341a214d1800ae2e0fbdbe5466fe6a6a26163c17
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xc085=['authorization','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','find','sub','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','blocked','blockedAt','add','minutes','User\x20object\x20not\x20found.','canUpdate','getLicense','Forbidden','isWebrtcLicence','webrtc','isMiddleware','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','split','length','splice','encryptString','join','promisify','sign','secret','randomBytes','toString','hex','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','secrets','session','role','fullname','name','internal','email','userpic','permissions','voicePause','mailPause','faxPause','openchannelPause','pauseType','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','privacyEnabled','wssPort','downloadAttachments','ignorePauseForPreviewCalls','chatAutoanswerDelay','emailAutoanswer','smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer','openchannelAutoanswerDelay','faxAutoanswerDelay','whatsappAutoanswerDelay','messengerSoundNotification','isChatInteractionAuthorized','isAuthenticated','user','ChatInteraction','findOne','params','closed','then','query','forceDownload','status','disposition','unmanaged','json','Unmanaged.','Forbidden.','use','headers','Basic','User','pass','Wrong\x20credentials.','catch','startsWith'];(function(_0x577427,_0x2598b9){var _0x2d4789=function(_0x5bfe81){while(--_0x5bfe81){_0x577427['push'](_0x577427['shift']());}};_0x2d4789(++_0x2598b9);}(_0xc085,0xc2));var _0x5c08=function(_0x360061,_0x2f14e5){_0x360061=_0x360061-0x0;var _0x567662=_0xc085[_0x360061];return _0x567662;};'use strict';var db=require(_0x5c08('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x5c08('0x1'));var licenseUtil=require(_0x5c08('0x2'));var encryptor=require(_0x5c08('0x3'));var _=require(_0x5c08('0x4'));var jwt=require(_0x5c08('0x5'));var expressJwt=require(_0x5c08('0x6'));var compose=require(_0x5c08('0x7'));var basicAuth=require(_0x5c08('0x8'));var crypto=require('crypto');var BPromise=require('bluebird');var util=require('util');var moment=require('moment');var validateJwt=expressJwt({'secret':config[_0x5c08('0x9')][_0x5c08('0xa')]});var userAttributes=['id',_0x5c08('0xb'),_0x5c08('0xc'),_0x5c08('0xd'),_0x5c08('0xe'),_0x5c08('0xf'),_0x5c08('0x10'),_0x5c08('0x11'),'md5secret',_0x5c08('0x12'),'chatPause',_0x5c08('0x13'),_0x5c08('0x14'),'smsPause',_0x5c08('0x15'),_0x5c08('0x16'),'showWebBar',_0x5c08('0x17'),_0x5c08('0x18'),_0x5c08('0x19'),_0x5c08('0x1a'),_0x5c08('0x1b'),_0x5c08('0x1c'),'phoneBarAutoAnswer','phoneBarAutoAnswerDelay',_0x5c08('0x1d'),_0x5c08('0x1e'),_0x5c08('0x1f'),_0x5c08('0x20'),_0x5c08('0x21'),_0x5c08('0x22'),_0x5c08('0x23'),_0x5c08('0x24'),_0x5c08('0x25'),_0x5c08('0x26'),'userProfileId',_0x5c08('0x27'),'settingsEnabled',_0x5c08('0x28'),'downloadVoiceRecordings','downloadOmnichannelInteractions',_0x5c08('0x29'),_0x5c08('0x2a'),'selectRecallMeCampaign','chatAutoanswer',_0x5c08('0x2b'),_0x5c08('0x2c'),'emailAutoanswerDelay',_0x5c08('0x2d'),_0x5c08('0x2e'),_0x5c08('0x2f'),_0x5c08('0x30'),'faxAutoanswer',_0x5c08('0x31'),'whatsappAutoanswer',_0x5c08('0x32'),_0x5c08('0x33')];exports[_0x5c08('0x34')]=function(){return