95a3a434da4c2b543cf317d7c5a3807875b6bd14
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x00fd=['whatsappAutoanswerDelay','isChatInteractionAuthorized','isAuthenticated','user','ChatInteraction','findOne','params','closed','disposition','then','query','forceDownload','unmanaged','Unmanaged.','Forbidden.','catch','use','headers','authorization','startsWith','find','authenticate','pass','status','json','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','User','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User\x20not\x20found.','canUpdate','getLicense','update','isWebrtcLicence','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','isNil','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','decryptString','length','unshift','encryptString','join','promisify','secret','verify','randomBytes','toString','hex','floor','now','HS512','../../config/environment','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util','moment','secrets','session','role','fullname','name','internal','email','userpic','permissions','md5secret','chatPause','mailPause','faxPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','privacyEnabled','settingsEnabled','wssPort','ignorePauseForPreviewCalls','selectRecallMeCampaign','chatAutoanswer','chatAutoanswerDelay','emailAutoanswer','emailAutoanswerDelay','smsAutoanswerDelay','openchannelAutoanswerDelay','faxAutoanswer','faxAutoanswerDelay'];(function(_0x5b561d,_0x422b7c){var _0x431060=function(_0x401409){while(--_0x401409){_0x5b561d['push'](_0x5b561d['shift']());}};_0x431060(++_0x422b7c);}(_0x00fd,0xe2));var _0xd00f=function(_0x157a5f,_0x3cc3fe){_0x157a5f=_0x157a5f-0x0;var _0x3c1de6=_0x00fd[_0x157a5f];return _0x3c1de6;};'use strict';var db=require('../../mysqldb')['db'];var config=require(_0xd00f('0x0'));var hardwareConf=require('../../config/license/hardware');var licenseUtil=require(_0xd00f('0x1'));var encryptor=require(_0xd00f('0x2'));var _=require(_0xd00f('0x3'));var jwt=require(_0xd00f('0x4'));var expressJwt=require(_0xd00f('0x5'));var compose=require(_0xd00f('0x6'));var basicAuth=require(_0xd00f('0x7'));var crypto=require(_0xd00f('0x8'));var BPromise=require(_0xd00f('0x9'));var util=require(_0xd00f('0xa'));var moment=require(_0xd00f('0xb'));var validateJwt=expressJwt({'secret':config[_0xd00f('0xc')][_0xd00f('0xd')]});var userAttributes=['id',_0xd00f('0xe'),_0xd00f('0xf'),_0xd00f('0x10'),_0xd00f('0x11'),_0xd00f('0x12'),_0xd00f('0x13'),_0xd00f('0x14'),_0xd00f('0x15'),'voicePause',_0xd00f('0x16'),_0xd00f('0x17'),_0xd00f('0x18'),'smsPause',_0xd00f('0x19'),_0xd00f('0x1a'),_0xd00f('0x1b'),_0xd00f('0x1c'),_0xd00f('0x1d'),'crudPermissions','allowmessenger','passwordResetAt','alias',_0xd00f('0x1e'),_0xd00f('0x1f'),_0xd00f('0x20'),_0xd00f('0x21'),_0xd00f('0x22'),_0xd00f('0x23'),'phoneBarExpires',_0xd00f('0x24'),_0xd00f('0x25'),_0xd00f('0x26'),_0xd00f('0x27'),_0xd00f('0x28'),'userProfileId',_0xd00f('0x29'),_0xd00f('0x2a'),_0xd00f('0x2b'),'downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments',_0xd00f('0x2c'),_0xd00f('0x2d'),_0xd00f('0x2e'),_0xd00f('0x2f'),_0xd00f('0x30'),_0xd00f('0x31'),'smsAutoanswer',_0xd00f('0x32'),'openchannelAutoanswer',_0xd00f('0x33'),_0xd00f('0x34'),_0xd00f('0x35'),'whatsappAutoanswer',_0xd00f('0x36'),'messengerSoundNotification'];exports[_0xd00f('0x37')]=function(){return