Built motion from commit da24aabd.|2.6.20
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x9348=['payload','verify','randomBytes','toString','hex','floor','now','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','jsonwebtoken','express-jwt','basic-auth','crypto','bluebird','util','moment','secrets','role','fullname','name','md5secret','chatPause','mailPause','faxPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','userProfileId','privacyEnabled','settingsEnabled','downloadAttachments','selectRecallMeCampaign','chatAutoanswer','chatAutoanswerDelay','emailAutoanswer','emailAutoanswerDelay','smsAutoanswerDelay','openchannelAutoanswerDelay','faxAutoanswer','faxAutoanswerDelay','whatsappAutoanswer','whatsappAutoanswerDelay','messengerSoundNotification','isChatInteractionAuthorized','use','user','findOne','params','closed','then','status','disposition','json','unmanaged','Unmanaged.','catch','isAuthenticated','headers','startsWith','Basic','User','find','authenticate','pass','Wrong\x20credentials.','authorization','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','disabled','Invalid\x20API\x20access\x20key','blocked','minutes','User\x20not\x20found.','User\x20object\x20not\x20found.','update','Forbidden','isWebrtcLicence','getLicense','webrtc','isMiddleware','signToken','setTokenCookie','motion.token','send','retrieveApiKey','isNil','generateApiKey','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','length','unshift','encryptString','promisify','secret','session'];(function(_0x4514aa,_0x24825e){var _0x28d52a=function(_0x40edbd){while(--_0x40edbd){_0x4514aa['push'](_0x4514aa['shift']());}};_0x28d52a(++_0x24825e);}(_0x9348,0x10d));var _0x8934=function(_0x9209b,_0x514299){_0x9209b=_0x9209b-0x0;var _0x24bd5c=_0x9348[_0x9209b];return _0x24bd5c;};'use strict';var db=require(_0x8934('0x0'))['db'];var config=require(_0x8934('0x1'));var hardwareConf=require(_0x8934('0x2'));var licenseUtil=require(_0x8934('0x3'));var encryptor=require(_0x8934('0x4'));var _=require('lodash');var jwt=require(_0x8934('0x5'));var expressJwt=require(_0x8934('0x6'));var compose=require('composable-middleware');var basicAuth=require(_0x8934('0x7'));var crypto=require(_0x8934('0x8'));var BPromise=require(_0x8934('0x9'));var util=require(_0x8934('0xa'));var moment=require(_0x8934('0xb'));var validateJwt=expressJwt({'secret':config[_0x8934('0xc')]['session']});var userAttributes=['id',_0x8934('0xd'),_0x8934('0xe'),_0x8934('0xf'),'internal','email','userpic','permissions',_0x8934('0x10'),'voicePause',_0x8934('0x11'),_0x8934('0x12'),_0x8934('0x13'),_0x8934('0x14'),_0x8934('0x15'),_0x8934('0x16'),_0x8934('0x17'),_0x8934('0x18'),'lastPauseAt',_0x8934('0x19'),_0x8934('0x1a'),_0x8934('0x1b'),_0x8934('0x1c'),_0x8934('0x1d'),_0x8934('0x1e'),'phoneBarDnd',_0x8934('0x1f'),_0x8934('0x20'),_0x8934('0x21'),_0x8934('0x22'),_0x8934('0x23'),_0x8934('0x24'),_0x8934('0x25'),_0x8934('0x26'),'interface',_0x8934('0x27'),_0x8934('0x28'),_0x8934('0x29'),'wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions',_0x8934('0x2a'),'ignorePauseForPreviewCalls',_0x8934('0x2b'),_0x8934('0x2c'),_0x8934('0x2d'),_0x8934('0x2e'),_0x8934('0x2f'),'smsAutoanswer',_0x8934('0x30'),'openchannelAutoanswer',_0x8934('0x31'),_0x8934('0x32'),_0x8934('0x33'),_0x8934('0x34'),_0x8934('0x35'),_0x8934('0x36')];exports[_0x8934('0x37')]=function(){return