15453f82fefdc3974a3b1d3c0eb5316c03c45a5c
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x3e17=['internal','email','userpic','permissions','md5secret','voicePause','chatPause','mailPause','faxPause','smsPause','pauseType','lastLoginAt','lastPauseAt','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','userProfileId','settingsEnabled','isChatInteractionAuthorized','use','ChatInteraction','findOne','params','closed','disposition','then','status','unmanaged','json','Unmanaged.','Forbidden.','catch','headers','authorization','Basic','User','find','name','authenticate','pass','Wrong\x20credentials.','user','startsWith','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','allowedLoginAttempts','blockDuration','nonce','disabled','blocked','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User\x20not\x20found.','canUpdate','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','apiKeyNonce','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','ValidationError','splice','join','promisify','sign','session','options','randomBytes','toString','floor','now','HS512','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','composable-middleware','util','secrets','role','fullname'];(function(_0x4b2331,_0x3dcd93){var _0x3005df=function(_0x47f6a7){while(--_0x47f6a7){_0x4b2331['push'](_0x4b2331['shift']());}};_0x3005df(++_0x3dcd93);}(_0x3e17,0xe7));var _0x73e1=function(_0x57b54c,_0x54ce0d){_0x57b54c=_0x57b54c-0x0;var _0x59cc19=_0x3e17[_0x57b54c];return _0x59cc19;};'use strict';var db=require('../../mysqldb')['db'];var config=require(_0x73e1('0x0'));var hardwareConf=require(_0x73e1('0x1'));var licenseUtil=require(_0x73e1('0x2'));var encryptor=require(_0x73e1('0x3'));var _=require(_0x73e1('0x4'));var jwt=require(_0x73e1('0x5'));var expressJwt=require('express-jwt');var compose=require(_0x73e1('0x6'));var basicAuth=require('basic-auth');var crypto=require('crypto');var BPromise=require('bluebird');var util=require(_0x73e1('0x7'));var moment=require('moment');var validateJwt=expressJwt({'secret':config[_0x73e1('0x8')]['session']});var userAttributes=['id',_0x73e1('0x9'),_0x73e1('0xa'),'name',_0x73e1('0xb'),_0x73e1('0xc'),_0x73e1('0xd'),_0x73e1('0xe'),_0x73e1('0xf'),_0x73e1('0x10'),_0x73e1('0x11'),_0x73e1('0x12'),_0x73e1('0x13'),_0x73e1('0x14'),'openchannelPause',_0x73e1('0x15'),'showWebBar',_0x73e1('0x16'),_0x73e1('0x17'),'crudPermissions',_0x73e1('0x18'),_0x73e1('0x19'),_0x73e1('0x1a'),'phoneBarAutoAnswer',_0x73e1('0x1b'),_0x73e1('0x1c'),_0x73e1('0x1d'),_0x73e1('0x1e'),'phoneBarEnableSettings',_0x73e1('0x1f'),_0x73e1('0x20'),_0x73e1('0x21'),_0x73e1('0x22'),_0x73e1('0x23'),'interface',_0x73e1('0x24'),_0x73e1('0x25')];exports[_0x73e1('0x26')]=function(){return