Built motion from commit 4ca75f1b.|2.6.28
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x9df4=['unmanaged','json','Unmanaged.','Forbidden.','headers','authorization','Basic','find','pass','Wrong\x20credentials.','user','startsWith','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','User','sub','Setting','allowedLoginAttempts','blockDuration','apiKeyNonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','catch','canUpdate','getLicense','update','Forbidden','isWebrtcLicence','webrtc','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','isNil','regenerateApiKey','apiKeyIat','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','format','ValidationError','updatePasswordsHistory','splice','encryptString','join','promisify','sign','secret','session','options','verify','randomBytes','toString','../../mysqldb','../../config/environment','../../config/license/hardware','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','util','moment','secrets','role','fullname','name','internal','email','userpic','md5secret','voicePause','chatPause','smsPause','pauseType','showWebBar','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControlPort','hotdesk','interface','privacyEnabled','settingsEnabled','wssPort','downloadOmnichannelInteractions','downloadAttachments','ignorePauseForPreviewCalls','selectRecallMeCampaign','chatAutoanswer','chatAutoanswerDelay','emailAutoanswer','emailAutoanswerDelay','smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer','faxAutoanswer','faxAutoanswerDelay','whatsappAutoanswer','whatsappAutoanswerDelay','messengerSoundNotification','isAuthenticated','use','ChatInteraction','findOne','closed','disposition','then','query','status'];(function(_0x2b7c95,_0x2a4374){var _0x9811ae=function(_0x5db73a){while(--_0x5db73a){_0x2b7c95['push'](_0x2b7c95['shift']());}};_0x9811ae(++_0x2a4374);}(_0x9df4,0x15b));var _0x49df=function(_0x475dce,_0x1754ff){_0x475dce=_0x475dce-0x0;var _0x40687a=_0x9df4[_0x475dce];return _0x40687a;};'use strict';var db=require(_0x49df('0x0'))['db'];var config=require(_0x49df('0x1'));var hardwareConf=require(_0x49df('0x2'));var licenseUtil=require('../../config/license/util');var encryptor=require(_0x49df('0x3'));var _=require(_0x49df('0x4'));var jwt=require(_0x49df('0x5'));var expressJwt=require(_0x49df('0x6'));var compose=require(_0x49df('0x7'));var basicAuth=require(_0x49df('0x8'));var crypto=require(_0x49df('0x9'));var BPromise=require('bluebird');var util=require(_0x49df('0xa'));var moment=require(_0x49df('0xb'));var validateJwt=expressJwt({'secret':config[_0x49df('0xc')]['session']});var