this['isAuthenticated'](!![])[_0x8934('0x38')](function(_0x2a5e67,_0x32020a,_0x343e09){if(_0x2a5e67[_0x8934('0x39')]){_0x343e09();}else{return db['ChatInteraction'][_0x8934('0x3a')]({'where':{'id':_0x2a5e67[_0x8934('0x3b')]['id']},'attributes':['id',_0x8934('0x3c'),'disposition'],'raw':!![]})[_0x8934('0x3d')](function(_0x561df2){if(_0x561df2&&_0x561df2[_0x8934('0x3c')]){return _0x32020a[_0x8934('0x3e')](_0x561df2[_0x8934('0x3f')]==='unmanaged'?0x195:0x193)[_0x8934('0x40')]({'message':_0x561df2[_0x8934('0x3f')]===_0x8934('0x41')?_0x8934('0x42'):'Forbidden.'});}else{_0x343e09();}})[_0x8934('0x43')](function(_0x249031){_0x343e09(_0x249031);});}});};exports[_0x8934('0x44')]=function isAuthenticated(_0x3d93c7){return compose()[_0x8934('0x38')](function(_0x20d448,_0x3f328a,_0x457634){var _0x9c6a71;if(_0x20d448[_0x8934('0x45')]['authorization']){if(_[_0x8934('0x46')](_0x20d448[_0x8934('0x45')]['authorization'],_0x8934('0x47'))){var _0x3d60f9=basicAuth(_0x20d448);db[_0x8934('0x48')][_0x8934('0x49')]({'where':{'name':_0x3d60f9['name']}})[_0x8934('0x3d')](function(_0x18e881){if(!_0x18e881||!_0x18e881[_0x8934('0x4a')](_0x3d60f9[_0x8934('0x4b')])){return _0x3f328a[_0x8934('0x3e')](0x191)['json']({'message':_0x8934('0x4c')});}_0x20d448['user']={'id':_0x18e881['id']};_0x457634();})['catch'](function(_0xff95be){_0x457634(_0xff95be);});}else if(_[_0x8934('0x46')](_0x20d448[_0x8934('0x45')][_0x8934('0x4d')],'Bearer')){validateJwt(_0x20d448,_0x3f328a,_0x457634);}else{if(_0x3d93c7){_0x457634();}else{return _0x3f328a[_0x8934('0x3e')](0x193)[_0x8934('0x40')]({'message':_0x8934('0x4e')});}}}else if(_0x20d448[_0x8934('0x4f')][_0x8934('0x50')]){try{var _0x4cd282={'audience':hardwareConf[_0x8934('0x51')](),'issuer':hardwareConf[_0x8934('0x51')]()};verifyJwt(_0x20d448['query']['apikey'],_0x4cd282)[_0x8934('0x3d')](function(_0x2a790f){return db['User']['find']({'where':{'id':_0x2a790f[_0x8934('0x52')]}})[_0x8934('0x3d')](function(_0x2f710a){_0x9c6a71=_0x2f710a;return db[_0x8934('0x53')][_0x8934('0x3a')]({'where':{'id':0x1},'attributes':[_0x8934('0x54'),_0x8934('0x55')],'raw':!![]});})[_0x8934('0x3d')](function(_0x27920e){if(!_0x9c6a71||!_[_0x8934('0x56')](_0x9c6a71[_0x8934('0x57')],_0x2a790f['nonce'])){return _0x3f328a[_0x8934('0x3e')](0x191)[_0x8934('0x40')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x9c6a71[_0x8934('0x58')]){return _0x3f328a[_0x8934('0x3e')](0x191)[_0x8934('0x40')]({'message':_0x8934('0x59')});}if(_0x9c6a71[_0x8934('0x5a')]){if(_0x27920e['blockDuration']>0x0){if(moment(_0x9c6a71['blockedAt'])['add'](_0x27920e[_0x8934('0x55')],_0x8934('0x5b'))>moment()){return _0x3f328a[_0x8934('0x3e')](0x191)['json']({'message':_0x8934('0x59')});}}else{return _0x3f328a['status'](0x191)['json']({'message':_0x8934('0x59')});}}_0x20d448[_0x8934('0x39')]={'id':_0x9c6a71['id']};_0x457634();});})['catch'](function(){return _0x3f328a['status'](0x191)[_0x8934('0x40')]({'message':_0x8934('0x59')});});}catch(_0x3d2b14){_0x457634(_0x3d2b14);}}else if(_0x3d93c7){_0x457634();}else{return _0x3f328a['status'](0x193)[_0x8934('0x40')]({'message':'Unknown\x20authorization\x20format'});}})[_0x8934('0x38')](function(_0x58559d,_0x3cd028,_0x476ed9){if(_0x58559d[_0x8934('0x39')]){db['User'][_0x8934('0x49')]({'where':{'id':_0x58559d[_0x8934('0x39')]['id']},'attributes':userAttributes})[_0x8934('0x3d')](function(_0x1e339a){if(!_0x1e339a){return _0x3cd028['status'](0x194)[_0x8934('0x40')]({'message':_0x8934('0x5c')});}_0x58559d[_0x8934('0x39')]=_0x1e339a;_0x476ed9();})[_0x8934('0x43')](function(_0x6e63ff){_0x476ed9(_0x6e63ff);});}else if(_0x3d93c7){_0x476ed9();}else{return _0x3cd028[_0x8934('0x3e')](0x194)[_0x8934('0x40')]({'message':_0x8934('0x5d')});}});};exports['canUpdate']=function canUpdate(){return compose()['use'](function(_0x510152,_0x1daae2,_0x44dfe2){return licenseUtil['getLicense']()[_0x8934('0x3d')](function(_0x4f0a90){if(_0x4f0a90[_0x8934('0x5e')]){_0x44dfe2();}else{return _0x1daae2[_0x8934('0x3e')](0x193)['json']({'message':_0x8934('0x5f')});}})[_0x8934('0x43')](function(_0x3f7562){_0x44dfe2(_0x3f7562);});});};exports[_0x8934('0x60')]=function isWebrtcLicence(){return compose()['use'](function(_0x2adb63,_0xa35ac9,_0x5991fc){return licenseUtil[_0x8934('0x61')]()[_0x8934('0x3d')](function(_0x27a98c){if(_0x27a98c[_0x8934('0x62')]){_0x5991fc();}else{return _0xa35ac9[_0x8934('0x3e')](0x193)[_0x8934('0x40')]({'message':_0x8934('0x5f')});}})[_0x8934('0x43')](function(_0x76684){_0x5991fc(_0x76684);});});};exports[_0x8934('0x63')]=function(_0x1e2175,_0xe212bc,_0x2c322d){_0x1e2175[_0x8934('0x63')]=!![];return _0x2c322d();};exports[_0x8934('0x64')]=function signToken(_0x245176){return signJwt(_0x245176);};exports[_0x8934('0x65')]=function(_0x248d88,_0x53d058){if(!_0x248d88[_0x8934('0x39')]){return _0x53d058[_0x8934('0x3e')](0x194)['json']({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x4a52c0={'payload':{'id':_0x248d88['user']['id'],'role':_0x248d88[_0x8934('0x39')][_0x8934('0xd')]},'options':{'expiresIn':0x15180}};return signJwt(_0x4a52c0)[_0x8934('0x3d')](function(_0x4d1433){_0x53d058['cookie'](_0x8934('0x66'),_0x4d1433);_0x53d058['redirect']('/dashboards/general');})[_0x8934('0x43')](function(_0x2778f9){return _0x53d058[_0x8934('0x3e')](0x1f4)[_0x8934('0x67')](_0x2778f9);});};exports[_0x8934('0x68')]=function(_0x1b66d8){if(_[_0x8934('0x69')](_0x1b66d8['apiKeyNonce'])||_[_0x8934('0x69')](_0x1b66d8['apiKeyIat'])){return null;}else{return createJwt(_0x1b66d8);}};exports[_0x8934('0x6a')]=function(_0x3f2ee0){_0x3f2ee0[_0x8934('0x57')]=generateNonce();_0x3f2ee0[_0x8934('0x6b')]=generateIssuedAt();return