84a3c9a36bdb1eea832adb158c917793c1a14869
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x9411=['apikey','getUuid','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','blocked','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User\x20not\x20found.','User\x20object\x20not\x20found.','update','isMiddleware','setTokenCookie','motion.token','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','ValidationError','validatePasswordHistory','decryptString','split','toLowerCase','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','Sequelize','length','splice','unshift','encryptString','promisify','secret','payload','randomBytes','toString','hex','floor','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','jsonwebtoken','composable-middleware','basic-auth','crypto','util','moment','secrets','session','role','fullname','name','userpic','permissions','voicePause','chatPause','mailPause','faxPause','openchannelPause','pauseType','showWebBar','lastLoginAt','allowmessenger','passwordResetAt','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','wssPort','downloadAttachments','ignorePauseForPreviewCalls','selectRecallMeCampaign','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','then','status','unmanaged','catch','authorization','startsWith','headers','Basic','User','authenticate','pass','json','Wrong\x20credentials.','Bearer','query'];(function(_0x4914e2,_0x48be8f){var _0x2dcd07=function(_0x1a2565){while(--_0x1a2565){_0x4914e2['push'](_0x4914e2['shift']());}};_0x2dcd07(++_0x48be8f);}(_0x9411,0x183));var _0x1941=function(_0x54220d,_0x36afe0){_0x54220d=_0x54220d-0x0;var _0x1a729e=_0x9411[_0x54220d];return _0x1a729e;};'use strict';var db=require(_0x1941('0x0'))['db'];var config=require(_0x1941('0x1'));var hardwareConf=require(_0x1941('0x2'));var licenseUtil=require('../../config/license/util');var encryptor=require('../encryptor');var _=require('lodash');var jwt=require(_0x1941('0x3'));var expressJwt=require('express-jwt');var compose=require(_0x1941('0x4'));var basicAuth=require(_0x1941('0x5'));var crypto=require(_0x1941('0x6'));var BPromise=require('bluebird');var util=require(_0x1941('0x7'));var moment=require(_0x1941('0x8'));var validateJwt=expressJwt({'secret':config[_0x1941('0x9')][_0x1941('0xa')]});var userAttributes=['id',_0x1941('0xb'),_0x1941('0xc'),_0x1941('0xd'),'internal','email',_0x1941('0xe'),_0x1941('0xf'),'md5secret',_0x1941('0x10'),_0x1941('0x11'),_0x1941('0x12'),_0x1941('0x13'),'smsPause',_0x1941('0x14'),_0x1941('0x15'),_0x1941('0x16'),_0x1941('0x17'),'lastPauseAt','crudPermissions',_0x1941('0x18'),_0x1941('0x19'),'alias','phoneBarAutoAnswer',_0x1941('0x1a'),_0x1941('0x1b'),_0x1941('0x1c'),'phoneBarEnableDtmfTone',_0x1941('0x1d'),_0x1941('0x1e'),_0x1941('0x1f'),_0x1941('0x20'),_0x1941('0x21'),_0x1941('0x22'),_0x1941('0x23'),_0x1941('0x24'),'privacyEnabled','settingsEnabled',_0x1941('0x25'),'downloadVoiceRecordings','downloadOmnichannelInteractions',_0x1941('0x26'),_0x1941('0x27'),_0x1941('0x28')];exports[_0x1941('0x29')]=function(){return