this[_0x5c08('0x35')](!![])['use'](function(_0x371a1c,_0x255b8f,_0x390fde){if(_0x371a1c[_0x5c08('0x36')]){_0x390fde();}else{return db[_0x5c08('0x37')][_0x5c08('0x38')]({'where':{'id':_0x371a1c[_0x5c08('0x39')]['id']},'attributes':['id',_0x5c08('0x3a'),'disposition'],'raw':!![]})[_0x5c08('0x3b')](function(_0x50d2c3){if(_0x50d2c3&&_0x50d2c3[_0x5c08('0x3a')]&&!_0x371a1c[_0x5c08('0x3c')][_0x5c08('0x3d')]){return _0x255b8f[_0x5c08('0x3e')](_0x50d2c3[_0x5c08('0x3f')]===_0x5c08('0x40')?0x195:0x193)[_0x5c08('0x41')]({'message':_0x50d2c3[_0x5c08('0x3f')]===_0x5c08('0x40')?_0x5c08('0x42'):_0x5c08('0x43')});}else{_0x390fde();}})['catch'](function(_0x3b5991){_0x390fde(_0x3b5991);});}});};exports[_0x5c08('0x35')]=function isAuthenticated(_0x4327f4){return compose()[_0x5c08('0x44')](function(_0x2cda49,_0x3561c8,_0x38c498){var _0xb3d6bc;if(_0x2cda49[_0x5c08('0x45')]['authorization']){if(_['startsWith'](_0x2cda49[_0x5c08('0x45')]['authorization'],_0x5c08('0x46'))){var _0x5eb1b9=basicAuth(_0x2cda49);db[_0x5c08('0x47')]['find']({'where':{'name':_0x5eb1b9[_0x5c08('0xd')]}})[_0x5c08('0x3b')](function(_0x558c76){if(!_0x558c76||!_0x558c76['authenticate'](_0x5eb1b9[_0x5c08('0x48')])){return _0x3561c8[_0x5c08('0x3e')](0x191)[_0x5c08('0x41')]({'message':_0x5c08('0x49')});}_0x2cda49[_0x5c08('0x36')]={'id':_0x558c76['id']};_0x38c498();})[_0x5c08('0x4a')](function(_0x4ea50c){_0x38c498(_0x4ea50c);});}else if(_[_0x5c08('0x4b')](_0x2cda49[_0x5c08('0x45')][_0x5c08('0x4c')],_0x5c08('0x4d'))){validateJwt(_0x2cda49,_0x3561c8,_0x38c498);}else{if(_0x4327f4){_0x38c498();}else{return _0x3561c8[_0x5c08('0x3e')](0x193)[_0x5c08('0x41')]({'message':_0x5c08('0x4e')});}}}else if(_0x2cda49['query'][_0x5c08('0x4f')]){try{var _0x399478={'audience':hardwareConf[_0x5c08('0x50')](),'issuer':hardwareConf[_0x5c08('0x50')]()};verifyJwt(_0x2cda49[_0x5c08('0x3c')][_0x5c08('0x4f')],_0x399478)[_0x5c08('0x3b')](function(_0x48ad99){return db[_0x5c08('0x47')][_0x5c08('0x51')]({'where':{'id':_0x48ad99[_0x5c08('0x52')]}})[_0x5c08('0x3b')](function(_0x4958b3){_0xb3d6bc=_0x4958b3;return db['Setting'][_0x5c08('0x38')]({'where':{'id':0x1},'attributes':[_0x5c08('0x53'),_0x5c08('0x54')],'raw':!![]});})[_0x5c08('0x3b')](function(_0x2c0029){if(!_0xb3d6bc||!_[_0x5c08('0x55')](_0xb3d6bc[_0x5c08('0x56')],_0x48ad99['nonce'])){return _0x3561c8['status'](0x191)[_0x5c08('0x41')]({'message':_0x5c08('0x57')});}if(_0xb3d6bc['disabled']){return _0x3561c8[_0x5c08('0x3e')](0x191)[_0x5c08('0x41')]({'message':_0x5c08('0x58')});}if(_0xb3d6bc[_0x5c08('0x59')]){if(_0x2c0029[_0x5c08('0x54')]>0x0){if(moment(_0xb3d6bc[_0x5c08('0x5a')])[_0x5c08('0x5b')](_0x2c0029[_0x5c08('0x54')],_0x5c08('0x5c'))>moment()){return _0x3561c8[_0x5c08('0x3e')](0x191)['json']({'message':_0x5c08('0x58')});}}else{return _0x3561c8[_0x5c08('0x3e')](0x191)[_0x5c08('0x41')]({'message':_0x5c08('0x58')});}}_0x2cda49[_0x5c08('0x36')]={'id':_0xb3d6bc['id']};_0x38c498();});})[_0x5c08('0x4a')](function(){return _0x3561c8[_0x5c08('0x3e')](0x191)[_0x5c08('0x41')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x21e99c){_0x38c498(_0x21e99c);}}else if(_0x4327f4){_0x38c498();}else{return _0x3561c8[_0x5c08('0x3e')](0x193)[_0x5c08('0x41')]({'message':_0x5c08('0x4e')});}})['use'](function(_0x3bded1,_0x5a22f4,_0x332261){if(_0x3bded1[_0x5c08('0x36')]){db['User'][_0x5c08('0x51')]({'where':{'id':_0x3bded1['user']['id']},'attributes':userAttributes})[_0x5c08('0x3b')](function(_0x400d52){if(!_0x400d52){return _0x5a22f4[_0x5c08('0x3e')](0x194)[_0x5c08('0x41')]({'message':'User\x20not\x20found.'});}_0x3bded1[_0x5c08('0x36')]=_0x400d52;_0x332261();})[_0x5c08('0x4a')](function(_0x1f96a8){_0x332261(_0x1f96a8);});}else if(_0x4327f4){_0x332261();}else{return _0x5a22f4[_0x5c08('0x3e')](0x194)['json']({'message':_0x5c08('0x5d')});}});};exports[_0x5c08('0x5e')]=function canUpdate(){return compose()[_0x5c08('0x44')](function(_0x28fadd,_0x136080,_0x53e711){return licenseUtil[_0x5c08('0x5f')]()[_0x5c08('0x3b')](function(_0x9f46d8){if(_0x9f46d8['update']){_0x53e711();}else{return _0x136080['status'](0x193)[_0x5c08('0x41')]({'message':_0x5c08('0x60')});}})['catch'](function(_0x4a0f25){_0x53e711(_0x4a0f25);});});};exports[_0x5c08('0x61')]=function isWebrtcLicence(){return compose()[_0x5c08('0x44')](function(_0x16f391,_0x16e236,_0x17712a){return licenseUtil['getLicense']()[_0x5c08('0x3b')](function(_0x1b69f3){if(_0x1b69f3[_0x5c08('0x62')]){_0x17712a();}else{return _0x16e236[_0x5c08('0x3e')](0x193)[_0x5c08('0x41')]({'message':_0x5c08('0x60')});}})['catch'](function(_0x1cf107){_0x17712a(_0x1cf107);});});};exports[_0x5c08('0x63')]=function(_0xcfc87e,_0xe7415e,_0xf5e9a2){_0xcfc87e[_0x5c08('0x63')]=!![];return _0xf5e9a2();};exports['signToken']=function signToken(_0x3f2a34){return signJwt(_0x3f2a34);};exports[_0x5c08('0x64')]=function(_0x569d41,_0x44259e){if(!_0x569d41[_0x5c08('0x36')]){return _0x44259e[_0x5c08('0x3e')](0x194)[_0x5c08('0x41')]({'message':_0x5c08('0x65')});}var _0x8d8347={'payload':{'id':_0x569d41[_0x5c08('0x36')]['id'],'role':_0x569d41[_0x5c08('0x36')][_0x5c08('0xb')]},'options':{'expiresIn':0x15180}};return signJwt(_0x8d8347)[_0x5c08('0x3b')](function(_0x42153a){_0x44259e[_0x5c08('0x66')](_0x5c08('0x67'),_0x42153a);_0x44259e[_0x5c08('0x68')](_0x5c08('0x69'));})[_0x5c08('0x4a')](function(_0x154699){return _0x44259e['status'](0x1f4)[_0x5c08('0x6a')](_0x154699);});};exports[_0x5c08('0x6b')]=function(_0x2bfac5){if(_[_0x5c08('0x6c')](_0x2bfac5[_0x5c08('0x56')])||_['isNil'](_0x2bfac5[_0x5c08('0x6d')])){return null;}else{return createJwt(_0x2bfac5);}};exports[_0x5c08('0x6e')]=function(_0x1d2867){_0x1d2867[_0x5c08('0x56')]=generateNonce();_0x1d2867['apiKeyIat']=generateIssuedAt();return