this[_0xd00f('0x38')](!![])['use'](function(_0x464300,_0x11e877,_0x36f295){if(_0x464300[_0xd00f('0x39')]){_0x36f295();}else{return db[_0xd00f('0x3a')][_0xd00f('0x3b')]({'where':{'id':_0x464300[_0xd00f('0x3c')]['id']},'attributes':['id',_0xd00f('0x3d'),_0xd00f('0x3e')],'raw':!![]})[_0xd00f('0x3f')](function(_0x819af9){if(_0x819af9&&_0x819af9['closed']&&!_0x464300[_0xd00f('0x40')][_0xd00f('0x41')]){return _0x11e877['status'](_0x819af9[_0xd00f('0x3e')]===_0xd00f('0x42')?0x195:0x193)['json']({'message':_0x819af9[_0xd00f('0x3e')]===_0xd00f('0x42')?_0xd00f('0x43'):_0xd00f('0x44')});}else{_0x36f295();}})[_0xd00f('0x45')](function(_0x27a59f){_0x36f295(_0x27a59f);});}});};exports[_0xd00f('0x38')]=function isAuthenticated(_0x4e907e){return compose()[_0xd00f('0x46')](function(_0x518654,_0x790632,_0x810794){var _0x1cf27c;if(_0x518654[_0xd00f('0x47')][_0xd00f('0x48')]){if(_[_0xd00f('0x49')](_0x518654['headers'][_0xd00f('0x48')],'Basic')){var _0x14ab9f=basicAuth(_0x518654);db['User'][_0xd00f('0x4a')]({'where':{'name':_0x14ab9f[_0xd00f('0x10')]}})[_0xd00f('0x3f')](function(_0x558170){if(!_0x558170||!_0x558170[_0xd00f('0x4b')](_0x14ab9f[_0xd00f('0x4c')])){return _0x790632[_0xd00f('0x4d')](0x191)[_0xd00f('0x4e')]({'message':_0xd00f('0x4f')});}_0x518654[_0xd00f('0x39')]={'id':_0x558170['id']};_0x810794();})['catch'](function(_0x4b072a){_0x810794(_0x4b072a);});}else if(_['startsWith'](_0x518654[_0xd00f('0x47')]['authorization'],_0xd00f('0x50'))){validateJwt(_0x518654,_0x790632,_0x810794);}else{if(_0x4e907e){_0x810794();}else{return _0x790632[_0xd00f('0x4d')](0x193)[_0xd00f('0x4e')]({'message':_0xd00f('0x51')});}}}else if(_0x518654[_0xd00f('0x40')][_0xd00f('0x52')]){try{var _0x5f07a9={'audience':hardwareConf[_0xd00f('0x53')](),'issuer':hardwareConf[_0xd00f('0x53')]()};verifyJwt(_0x518654[_0xd00f('0x40')][_0xd00f('0x52')],_0x5f07a9)[_0xd00f('0x3f')](function(_0x56c37d){return db[_0xd00f('0x54')]['find']({'where':{'id':_0x56c37d[_0xd00f('0x55')]}})[_0xd00f('0x3f')](function(_0x538a18){_0x1cf27c=_0x538a18;return db[_0xd00f('0x56')][_0xd00f('0x3b')]({'where':{'id':0x1},'attributes':[_0xd00f('0x57'),_0xd00f('0x58')],'raw':!![]});})[_0xd00f('0x3f')](function(_0x4e6eb2){if(!_0x1cf27c||!