createJwt(_0x3f2ee0);};exports[_0x8934('0x6c')]=function(_0x265b0a,_0x1f6c5f){var _0x251cfe=_0x265b0a['query'][_0x8934('0x50')];if(_0x251cfe){var _0x345a95={'nonce':_0x1f6c5f[_0x8934('0x57')],'iat':_0x1f6c5f[_0x8934('0x6b')],'audience':hardwareConf[_0x8934('0x51')](),'issuer':hardwareConf['getUuid']()};return verifyJwt(_0x251cfe,_0x345a95)[_0x8934('0x3d')](function(){return generateApiKey(_0x1f6c5f);});}else{throw{'message':_0x8934('0x6d')};}};exports[_0x8934('0x6e')]=function(_0x4c2a52){var _0x447110=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x447110[_0x8934('0x6f')](_0x4c2a52))throw new db[(_0x8934('0x70'))]['ValidationError']('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports['validatePasswordHistory']=function(_0x3d5b45,_0x8e3e85,_0x3aab00){var _0x4ceb9b=encryptor[_0x8934('0x71')](_0x8e3e85)[_0x8934('0x72')](',');for(var _0x5f447c=0x0;_0x5f447c<_0x3aab00;_0x5f447c++){if(!_0x4ceb9b[_0x5f447c])break;if(_0x3d5b45['toLowerCase']()===_0x4ceb9b[_0x5f447c][_0x8934('0x73')]()){var _0x429769=util[_0x8934('0x74')](_0x8934('0x75'),_0x3aab00);if(_0x3aab00===0x1){_0x429769='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db['Sequelize']['ValidationError'](_0x429769);}}return;};exports['updatePasswordsHistory']=function(_0x43933f,_0x2b8837){var _0x18d08e=_0x2b8837?encryptor[_0x8934('0x71')](_0x2b8837)[_0x8934('0x72')](','):[];if(_0x18d08e[_0x8934('0x76')]===0x5){_0x18d08e['splice'](-0x1,0x1);}_0x18d08e[_0x8934('0x77')](_0x43933f);return encryptor[_0x8934('0x78')](_0x18d08e['join'](','));};function signJwt(_0x41e6b4){var _0x5abde1=BPromise[_0x8934('0x79')](jwt['sign'],{'context':jwt});var _0x29acc9=_0x41e6b4[_0x8934('0x7a')]||config[_0x8934('0xc')][_0x8934('0x7b')];return new BPromise(function(_0x458895,_0x3cae46){_0x5abde1(_0x41e6b4[_0x8934('0x7c')],_0x29acc9,_0x41e6b4['options'])['then'](function(_0x321dad){_0x458895(_0x321dad);})[_0x8934('0x43')](function(_0x181a07){_0x3cae46(_0x181a07);});});}function verifyJwt(_0x458aaf,_0x511ac6,_0x18850a){var _0x35c437=BPromise[_0x8934('0x79')](jwt[_0x8934('0x7d')],{'context':jwt});var _0x2b1888=_0x18850a||config[_0x8934('0xc')][_0x8934('0x7b')];return new BPromise(function(_0x5bcb09,_0x143d9e){_0x35c437(_0x458aaf,_0x2b1888,_0x511ac6)['then'](function(_0x5c2819){_0x5bcb09(_0x5c2819);})[_0x8934('0x43')](function(_0x11b2c6){_0x143d9e(_0x11b2c6);});});}function generateNonce(){return crypto[_0x8934('0x7e')](0x10)[_0x8934('0x7f')](_0x8934('0x80'));}function generateIssuedAt(){return Math[_0x8934('0x81')](Date[_0x8934('0x82')]()/0x3e8)['toString']();}function createJwt(_0x1ccd22){var _0x3f51dc={'payload':{'iat':_0x1ccd22['apiKeyIat'],'nonce':_0x1ccd22[_0x8934('0x57')]},'options':{'algorithm':'HS512','subject':_0x1ccd22['id'][_0x8934('0x7f')](),'issuer':hardwareConf[_0x8934('0x51')](),'audience':hardwareConf[_0x8934('0x51')]()}};return signJwt(_0x3f51dc)['then'](function(_0x2e1b40){return{'iat':_0x1ccd22[_0x8934('0x6b')],'nonce':_0x1ccd22['apiKeyNonce'],'token':_0x2e1b40};});}