createJwt(_0x1d2867);};exports[_0x5c08('0x6f')]=function(_0x328985,_0x479acd){var _0xf18d20=_0x328985[_0x5c08('0x3c')][_0x5c08('0x4f')];if(_0xf18d20){var _0x26e5a4={'nonce':_0x479acd['apiKeyNonce'],'iat':_0x479acd[_0x5c08('0x6d')],'audience':hardwareConf[_0x5c08('0x50')](),'issuer':hardwareConf[_0x5c08('0x50')]()};return verifyJwt(_0xf18d20,_0x26e5a4)[_0x5c08('0x3b')](function(){return generateApiKey(_0x479acd);});}else{throw{'message':_0x5c08('0x70')};}};exports[_0x5c08('0x71')]=function(_0x4e6da6){var _0x12fd02=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x12fd02[_0x5c08('0x72')](_0x4e6da6))throw new db[(_0x5c08('0x73'))][(_0x5c08('0x74'))](_0x5c08('0x75'));return;};exports[_0x5c08('0x76')]=function(_0x29dc0c,_0xd4abaf,_0x170621){var _0x2ec02f=encryptor[_0x5c08('0x77')](_0xd4abaf)['split'](',');for(var _0x32581a=0x0;_0x32581a<_0x170621;_0x32581a++){if(!_0x2ec02f[_0x32581a])break;if(_0x29dc0c[_0x5c08('0x78')]()===_0x2ec02f[_0x32581a]['toLowerCase']()){var _0x13b3bf=util[_0x5c08('0x79')](_0x5c08('0x7a'),_0x170621);if(_0x170621===0x1){_0x13b3bf='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db['Sequelize'][(_0x5c08('0x74'))](_0x13b3bf);}}return;};exports['updatePasswordsHistory']=function(_0x54503f,_0x2bda5d){var _0x6c82a1=_0x2bda5d?encryptor[_0x5c08('0x77')](_0x2bda5d)[_0x5c08('0x7b')](','):[];if(_0x6c82a1[_0x5c08('0x7c')]===0x5){_0x6c82a1[_0x5c08('0x7d')](-0x1,0x1);}_0x6c82a1['unshift'](_0x54503f);return encryptor[_0x5c08('0x7e')](_0x6c82a1[_0x5c08('0x7f')](','));};function signJwt(_0x5cb9df){var _0x3ae966=BPromise[_0x5c08('0x80')](jwt[_0x5c08('0x81')],{'context':jwt});var _0x1ada59=_0x5cb9df[_0x5c08('0x82')]||config[_0x5c08('0x9')]['session'];return new BPromise(function(_0x6de268,_0x555b86){_0x3ae966(_0x5cb9df['payload'],_0x1ada59,_0x5cb9df['options'])[_0x5c08('0x3b')](function(_0x2803bc){_0x6de268(_0x2803bc);})[_0x5c08('0x4a')](function(_0x180265){_0x555b86(_0x180265);});});}function verifyJwt(_0x210fb2,_0x19e222,_0x1a811c){var _0x4e9550=BPromise['promisify'](jwt['verify'],{'context':jwt});var _0x336bbc=_0x1a811c||config[_0x5c08('0x9')]['session'];return new BPromise(function(_0x2ad007,_0x37bfc7){_0x4e9550(_0x210fb2,_0x336bbc,_0x19e222)[_0x5c08('0x3b')](function(_0x4c6fc6){_0x2ad007(_0x4c6fc6);})[_0x5c08('0x4a')](function(_0x39bf25){_0x37bfc7(_0x39bf25);});});}function generateNonce(){return crypto[_0x5c08('0x83')](0x10)[_0x5c08('0x84')](_0x5c08('0x85'));}function generateIssuedAt(){return Math['floor'](Date['now']()/0x3e8)[_0x5c08('0x84')]();}function createJwt(_0x2dc085){var _0xf1ad06={'payload':{'iat':_0x2dc085['apiKeyIat'],'nonce':_0x2dc085[_0x5c08('0x56')]},'options':{'algorithm':_0x5c08('0x86'),'subject':_0x2dc085['id'][_0x5c08('0x84')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x5c08('0x50')]()}};return signJwt(_0xf1ad06)[_0x5c08('0x3b')](function(_0x34c1cb){return{'iat':_0x2dc085[_0x5c08('0x6d')],'nonce':_0x2dc085[_0x5c08('0x56')],'token':_0x34c1cb};});}