_[_0xd00f('0x59')](_0x1cf27c[_0xd00f('0x5a')],_0x56c37d['nonce'])){return _0x790632[_0xd00f('0x4d')](0x191)['json']({'message':_0xd00f('0x5b')});}if(_0x1cf27c[_0xd00f('0x5c')]){return _0x790632[_0xd00f('0x4d')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}if(_0x1cf27c[_0xd00f('0x5d')]){if(_0x4e6eb2['blockDuration']>0x0){if(moment(_0x1cf27c[_0xd00f('0x5e')])[_0xd00f('0x5f')](_0x4e6eb2[_0xd00f('0x58')],_0xd00f('0x60'))>moment()){return _0x790632[_0xd00f('0x4d')](0x191)['json']({'message':_0xd00f('0x61')});}}else{return _0x790632['status'](0x191)['json']({'message':_0xd00f('0x61')});}}_0x518654['user']={'id':_0x1cf27c['id']};_0x810794();});})[_0xd00f('0x45')](function(){return _0x790632['status'](0x191)[_0xd00f('0x4e')]({'message':_0xd00f('0x61')});});}catch(_0x349c69){_0x810794(_0x349c69);}}else if(_0x4e907e){_0x810794();}else{return _0x790632[_0xd00f('0x4d')](0x193)[_0xd00f('0x4e')]({'message':_0xd00f('0x51')});}})[_0xd00f('0x46')](function(_0x562e14,_0x47853e,_0x450ece){if(_0x562e14[_0xd00f('0x39')]){db['User']['find']({'where':{'id':_0x562e14['user']['id']},'attributes':userAttributes})['then'](function(_0x554248){if(!_0x554248){return _0x47853e[_0xd00f('0x4d')](0x194)[_0xd00f('0x4e')]({'message':_0xd00f('0x62')});}_0x562e14[_0xd00f('0x39')]=_0x554248;_0x450ece();})['catch'](function(_0x49114e){_0x450ece(_0x49114e);});}else if(_0x4e907e){_0x450ece();}else{return _0x47853e[_0xd00f('0x4d')](0x194)['json']({'message':'User\x20object\x20not\x20found.'});}});};exports[_0xd00f('0x63')]=function canUpdate(){return compose()[_0xd00f('0x46')](function(_0x35a855,_0x1e5744,_0x125acd){return licenseUtil[_0xd00f('0x64')]()[_0xd00f('0x3f')](function(_0x48b713){if(_0x48b713[_0xd00f('0x65')]){_0x125acd();}else{return _0x1e5744[_0xd00f('0x4d')](0x193)[_0xd00f('0x4e')]({'message':'Forbidden'});}})[_0xd00f('0x45')](function(_0x5259f2){_0x125acd(_0x5259f2);});});};exports[_0xd00f('0x66')]=function isWebrtcLicence(){return compose()['use'](function(_0x379226,_0x12a708,_0x162d4a){return licenseUtil[_0xd00f('0x64')]()['then'](function(_0x3e6709){if(_0x3e6709['webrtc']){_0x162d4a();}else{return _0x12a708[_0xd00f('0x4d')](0x193)[_0xd00f('0x4e')]({'message':_0xd00f('0x67')});}})[_0xd00f('0x45')](function(_0x4b5578){_0x162d4a(_0x4b5578);});});};exports[_0xd00f('0x68')]=function(_0x5d15dc,_0x560612,_0x273f4a){_0x5d15dc[_0xd00f('0x68')]=!![];return _0x273f4a();};exports[_0xd00f('0x69')]=function signToken(_0x59199d){return signJwt(_0x59199d);};exports[_0xd00f('0x6a')]=function(_0x5a4136,_0x467020){if(!_0x5a4136['user']){return _0x467020['status'](0x194)[_0xd00f('0x4e')]({'message':_0xd00f('0x6b')});}var _0x44e1ca={'payload':{'id':_0x5a4136[_0xd00f('0x39')]['id'],'role':_0x5a4136[_0xd00f('0x39')][_0xd00f('0xe')]},'options':{'expiresIn':0x15180}};return signJwt(_0x44e1ca)[_0xd00f('0x3f')](function(_0x32d3f3){_0x467020[_0xd00f('0x6c')](_0xd00f('0x6d'),_0x32d3f3);_0x467020[_0xd00f('0x6e')]('/dashboards/general');})['catch'](function(_0x503bea){return _0x467020[_0xd00f('0x4d')](0x1f4)['send'](_0x503bea);});};exports['retrieveApiKey']=function(_0x2c7090){if(_[_0xd00f('0x6f')](_0x2c7090['apiKeyNonce'])||_[_0xd00f('0x6f')](_0x2c7090[_0xd00f('0x70')])){return null;}else{return createJwt(_0x2c7090);}};exports[_0xd00f('0x71')]=function(_0x35dda2){_0x35dda2[_0xd00f('0x5a')]=generateNonce();_0x35dda2[_0xd00f('0x70')]=generateIssuedAt();return