userAttributes=['id',_0x49df('0xd'),_0x49df('0xe'),_0x49df('0xf'),_0x49df('0x10'),_0x49df('0x11'),_0x49df('0x12'),'permissions',_0x49df('0x13'),_0x49df('0x14'),_0x49df('0x15'),'mailPause','faxPause',_0x49df('0x16'),'openchannelPause',_0x49df('0x17'),_0x49df('0x18'),'lastLoginAt',_0x49df('0x19'),_0x49df('0x1a'),_0x49df('0x1b'),_0x49df('0x1c'),'alias',_0x49df('0x1d'),_0x49df('0x1e'),'phoneBarDnd',_0x49df('0x1f'),_0x49df('0x20'),_0x49df('0x21'),_0x49df('0x22'),_0x49df('0x23'),'phoneBarRemoteControl',_0x49df('0x24'),_0x49df('0x25'),_0x49df('0x26'),'userProfileId',_0x49df('0x27'),_0x49df('0x28'),_0x49df('0x29'),'downloadVoiceRecordings',_0x49df('0x2a'),_0x49df('0x2b'),_0x49df('0x2c'),_0x49df('0x2d'),_0x49df('0x2e'),_0x49df('0x2f'),_0x49df('0x30'),_0x49df('0x31'),_0x49df('0x32'),_0x49df('0x33'),_0x49df('0x34'),'openchannelAutoanswerDelay',_0x49df('0x35'),_0x49df('0x36'),_0x49df('0x37'),_0x49df('0x38'),_0x49df('0x39')];exports['isChatInteractionAuthorized']=function(){return this[_0x49df('0x3a')](!![])[_0x49df('0x3b')](function(_0x17bdfb,_0x22001c,_0x3e1fce){if(_0x17bdfb['user']){_0x3e1fce();}else{return db[_0x49df('0x3c')][_0x49df('0x3d')]({'where':{'id':_0x17bdfb['params']['id']},'attributes':['id',_0x49df('0x3e'),_0x49df('0x3f')],'raw':!![]})[_0x49df('0x40')](function(_0x3e30e9){if(_0x3e30e9&&_0x3e30e9[_0x49df('0x3e')]&&!_0x17bdfb[_0x49df('0x41')]['forceDownload']){return _0x22001c[_0x49df('0x42')](_0x3e30e9['disposition']===_0x49df('0x43')?0x195:0x193)[_0x49df('0x44')]({'message':_0x3e30e9[_0x49df('0x3f')]===_0x49df('0x43')?_0x49df('0x45'):_0x49df('0x46')});}else{_0x3e1fce();}})['catch'](function(_0x4299e1){_0x3e1fce(_0x4299e1);});}});};exports[_0x49df('0x3a')]=function isAuthenticated(_0x4ab499){return compose()['use'](function(_0xbe4f73,_0x59cd01,_0x5b37f2){var _0x29a799;if(_0xbe4f73[_0x49df('0x47')][_0x49df('0x48')]){if(_['startsWith'](_0xbe4f73[_0x49df('0x47')][_0x49df('0x48')],_0x49df('0x49'))){var _0x2cbc56=basicAuth(_0xbe4f73);db['User'][_0x49df('0x4a')]({'where':{'name':_0x2cbc56[_0x49df('0xf')]}})[_0x49df('0x40')](function(_0x1e22c2){if(!_0x1e22c2||!_0x1e22c2['authenticate'](_0x2cbc56[_0x49df('0x4b')])){return _0x59cd01[_0x49df('0x42')](0x191)[_0x49df('0x44')]({'message':_0x49df('0x4c')});}_0xbe4f73[_0x49df('0x4d')]={'id':_0x1e22c2['id']};_0x5b37f2();})['catch'](function(_0x83ec8c){_0x5b37f2(_0x83ec8c);});}else if(_[_0x49df('0x4e')](_0xbe4f73[_0x49df('0x47')]['authorization'],_0x49df('0x4f'))){validateJwt(_0xbe4f73,_0x59cd01,_0x5b37f2);}else{if(_0x4ab499){_0x5b37f2();}else{return _0x59cd01[_0x49df('0x42')](0x193)[_0x49df('0x44')]({'message':_0x49df('0x50')});}}}else if(_0xbe4f73[_0x49df('0x41')][_0x49df('0x51')]){try{var _0x3e5346={'audience':hardwareConf[_0x49df('0x52')](),'issuer':hardwareConf[_0x49df('0x52')]()};verifyJwt(_0xbe4f73['query'][_0x49df('0x51')],_0x3e5346)[_0x49df('0x40')](function(_0x257514){return db[_0x49df('0x53')][_0x49df('0x4a')]({'where':{'id':_0x257514[_0x49df('0x54')]}})['then'](function(_0x2528ff){_0x29a799=_0x2528ff;return db[_0x49df('0x55')][_0x49df('0x3d')]({'where':{'id':0x1},'attributes':[_0x49df('0x56'),_0x49df('0x57')],'raw':!![]});})[_0x49df('0x40')](function(_0x481aed){if(!_0x29a799||!