this['isAuthenticated'](!![])[_0x73e1('0x27')](function(_0x470342,_0x29c259,_0x10762d){if(_0x470342['user']){_0x10762d();}else{return db[_0x73e1('0x28')][_0x73e1('0x29')]({'where':{'id':_0x470342[_0x73e1('0x2a')]['id']},'attributes':['id',_0x73e1('0x2b'),_0x73e1('0x2c')],'raw':!![]})[_0x73e1('0x2d')](function(_0x4f2803){if(_0x4f2803&&_0x4f2803['closed']){return _0x29c259[_0x73e1('0x2e')](_0x4f2803['disposition']===_0x73e1('0x2f')?0x195:0x193)[_0x73e1('0x30')]({'message':_0x4f2803[_0x73e1('0x2c')]===_0x73e1('0x2f')?_0x73e1('0x31'):_0x73e1('0x32')});}else{_0x10762d();}})[_0x73e1('0x33')](function(_0x2e4e97){_0x10762d(_0x2e4e97);});}});};exports['isAuthenticated']=function isAuthenticated(_0x60c857){return compose()[_0x73e1('0x27')](function(_0x57cb24,_0x11c69c,_0x33f57a){var _0xb0e742;if(_0x57cb24[_0x73e1('0x34')][_0x73e1('0x35')]){if(_['startsWith'](_0x57cb24[_0x73e1('0x34')][_0x73e1('0x35')],_0x73e1('0x36'))){var _0x3ca350=basicAuth(_0x57cb24);db[_0x73e1('0x37')][_0x73e1('0x38')]({'where':{'name':_0x3ca350[_0x73e1('0x39')]}})[_0x73e1('0x2d')](function(_0x4ab24c){if(!_0x4ab24c||!_0x4ab24c[_0x73e1('0x3a')](_0x3ca350[_0x73e1('0x3b')])){return _0x11c69c[_0x73e1('0x2e')](0x191)[_0x73e1('0x30')]({'message':_0x73e1('0x3c')});}_0x57cb24[_0x73e1('0x3d')]={'id':_0x4ab24c['id']};_0x33f57a();})[_0x73e1('0x33')](function(_0x37af45){_0x33f57a(_0x37af45);});}else if(_[_0x73e1('0x3e')](_0x57cb24[_0x73e1('0x34')][_0x73e1('0x35')],_0x73e1('0x3f'))){validateJwt(_0x57cb24,_0x11c69c,_0x33f57a);}else{if(_0x60c857){_0x33f57a();}else{return _0x11c69c[_0x73e1('0x2e')](0x193)[_0x73e1('0x30')]({'message':_0x73e1('0x40')});}}}else if(_0x57cb24[_0x73e1('0x41')][_0x73e1('0x42')]){try{var _0x53618c={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x73e1('0x43')]()};verifyJwt(_0x57cb24[_0x73e1('0x41')][_0x73e1('0x42')],_0x53618c)[_0x73e1('0x2d')](function(_0x57887b){return db['User']['find']({'where':{'id':_0x57887b[_0x73e1('0x44')]}})[_0x73e1('0x2d')](function(_0x40b567){_0xb0e742=_0x40b567;return db['Setting'][_0x73e1('0x29')]({'where':{'id':0x1},'attributes':[_0x73e1('0x45'),_0x73e1('0x46')],'raw':!![]});})['then'](function(_0x4fad9a){if(!_0xb0e742||!_['isEqual'](_0xb0e742['apiKeyNonce'],_0x57887b[_0x73e1('0x47')])){return _0x11c69c[_0x73e1('0x2e')](0x191)[_0x73e1('0x30')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0xb0e742[_0x73e1('0x48')]){return _0x11c69c[_0x73e1('0x2e')](0x191)[_0x73e1('0x30')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0xb0e742[_0x73e1('0x49')]){if(_0x4fad9a[_0x73e1('0x46')]>0x0){if(moment(_0xb0e742[_0x73e1('0x4a')])[_0x73e1('0x4b')](_0x4fad9a[_0x73e1('0x46')],_0x73e1('0x4c'))>moment()){return _0x11c69c[_0x73e1('0x2e')](0x191)[_0x73e1('0x30')]({'message':_0x73e1('0x4d')});}}else{return _0x11c69c['status'](0x191)[_0x73e1('0x30')]({'message':_0x73e1('0x4d')});}}_0x57cb24['user']={'id':_0xb0e742['id']};_0x33f57a();});})['catch'](function(){return _0x11c69c[_0x73e1('0x2e')](0x191)[_0x73e1('0x30')]({'message':_0x73e1('0x4d')});});}catch(_0x16fcb7){_0x33f57a(_0x16fcb7);}}else if(_0x60c857){_0x33f57a();}else{return _0x11c69c[_0x73e1('0x2e')](0x193)[_0x73e1('0x30')]({'message':_0x73e1('0x40')});}})[_0x73e1('0x27')](function(_0x4a1ec3,_0x3391ad,_0x561152){if(_0x4a1ec3['user']){db[_0x73e1('0x37')]['find']({'where':{'id':_0x4a1ec3[_0x73e1('0x3d')]['id']},'attributes':userAttributes})[_0x73e1('0x2d')](function(_0x595768){if(!_0x595768){return _0x3391ad[_0x73e1('0x2e')](0x194)[_0x73e1('0x30')]({'message':_0x73e1('0x4e')});}_0x4a1ec3[_0x73e1('0x3d')]=_0x595768;_0x561152();})[_0x73e1('0x33')](function(_0x1b712d){_0x561152(_0x1b712d);});}else if(_0x60c857){_0x561152();}else{return _0x3391ad[_0x73e1('0x2e')](0x194)['json']({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x73e1('0x4f')]=function canUpdate(){return compose()[_0x73e1('0x27')](function(_0x4fbb0e,_0x15a924,_0xebc320){return licenseUtil[_0x73e1('0x50')]()[_0x73e1('0x2d')](function(_0xa3845f){if(_0xa3845f[_0x73e1('0x51')]){_0xebc320();}else{return _0x15a924[_0x73e1('0x2e')](0x193)[_0x73e1('0x30')]({'message':_0x73e1('0x52')});}})[_0x73e1('0x33')](function(_0x24e7d2){_0xebc320(_0x24e7d2);});});};exports[_0x73e1('0x53')]=function(_0x916aa,_0x58f3eb,_0x12de39){_0x916aa['isMiddleware']=!![];return _0x12de39();};exports[_0x73e1('0x54')]=function signToken(_0x1b29d7){return signJwt(_0x1b29d7);};exports[_0x73e1('0x55')]=function(_0xfda807,_0x4cc6ca){if(!_0xfda807['user']){return _0x4cc6ca[_0x73e1('0x2e')](0x194)[_0x73e1('0x30')]({'message':_0x73e1('0x56')});}var _0x35b1ef={'payload':{'id':_0xfda807[_0x73e1('0x3d')]['id'],'role':_0xfda807[_0x73e1('0x3d')][_0x73e1('0x9')]},'options':{'expiresIn':0x15180}};return signJwt(_0x35b1ef)['then'](function(_0x233393){_0x4cc6ca[_0x73e1('0x57')](_0x73e1('0x58'),_0x233393);_0x4cc6ca[_0x73e1('0x59')](_0x73e1('0x5a'));})[_0x73e1('0x33')](function(_0x1a2a1b){return _0x4cc6ca[_0x73e1('0x2e')](0x1f4)[_0x73e1('0x5b')](_0x1a2a1b);});};exports[_0x73e1('0x5c')]=function(_0x3c7625){if(_[_0x73e1('0x5d')](_0x3c7625['apiKeyNonce'])||_['isNil'](_0x3c7625[_0x73e1('0x5e')])){return null;}else{return createJwt(_0x3c7625);}};exports[_0x73e1('0x5f')]=function(_0x17bbab){_0x17bbab[_0x73e1('0x60')]=generateNonce();_0x17bbab[_0x73e1('0x5e')]=generateIssuedAt();return createJwt(_0x17bbab);};exports[_0x73e1('0x61')]=function(_0x1136ef,_0x4a8b3e){var _0x2f3e56=_0x1136ef['query']['apikey'];if(_0x2f3e56){var _0xe3cf1b={'nonce':_0x4a8b3e[_0x73e1('0x60')],'iat':_0x4a8b3e[_0x73e1('0x5e')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x73e1('0x43')]()};return verifyJwt(_0x2f3e56,_0xe3cf1b)['then'](function(){return generateApiKey(_0x4a8b3e);});}else{throw{'message':_0x73e1('0x62')};}};exports[_0x73e1('0x63')]=function(_0x3879da){var _0x3e7feb=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x3e7feb[_0x73e1('0x64')](_0x3879da))throw new db[(_0x73e1('0x65'))]['ValidationError'](_0x73e1('0x66'));return;};exports[_0x73e1('0x67')]=function(_0x12a6f9,_0x1a2f2c,_0x4fb5bb){var _0x41936f=encryptor[_0x73e1('0x68')](_0x1a2f2c)[_0x73e1('0x69')](',');for(var _0x588612=0x0;_0x588612<_0x4fb5bb;_0x588612++){if(!_0x41936f[_0x588612])break;if(_0x12a6f9['toLowerCase']()===_0x41936f[_0x588612]['toLowerCase']()){var _0x5dea61=util[_0x73e1('0x6a')](_0x73e1('0x6b'),_0x4fb5bb);if(_0x4fb5bb===0x1){_0x5dea61=_0x73e1('0x6c');}throw new db[(_0x73e1('0x65'))][(_0x73e1('0x6d'))](_0x5dea61);}}return;};exports['updatePasswordsHistory']=function(_0x334b7a,_0x3a3d74){var _0x3acc9c=_0x3a3d74?encryptor[_0x73e1('0x68')](_0x3a3d74)[_0x73e1('0x69')](','):[];if(_0x3acc9c['length']===0x5){_0x3acc9c[_0x73e1('0x6e')](-0x1,0x1);}_0x3acc9c['unshift'](_0x334b7a);return encryptor['encryptString'](_0x3acc9c[_0x73e1('0x6f')](','));};function signJwt(_0x2c67cd){var _0x4a755a=BPromise[_0x73e1('0x70')](jwt[_0x73e1('0x71')],{'context':jwt});var _0x4d9dac=_0x2c67cd['secret']||config[_0x73e1('0x8')][_0x73e1('0x72')];return new BPromise(function(_0x34ff6d,_0x7f49d6){_0x4a755a(_0x2c67cd['payload'],_0x4d9dac,_0x2c67cd[_0x73e1('0x73')])[_0x73e1('0x2d')](function(_0x17c97b){_0x34ff6d(_0x17c97b);})[_0x73e1('0x33')](function(_0x255020){_0x7f49d6(_0x255020);});});}function verifyJwt(_0x2d9ce2,_0x47cadd,_0x52cedb){var _0x3493f6=BPromise[_0x73e1('0x70')](jwt['verify'],{'context':jwt});var _0x45862f=_0x52cedb||config[_0x73e1('0x8')][_0x73e1('0x72')];return new BPromise(function(_0x57cf6f,_0x3ebe30){_0x3493f6(_0x2d9ce2,_0x45862f,_0x47cadd)[_0x73e1('0x2d')](function(_0x2399c3){_0x57cf6f(_0x2399c3);})[_0x73e1('0x33')](function(_0x5762a1){_0x3ebe30(_0x5762a1);});});}function generateNonce(){return crypto[_0x73e1('0x74')](0x10)[_0x73e1('0x75')]('hex');}function generateIssuedAt(){return Math[_0x73e1('0x76')](Date[_0x73e1('0x77')]()/0x3e8)[_0x73e1('0x75')]();}function createJwt(_0x34fdf4){var _0x11e8e1={'payload':{'iat':_0x34fdf4['apiKeyIat'],'nonce':_0x34fdf4['apiKeyNonce']},'options':{'algorithm':_0x73e1('0x78'),'subject':_0x34fdf4['id'][_0x73e1('0x75')](),'issuer':hardwareConf[_0x73e1('0x43')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x11e8e1)['then'](function(_0x35f27d){return{'iat':_0x34fdf4[_0x73e1('0x5e')],'nonce':_0x34fdf4[_0x73e1('0x60')],'token':_0x35f27d};});}