this[_0x1941('0x2a')](!![])[_0x1941('0x2b')](function(_0x335d6a,_0x16af5e,_0x22e5a5){if(_0x335d6a[_0x1941('0x2c')]){_0x22e5a5();}else{return db[_0x1941('0x2d')][_0x1941('0x2e')]({'where':{'id':_0x335d6a[_0x1941('0x2f')]['id']},'attributes':['id',_0x1941('0x30'),_0x1941('0x31')],'raw':!![]})[_0x1941('0x32')](function(_0x434c8d){if(_0x434c8d&&_0x434c8d[_0x1941('0x30')]){return _0x16af5e[_0x1941('0x33')](_0x434c8d['disposition']===_0x1941('0x34')?0x195:0x193)['json']({'message':_0x434c8d['disposition']==='unmanaged'?'Unmanaged.':'Forbidden.'});}else{_0x22e5a5();}})[_0x1941('0x35')](function(_0x4c66ba){_0x22e5a5(_0x4c66ba);});}});};exports['isAuthenticated']=function isAuthenticated(_0x46e0a4){return compose()['use'](function(_0x311b24,_0xccaf17,_0x122cb2){var _0xcafc07;if(_0x311b24['headers'][_0x1941('0x36')]){if(_[_0x1941('0x37')](_0x311b24[_0x1941('0x38')][_0x1941('0x36')],_0x1941('0x39'))){var _0x1c3402=basicAuth(_0x311b24);db[_0x1941('0x3a')]['find']({'where':{'name':_0x1c3402[_0x1941('0xd')]}})[_0x1941('0x32')](function(_0x3bad4c){if(!_0x3bad4c||!_0x3bad4c[_0x1941('0x3b')](_0x1c3402[_0x1941('0x3c')])){return _0xccaf17[_0x1941('0x33')](0x191)[_0x1941('0x3d')]({'message':_0x1941('0x3e')});}_0x311b24[_0x1941('0x2c')]={'id':_0x3bad4c['id']};_0x122cb2();})['catch'](function(_0x22e904){_0x122cb2(_0x22e904);});}else if(_[_0x1941('0x37')](_0x311b24[_0x1941('0x38')][_0x1941('0x36')],_0x1941('0x3f'))){validateJwt(_0x311b24,_0xccaf17,_0x122cb2);}else{if(_0x46e0a4){_0x122cb2();}else{return _0xccaf17[_0x1941('0x33')](0x193)[_0x1941('0x3d')]({'message':'Unknown\x20authorization\x20format'});}}}else if(_0x311b24[_0x1941('0x40')][_0x1941('0x41')]){try{var _0x3b4fd5={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x1941('0x42')]()};verifyJwt(_0x311b24[_0x1941('0x40')][_0x1941('0x41')],_0x3b4fd5)[_0x1941('0x32')](function(_0x3a82eb){return db['User']['find']({'where':{'id':_0x3a82eb['sub']}})['then'](function(_0x327ec2){_0xcafc07=_0x327ec2;return db[_0x1941('0x43')][_0x1941('0x2e')]({'where':{'id':0x1},'attributes':[_0x1941('0x44'),_0x1941('0x45')],'raw':!![]});})[_0x1941('0x32')](function(_0x44a55c){if(!_0xcafc07||!_[_0x1941('0x46')](_0xcafc07[_0x1941('0x47')],_0x3a82eb[_0x1941('0x48')])){return _0xccaf17[_0x1941('0x33')](0x191)[_0x1941('0x3d')]({'message':_0x1941('0x49')});}if(_0xcafc07['disabled']){return _0xccaf17[_0x1941('0x33')](0x191)[_0x1941('0x3d')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0xcafc07[_0x1941('0x4a')]){if(_0x44a55c[_0x1941('0x45')]>0x0){if(moment(_0xcafc07[_0x1941('0x4b')])[_0x1941('0x4c')](_0x44a55c[_0x1941('0x45')],_0x1941('0x4d'))>moment()){return _0xccaf17[_0x1941('0x33')](0x191)[_0x1941('0x3d')]({'message':_0x1941('0x4e')});}}else{return _0xccaf17[_0x1941('0x33')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}}_0x311b24[_0x1941('0x2c')]={'id':_0xcafc07['id']};_0x122cb2();});})[_0x1941('0x35')](function(){return _0xccaf17[_0x1941('0x33')](0x191)[_0x1941('0x3d')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0xcc7743){_0x122cb2(_0xcc7743);}}else if(_0x46e0a4){_0x122cb2();}else{return _0xccaf17[_0x1941('0x33')](0x193)[_0x1941('0x3d')]({'message':'Unknown\x20authorization\x20format'});}})[_0x1941('0x2b')](function(_0x2f3a3d,_0x3e7569,_0x57a1fd){if(_0x2f3a3d[_0x1941('0x2c')]){db[_0x1941('0x3a')]['find']({'where':{'id':_0x2f3a3d[_0x1941('0x2c')]['id']},'attributes':userAttributes})[_0x1941('0x32')](function(_0xee3d4f){if(!_0xee3d4f){return _0x3e7569[_0x1941('0x33')](0x194)[_0x1941('0x3d')]({'message':_0x1941('0x4f')});}_0x2f3a3d[_0x1941('0x2c')]=_0xee3d4f;_0x57a1fd();})[_0x1941('0x35')](function(_0x459bb6){_0x57a1fd(_0x459bb6);});}else if(_0x46e0a4){_0x57a1fd();}else{return _0x3e7569['status'](0x194)[_0x1941('0x3d')]({'message':_0x1941('0x50')});}});};exports['canUpdate']=function canUpdate(){return compose()[_0x1941('0x2b')](function(_0x2244e8,_0x264f7c,_0x5d5caf){return licenseUtil['getLicense']()[_0x1941('0x32')](function(_0x4fc9de){if(_0x4fc9de[_0x1941('0x51')]){_0x5d5caf();}else{return _0x264f7c[_0x1941('0x33')](0x193)['json']({'message':'Forbidden'});}})[_0x1941('0x35')](function(_0x5c3c86){_0x5d5caf(_0x5c3c86);});});};exports[_0x1941('0x52')]=function(_0x21875b,_0x3f34f1,_0x3de8e4){_0x21875b[_0x1941('0x52')]=!![];return _0x3de8e4();};exports['signToken']=function signToken(_0x262f5e){return signJwt(_0x262f5e);};exports[_0x1941('0x53')]=function(_0xcfbba3,_0x2c1666){if(!_0xcfbba3[_0x1941('0x2c')]){return _0x2c1666[_0x1941('0x33')](0x194)[_0x1941('0x3d')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x38e692={'payload':{'id':_0xcfbba3[_0x1941('0x2c')]['id'],'role':_0xcfbba3[_0x1941('0x2c')][_0x1941('0xb')]},'options':{'expiresIn':0x15180}};return signJwt(_0x38e692)[_0x1941('0x32')](function(_0xf4f7a5){_0x2c1666['cookie'](_0x1941('0x54'),_0xf4f7a5);_0x2c1666['redirect'](_0x1941('0x55'));})[_0x1941('0x35')](function(_0x1abbe8){return _0x2c1666[_0x1941('0x33')](0x1f4)[_0x1941('0x56')](_0x1abbe8);});};exports[_0x1941('0x57')]=function(_0x2a1eff){if(_[_0x1941('0x58')](_0x2a1eff[_0x1941('0x47')])||_[_0x1941('0x58')](_0x2a1eff['apiKeyIat'])){return null;}else{return createJwt(_0x2a1eff);}};exports['generateApiKey']=function(_0x2f3c2b){_0x2f3c2b[_0x1941('0x47')]=generateNonce();_0x2f3c2b['apiKeyIat']=generateIssuedAt();return createJwt(_0x2f3c2b);};exports['regenerateApiKey']=function(_0x9cf981,_0xc39450){var _0x46437e=_0x9cf981['query'][_0x1941('0x41')];if(_0x46437e){var _0x1d2509={'nonce':_0xc39450[_0x1941('0x47')],'iat':_0xc39450[_0x1941('0x59')],'audience':hardwareConf[_0x1941('0x42')](),'issuer':hardwareConf[_0x1941('0x42')]()};return verifyJwt(_0x46437e,_0x1d2509)['then'](function(){return generateApiKey(_0xc39450);});}else{throw{'message':_0x1941('0x5a')};}};exports[_0x1941('0x5b')]=function(_0x1971d){var _0x36c6d5=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x36c6d5[_0x1941('0x5c')](_0x1971d))throw new db['Sequelize'][(_0x1941('0x5d'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x1941('0x5e')]=function(_0x54c131,_0x2482c0,_0x4de4e1){var _0x38b82c=encryptor[_0x1941('0x5f')](_0x2482c0)[_0x1941('0x60')](',');for(var _0x40b199=0x0;_0x40b199<_0x4de4e1;_0x40b199++){if(!_0x38b82c[_0x40b199])break;if(_0x54c131[_0x1941('0x61')]()===_0x38b82c[_0x40b199][_0x1941('0x61')]()){var _0x58c8a7=util['format'](_0x1941('0x62'),_0x4de4e1);if(_0x4de4e1===0x1){_0x58c8a7=_0x1941('0x63');}throw new db[(_0x1941('0x64'))][(_0x1941('0x5d'))](_0x58c8a7);}}return;};exports['updatePasswordsHistory']=function(_0x3f61ff,_0x1e7bc2){var _0x22e48b=_0x1e7bc2?encryptor['decryptString'](_0x1e7bc2)['split'](','):[];if(_0x22e48b[_0x1941('0x65')]===0x5){_0x22e48b[_0x1941('0x66')](-0x1,0x1);}_0x22e48b[_0x1941('0x67')](_0x3f61ff);return encryptor[_0x1941('0x68')](_0x22e48b['join'](','));};function signJwt(_0x8f781b){var _0x95febb=BPromise[_0x1941('0x69')](jwt['sign'],{'context':jwt});var _0xc93f7=_0x8f781b[_0x1941('0x6a')]||config[_0x1941('0x9')]['session'];return new BPromise(function(_0x5d3d23,_0x22e730){_0x95febb(_0x8f781b[_0x1941('0x6b')],_0xc93f7,_0x8f781b['options'])['then'](function(_0x64bb24){_0x5d3d23(_0x64bb24);})[_0x1941('0x35')](function(_0xed959f){_0x22e730(_0xed959f);});});}function verifyJwt(_0x414ce7,_0x52f4fc,_0x21dea1){var _0x5979e=BPromise[_0x1941('0x69')](jwt['verify'],{'context':jwt});var _0x11ec9d=_0x21dea1||config[_0x1941('0x9')][_0x1941('0xa')];return new BPromise(function(_0x197733,_0x592d8e){_0x5979e(_0x414ce7,_0x11ec9d,_0x52f4fc)['then'](function(_0x1b6cba){_0x197733(_0x1b6cba);})[_0x1941('0x35')](function(_0x2ef1f7){_0x592d8e(_0x2ef1f7);});});}function generateNonce(){return crypto[_0x1941('0x6c')](0x10)[_0x1941('0x6d')](_0x1941('0x6e'));}function generateIssuedAt(){return Math[_0x1941('0x6f')](Date['now']()/0x3e8)[_0x1941('0x6d')]();}function createJwt(_0x476459){var _0x3d425a={'payload':{'iat':_0x476459[_0x1941('0x59')],'nonce':_0x476459['apiKeyNonce']},'options':{'algorithm':_0x1941('0x70'),'subject':_0x476459['id'][_0x1941('0x6d')](),'issuer':hardwareConf[_0x1941('0x42')](),'audience':hardwareConf[_0x1941('0x42')]()}};return signJwt(_0x3d425a)[_0x1941('0x32')](function(_0x34b0f1){return{'iat':_0x476459[_0x1941('0x59')],'nonce':_0x476459[_0x1941('0x47')],'token':_0x34b0f1};});}