_['isEqual'](_0x29a799[_0x49df('0x58')],_0x257514['nonce'])){return _0x59cd01[_0x49df('0x42')](0x191)['json']({'message':_0x49df('0x59')});}if(_0x29a799[_0x49df('0x5a')]){return _0x59cd01[_0x49df('0x42')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}if(_0x29a799[_0x49df('0x5b')]){if(_0x481aed[_0x49df('0x57')]>0x0){if(moment(_0x29a799[_0x49df('0x5c')])[_0x49df('0x5d')](_0x481aed[_0x49df('0x57')],_0x49df('0x5e'))>moment()){return _0x59cd01[_0x49df('0x42')](0x191)['json']({'message':_0x49df('0x5f')});}}else{return _0x59cd01[_0x49df('0x42')](0x191)['json']({'message':_0x49df('0x5f')});}}_0xbe4f73[_0x49df('0x4d')]={'id':_0x29a799['id']};_0x5b37f2();});})[_0x49df('0x60')](function(){return _0x59cd01[_0x49df('0x42')](0x191)[_0x49df('0x44')]({'message':_0x49df('0x5f')});});}catch(_0x4b939c){_0x5b37f2(_0x4b939c);}}else if(_0x4ab499){_0x5b37f2();}else{return _0x59cd01[_0x49df('0x42')](0x193)['json']({'message':'Unknown\x20authorization\x20format'});}})[_0x49df('0x3b')](function(_0x57855d,_0x591ad3,_0x441737){if(_0x57855d[_0x49df('0x4d')]){db[_0x49df('0x53')][_0x49df('0x4a')]({'where':{'id':_0x57855d[_0x49df('0x4d')]['id']},'attributes':userAttributes})['then'](function(_0x1da5fe){if(!_0x1da5fe){return _0x591ad3[_0x49df('0x42')](0x194)[_0x49df('0x44')]({'message':'User\x20not\x20found.'});}_0x57855d[_0x49df('0x4d')]=_0x1da5fe;_0x441737();})[_0x49df('0x60')](function(_0x523cc0){_0x441737(_0x523cc0);});}else if(_0x4ab499){_0x441737();}else{return _0x591ad3[_0x49df('0x42')](0x194)[_0x49df('0x44')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x49df('0x61')]=function canUpdate(){return compose()[_0x49df('0x3b')](function(_0x3b2d19,_0x46f063,_0x56e305){return licenseUtil[_0x49df('0x62')]()['then'](function(_0x510afb){if(_0x510afb[_0x49df('0x63')]){_0x56e305();}else{return _0x46f063['status'](0x193)[_0x49df('0x44')]({'message':_0x49df('0x64')});}})[_0x49df('0x60')](function(_0x3ac3e1){_0x56e305(_0x3ac3e1);});});};exports[_0x49df('0x65')]=function isWebrtcLicence(){return compose()[_0x49df('0x3b')](function(_0x23fcb6,_0x467535,_0x206543){return licenseUtil[_0x49df('0x62')]()[_0x49df('0x40')](function(_0x72a94a){if(_0x72a94a[_0x49df('0x66')]){_0x206543();}else{return _0x467535[_0x49df('0x42')](0x193)['json']({'message':_0x49df('0x64')});}})['catch'](function(_0x462759){_0x206543(_0x462759);});});};exports['isMiddleware']=function(_0x1c955b,_0x56268a,_0x43ed47){_0x1c955b[_0x49df('0x67')]=!![];return _0x43ed47();};exports[_0x49df('0x68')]=function signToken(_0xc5c7fb){return signJwt(_0xc5c7fb);};exports[_0x49df('0x69')]=function(_0xc7e627,_0x2add2b){if(!_0xc7e627[_0x49df('0x4d')]){return _0x2add2b[_0x49df('0x42')](0x194)[_0x49df('0x44')]({'message':_0x49df('0x6a')});}var _0x40cb15={'payload':{'id':_0xc7e627[_0x49df('0x4d')]['id'],'role':_0xc7e627[_0x49df('0x4d')][_0x49df('0xd')]},'options':{'expiresIn':0x15180}};return signJwt(_0x40cb15)[_0x49df('0x40')](function(_0x418017){_0x2add2b[_0x49df('0x6b')](_0x49df('0x6c'),_0x418017);_0x2add2b[_0x49df('0x6d')](_0x49df('0x6e'));})[_0x49df('0x60')](function(_0x620594){return _0x2add2b[_0x49df('0x42')](0x1f4)[_0x49df('0x6f')](_0x620594);});};exports['retrieveApiKey']=function(_0x478420){if(_[_0x49df('0x70')](_0x478420['apiKeyNonce'])||_[_0x49df('0x70')](_0x478420['apiKeyIat'])){return null;}else{return