createJwt(_0x35dda2);};exports[_0xd00f('0x72')]=function(_0x277c33,_0x5eea81){var _0x522209=_0x277c33[_0xd00f('0x40')][_0xd00f('0x52')];if(_0x522209){var _0x45b005={'nonce':_0x5eea81[_0xd00f('0x5a')],'iat':_0x5eea81['apiKeyIat'],'audience':hardwareConf[_0xd00f('0x53')](),'issuer':hardwareConf[_0xd00f('0x53')]()};return verifyJwt(_0x522209,_0x45b005)['then'](function(){return generateApiKey(_0x5eea81);});}else{throw{'message':_0xd00f('0x73')};}};exports[_0xd00f('0x74')]=function(_0x5f2f47){var _0x50720e=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x50720e[_0xd00f('0x75')](_0x5f2f47))throw new db[(_0xd00f('0x76'))][(_0xd00f('0x77'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports['validatePasswordHistory']=function(_0x6ab13f,_0x37b350,_0x51b1a2){var _0x1fa151=encryptor['decryptString'](_0x37b350)[_0xd00f('0x78')](',');for(var _0x40a9fb=0x0;_0x40a9fb<_0x51b1a2;_0x40a9fb++){if(!_0x1fa151[_0x40a9fb])break;if(_0x6ab13f[_0xd00f('0x79')]()===_0x1fa151[_0x40a9fb][_0xd00f('0x79')]()){var _0x2435c6=util[_0xd00f('0x7a')](_0xd00f('0x7b'),_0x51b1a2);if(_0x51b1a2===0x1){_0x2435c6=_0xd00f('0x7c');}throw new db['Sequelize'][(_0xd00f('0x77'))](_0x2435c6);}}return;};exports[_0xd00f('0x7d')]=function(_0x3946c4,_0xd042f0){var _0x4918e9=_0xd042f0?encryptor[_0xd00f('0x7e')](_0xd042f0)[_0xd00f('0x78')](','):[];if(_0x4918e9[_0xd00f('0x7f')]===0x5){_0x4918e9['splice'](-0x1,0x1);}_0x4918e9[_0xd00f('0x80')](_0x3946c4);return encryptor[_0xd00f('0x81')](_0x4918e9[_0xd00f('0x82')](','));};function signJwt(_0x3ae2ae){var _0x373002=BPromise[_0xd00f('0x83')](jwt['sign'],{'context':jwt});var _0x5bacfc=_0x3ae2ae[_0xd00f('0x84')]||config[_0xd00f('0xc')][_0xd00f('0xd')];return new BPromise(function(_0x2266cd,_0x972dda){_0x373002(_0x3ae2ae['payload'],_0x5bacfc,_0x3ae2ae['options'])[_0xd00f('0x3f')](function(_0x4cd2bb){_0x2266cd(_0x4cd2bb);})['catch'](function(_0x2de46c){_0x972dda(_0x2de46c);});});}function verifyJwt(_0x2bc849,_0x3ee36e,_0x219ee2){var _0x1f1cab=BPromise[_0xd00f('0x83')](jwt[_0xd00f('0x85')],{'context':jwt});var _0x4ab331=_0x219ee2||config['secrets'][_0xd00f('0xd')];return new BPromise(function(_0x4f28f3,_0xfca31d){_0x1f1cab(_0x2bc849,_0x4ab331,_0x3ee36e)[_0xd00f('0x3f')](function(_0x17bd18){_0x4f28f3(_0x17bd18);})[_0xd00f('0x45')](function(_0x53caec){_0xfca31d(_0x53caec);});});}function generateNonce(){return crypto[_0xd00f('0x86')](0x10)[_0xd00f('0x87')](_0xd00f('0x88'));}function generateIssuedAt(){return Math[_0xd00f('0x89')](Date[_0xd00f('0x8a')]()/0x3e8)[_0xd00f('0x87')]();}function createJwt(_0x31ffa7){var _0x48e199={'payload':{'iat':_0x31ffa7[_0xd00f('0x70')],'nonce':_0x31ffa7[_0xd00f('0x5a')]},'options':{'algorithm':_0xd00f('0x8b'),'subject':_0x31ffa7['id']['toString'](),'issuer':hardwareConf[_0xd00f('0x53')](),'audience':hardwareConf[_0xd00f('0x53')]()}};return signJwt(_0x48e199)[_0xd00f('0x3f')](function(_0x5f0e27){return{'iat':_0x31ffa7[_0xd00f('0x70')],'nonce':_0x31ffa7[_0xd00f('0x5a')],'token':_0x5f0e27};});}