f6f){return db[_0x5d06('0x32')]['find']({'where':{'id':_0x192f6f[_0x5d06('0x3c')]}})[_0x5d06('0x34')](function(_0x4d32c4){_0x1762c0=_0x4d32c4;return db[_0x5d06('0x3d')][_0x5d06('0x25')]({'where':{'id':0x1},'attributes':[_0x5d06('0x3e'),_0x5d06('0x3f')],'raw':!![]});})[_0x5d06('0x34')](function(_0x47ba15){if(!_0x1762c0||!_[_0x5d06('0x40')](_0x1762c0['apiKeyNonce'],_0x192f6f['nonce'])){return _0x2d4c0c[_0x5d06('0x28')](0x191)[_0x5d06('0x2a')]({'message':_0x5d06('0x41')});}if(_0x1762c0[_0x5d06('0x42')]){return _0x2d4c0c[_0x5d06('0x28')](0x191)[_0x5d06('0x2a')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x1762c0['blocked']){if(_0x47ba15[_0x5d06('0x3f')]>0x0){if(moment(_0x1762c0[_0x5d06('0x43')])['add'](_0x47ba15[_0x5d06('0x3f')],'minutes')>moment()){return _0x2d4c0c[_0x5d06('0x28')](0x191)['json']({'message':_0x5d06('0x44')});}}else{return _0x2d4c0c[_0x5d06('0x28')](0x191)[_0x5d06('0x2a')]({'message':_0x5d06('0x44')});}}_0x4d29a6[_0x5d06('0x24')]={'id':_0x1762c0['id']};_0x485611();});})[_0x5d06('0x2c')](function(){return _0x2d4c0c[_0x5d06('0x28')](0x191)[_0x5d06('0x2a')]({'message':_0x5d06('0x44')});});}catch(_0x9ba309){_0x485611(_0x9ba309);}}else if(_0x83826b){_0x485611();}else{return _0x2d4c0c[_0x5d06('0x28')](0x193)['json']({'message':_0x5d06('0x38')});}})['use'](function(_0x3d3ab1,_0x10bfba,_0x433c6){if(_0x3d3ab1[_0x5d06('0x24')]){db['User']['find']({'where':{'id':_0x3d3ab1[_0x5d06('0x24')]['id']},'attributes':userAttributes})[_0x5d06('0x34')](function(_0x15809e){if(!_0x15809e){return _0x10bfba[_0x5d06('0x28')](0x194)['json']({'message':_0x5d06('0x45')});}_0x3d3ab1[_0x5d06('0x24')]=_0x15809e;_0x433c6();})[_0x5d06('0x2c')](function(_0x5836c5){_0x433c6(_0x5836c5);});}else if(_0x83826b){_0x433c6();}else{return _0x10bfba[_0x5d06('0x28')](0x194)[_0x5d06('0x2a')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x5d06('0x46')]=function canUpdate(){return compose()[_0x5d06('0x2d')](function(_0x20db5a,_0x252256,_0x42eb3f){return licenseUtil[_0x5d06('0x47')]()[_0x5d06('0x34')](function(_0x39da13){if(_0x39da13['update']){_0x42eb3f();}else{return _0x252256[_0x5d06('0x28')](0x193)[_0x5d06('0x2a')]({'message':_0x5d06('0x48')});}})['catch'](function(_0xd4b24){_0x42eb3f(_0xd4b24);});});};exports[_0x5d06('0x49')]=function(_0x2d3dbe,_0xcddf67,_0x1946c1){_0x2d3dbe[_0x5d06('0x49')]=!![];return _0x1946c1();};exports[_0x5d06('0x4a')]=function signToken(_0x424f5c){return signJwt(_0x424f5c);};exports[_0x5d06('0x4b')]=function(_0x42417a,_0x21a2de){if(!_0x42417a['user']){return _0x21a2de[_0x5d06('0x28')](0x194)['json']({'message':_0x5d06('0x4c')});}var _0x2ce366={'payload':{'id':_0x42417a[_0x5d06('0x24')]['id'],'role':_0x42417a[_0x5d06('0x24')][_0x5d06('0xc')]},'options':{'expiresIn':0x15180}};return signJwt(_0x2ce366)[_0x5d06('0x34')](function(_0x5691ef){_0x21a2de[_0x5d06('0x4d')](_0x5d06('0x4e'),_0x5691ef);_0x21a2de[_0x5d06('0x4f')](_0x5d06('0x50'));})[_0x5d06('0x2c')](function(_0x19a40b){return _0x21a2de['status'](0x1f4)[_0x5d06('0x51')](_0x19a40b);});};exports[_0x5d06('0x52')]=function(_0x3a3bd3){if(_[_0x5d06('0x53')](_0x3a3bd3[_0x5d06('0x54')])||_['isNil'](_0x3a3bd3['apiKeyIat'])){return