createJwt(_0x478420);}};exports['generateApiKey']=function(_0x37858a){_0x37858a['apiKeyNonce']=generateNonce();_0x37858a['apiKeyIat']=generateIssuedAt();return createJwt(_0x37858a);};exports[_0x49df('0x71')]=function(_0xabb9c2,_0x405baf){var _0x59018d=_0xabb9c2[_0x49df('0x41')][_0x49df('0x51')];if(_0x59018d){var _0x1671bc={'nonce':_0x405baf['apiKeyNonce'],'iat':_0x405baf[_0x49df('0x72')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x49df('0x52')]()};return verifyJwt(_0x59018d,_0x1671bc)[_0x49df('0x40')](function(){return generateApiKey(_0x405baf);});}else{throw{'message':_0x49df('0x73')};}};exports[_0x49df('0x74')]=function(_0x2fde3e){var _0x4235ba=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x4235ba[_0x49df('0x75')](_0x2fde3e))throw new db[(_0x49df('0x76'))]['ValidationError'](_0x49df('0x77'));return;};exports[_0x49df('0x78')]=function(_0x128c18,_0x309850,_0x3c38b8){var _0x67812c=encryptor[_0x49df('0x79')](_0x309850)[_0x49df('0x7a')](',');for(var _0x3649fa=0x0;_0x3649fa<_0x3c38b8;_0x3649fa++){if(!_0x67812c[_0x3649fa])break;if(_0x128c18[_0x49df('0x7b')]()===_0x67812c[_0x3649fa][_0x49df('0x7b')]()){var _0xf8898a=util[_0x49df('0x7c')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x3c38b8);if(_0x3c38b8===0x1){_0xf8898a='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x49df('0x76'))][(_0x49df('0x7d'))](_0xf8898a);}}return;};exports[_0x49df('0x7e')]=function(_0x530c78,_0x508602){var _0x271227=_0x508602?encryptor['decryptString'](_0x508602)['split'](','):[];if(_0x271227['length']===0x5){_0x271227[_0x49df('0x7f')](-0x1,0x1);}_0x271227['unshift'](_0x530c78);return encryptor[_0x49df('0x80')](_0x271227[_0x49df('0x81')](','));};function signJwt(_0x2ff996){var _0x5a92aa=BPromise[_0x49df('0x82')](jwt[_0x49df('0x83')],{'context':jwt});var _0x2edc2b=_0x2ff996[_0x49df('0x84')]||config[_0x49df('0xc')][_0x49df('0x85')];return new BPromise(function(_0xe508ca,_0x502265){_0x5a92aa(_0x2ff996['payload'],_0x2edc2b,_0x2ff996[_0x49df('0x86')])[_0x49df('0x40')](function(_0x3bb508){_0xe508ca(_0x3bb508);})[_0x49df('0x60')](function(_0x360e14){_0x502265(_0x360e14);});});}function verifyJwt(_0x2187cb,_0x5aafc2,_0x58aab0){var _0x5dbaa1=BPromise[_0x49df('0x82')](jwt[_0x49df('0x87')],{'context':jwt});var _0x18a0f0=_0x58aab0||config['secrets'][_0x49df('0x85')];return new BPromise(function(_0x3c70db,_0x1aa4eb){_0x5dbaa1(_0x2187cb,_0x18a0f0,_0x5aafc2)[_0x49df('0x40')](function(_0x1a9fb1){_0x3c70db(_0x1a9fb1);})[_0x49df('0x60')](function(_0x405cba){_0x1aa4eb(_0x405cba);});});}function generateNonce(){return crypto[_0x49df('0x88')](0x10)[_0x49df('0x89')]('hex');}function generateIssuedAt(){return Math['floor'](Date['now']()/0x3e8)['toString']();}function createJwt(_0x535716){var _0x1cca8b={'payload':{'iat':_0x535716[_0x49df('0x72')],'nonce':_0x535716['apiKeyNonce']},'options':{'algorithm':'HS512','subject':_0x535716['id']['toString'](),'issuer':hardwareConf[_0x49df('0x52')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x1cca8b)[_0x49df('0x40')](function(_0x43a7a8){return{'iat':_0x535716[_0x49df('0x72')],'nonce':_0x535716[_0x49df('0x58')],'token':_0x43a7a8};});}