null;}else{return createJwt(_0x3a3bd3);}};exports[_0x5d06('0x55')]=function(_0x114fbc){_0x114fbc[_0x5d06('0x54')]=generateNonce();_0x114fbc[_0x5d06('0x56')]=generateIssuedAt();return createJwt(_0x114fbc);};exports[_0x5d06('0x57')]=function(_0x3522fd,_0x4af4da){var _0x1288c4=_0x3522fd[_0x5d06('0x39')][_0x5d06('0x3b')];if(_0x1288c4){var _0x440c43={'nonce':_0x4af4da[_0x5d06('0x54')],'iat':_0x4af4da['apiKeyIat'],'audience':hardwareConf[_0x5d06('0x3a')](),'issuer':hardwareConf['getUuid']()};return verifyJwt(_0x1288c4,_0x440c43)[_0x5d06('0x34')](function(){return generateApiKey(_0x4af4da);});}else{throw{'message':_0x5d06('0x58')};}};exports['validatePasswordPattern']=function(_0x1f2d6c){var _0x432e4d=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x432e4d['test'](_0x1f2d6c))throw new db['Sequelize'][(_0x5d06('0x59'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x5d06('0x5a')]=function(_0x7e2c26,_0x36a3eb,_0x768606){var _0x9d7114=encryptor[_0x5d06('0x5b')](_0x36a3eb)[_0x5d06('0x5c')](',');for(var _0x3124f5=0x0;_0x3124f5<_0x768606;_0x3124f5++){if(!_0x9d7114[_0x3124f5])break;if(_0x7e2c26[_0x5d06('0x5d')]()===_0x9d7114[_0x3124f5][_0x5d06('0x5d')]()){var _0x37ad92=util[_0x5d06('0x5e')](_0x5d06('0x5f'),_0x768606);if(_0x768606===0x1){_0x37ad92=_0x5d06('0x60');}throw new db[(_0x5d06('0x61'))][(_0x5d06('0x59'))](_0x37ad92);}}return;};exports[_0x5d06('0x62')]=function(_0x400246,_0x427f6c){var _0x480bbf=_0x427f6c?encryptor['decryptString'](_0x427f6c)[_0x5d06('0x5c')](','):[];if(_0x480bbf[_0x5d06('0x63')]===0x5){_0x480bbf[_0x5d06('0x64')](-0x1,0x1);}_0x480bbf[_0x5d06('0x65')](_0x400246);return encryptor[_0x5d06('0x66')](_0x480bbf[_0x5d06('0x67')](','));};function signJwt(_0x2fffc8){var _0x1e1e05=BPromise[_0x5d06('0x68')](jwt[_0x5d06('0x69')],{'context':jwt});var _0x9cbe16=_0x2fffc8['secret']||config[_0x5d06('0xa')][_0x5d06('0xb')];return new BPromise(function(_0x5b560a,_0x6fb795){_0x1e1e05(_0x2fffc8[_0x5d06('0x6a')],_0x9cbe16,_0x2fffc8['options'])[_0x5d06('0x34')](function(_0x1e89c4){_0x5b560a(_0x1e89c4);})[_0x5d06('0x2c')](function(_0x54366d){_0x6fb795(_0x54366d);});});}function verifyJwt(_0x387c87,_0x5265fe,_0x123a52){var _0x48269f=BPromise[_0x5d06('0x68')](jwt['verify'],{'context':jwt});var _0x19449b=_0x123a52||config[_0x5d06('0xa')][_0x5d06('0xb')];return new BPromise(function(_0x25d9db,_0x15fc56){_0x48269f(_0x387c87,_0x19449b,_0x5265fe)['then'](function(_0x27200d){_0x25d9db(_0x27200d);})[_0x5d06('0x2c')](function(_0x27d3a9){_0x15fc56(_0x27d3a9);});});}function generateNonce(){return crypto[_0x5d06('0x6b')](0x10)[_0x5d06('0x6c')](_0x5d06('0x6d'));}function generateIssuedAt(){return Math[_0x5d06('0x6e')](Date[_0x5d06('0x6f')]()/0x3e8)[_0x5d06('0x6c')]();}function createJwt(_0x2dc585){var _0x266c6c={'payload':{'iat':_0x2dc585[_0x5d06('0x56')],'nonce':_0x2dc585[_0x5d06('0x54')]},'options':{'algorithm':_0x5d06('0x70'),'subject':_0x2dc585['id']['toString'](),'issuer':hardwareConf[_0x5d06('0x3a')](),'audience':hardwareConf[_0x5d06('0x3a')]()}};return signJwt(_0x266c6c)[_0x5d06('0x34')](function(_0x534058){return{'iat':_0x2dc585[_0x5d06('0x56')],'nonce':_0x2dc585['apiKeyNonce'],'token':_0x534058};});}