Built motion from commit 4ffc18b1.|2.6.31
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xcfa5=['authorization','startsWith','find','authenticate','status','Wrong\x20credentials.','Unknown\x20authorization\x20format','apikey','getUuid','sub','then','Setting','findOne','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','getLicense','update','isWebrtcLicence','webrtc','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','role','cookie','motion.token','/dashboards/general','send','isNil','apiKeyIat','generateApiKey','regenerateApiKey','validatePasswordPattern','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','ValidationError','length','encryptString','join','promisify','sign','secret','secrets','payload','options','randomBytes','toString','hex','floor','now','HS512','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','composable-middleware','crypto','bluebird','util','moment','session','fullname','name','email','userpic','permissions','md5secret','chatPause','mailPause','faxPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','downloadAttachments','ignorePauseForPreviewCalls','selectRecallMeCampaign','chatAutoanswer','chatAutoanswerDelay','emailAutoanswer','emailAutoanswerDelay','smsAutoanswer','openchannelAutoanswer','openchannelAutoanswerDelay','faxAutoanswer','faxAutoanswerDelay','whatsappAutoanswer','whatsappAutoanswerDelay','messengerSoundNotification','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','params','closed','query','forceDownload','disposition','json','unmanaged','Unmanaged.','catch','headers'];(function(_0x2bc77e,_0x33a4d8){var _0x554eb5=function(_0x1abe07){while(--_0x1abe07){_0x2bc77e['push'](_0x2bc77e['shift']());}};_0x554eb5(++_0x33a4d8);}(_0xcfa5,0xda));var _0x5cfa=function(_0x167cc1,_0x56ef5a){_0x167cc1=_0x167cc1-0x0;var _0x10bc4b=_0xcfa5[_0x167cc1];return _0x10bc4b;};'use strict';var db=require('../../mysqldb')['db'];var config=require(_0x5cfa('0x0'));var hardwareConf=require(_0x5cfa('0x1'));var licenseUtil=require(_0x5cfa('0x2'));var encryptor=require(_0x5cfa('0x3'));var _=require(_0x5cfa('0x4'));var jwt=require('jsonwebtoken');var expressJwt=require('express-jwt');var compose=require(_0x5cfa('0x5'));var basicAuth=require('basic-auth');var crypto=require(_0x5cfa('0x6'));var BPromise=require(_0x5cfa('0x7'));var util=require(_0x5cfa('0x8'));var moment=require(_0x5cfa('0x9'));var validateJwt=expressJwt({'secret':config['secrets'][_0x5cfa('0xa')]});var userAttributes=['id','role',_0x5cfa('0xb'),_0x5cfa('0xc'),'internal',_0x5cfa('0xd'),_0x5cfa('0xe'),_0x5cfa('0xf'),_0x5cfa('0x10'),'voicePause',_0x5cfa('0x11'),_0x5cfa('0x12'),_0x5cfa('0x13'),_0x5cfa('0x14'),_0x5cfa('0x15'),_0x5cfa('0x16'),_0x5cfa('0x17'),_0x5cfa('0x18'),'lastPauseAt',_0x5cfa('0x19'),_0x5cfa('0x1a'),_0x5cfa('0x1b'),_0x5cfa('0x1c'),_0x5cfa('0x1d'),_0x5cfa('0x1e'),'phoneBarDnd',_0x5cfa('0x1f'),_0x5cfa('0x20'),_0x5cfa('0x21'),'phoneBarExpires',_0x5cfa('0x22'),_0x5cfa('0x23'),_0x5cfa('0x24'),_0x5cfa('0x25'),_0x5cfa('0x26'),_0x5cfa('0x27'),_0x5cfa('0x28'),_0x5cfa('0x29'),'wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions',_0x5cfa('0x2a'),_0x5cfa('0x2b'),_0x5cfa('0x2c'),_0x5cfa('0x2d'),_0x5cfa('0x2e'),_0x5cfa('0x2f'),_0x5cfa('0x30'),_0x5cfa('0x31'),'smsAutoanswerDelay',_0x5cfa('0x32'),_0x5cfa('0x33'),_0x5cfa('0x34'),_0x5cfa('0x35'),_0x5cfa('0x36'),_0x5cfa('0x37'),_0x5cfa('0x38')];exports[_0x5cfa('0x39')]=function(){return this[_0x5cfa('0x3a')](!![])[_0x5cfa('0x3b')](function(_0xee04b3,_0x987cc4,_0x495750){if(_0xee04b3[_0x5cfa('0x3c')]){_0x495750();}else{return db[_0x5cfa('0x3d')]['findOne']({'where':{'id':_0xee04b3[_0x5cfa('0x3e')]['id']},'attributes':['id',_0x5cfa('0x3f'),'disposition'],'raw':!![]})['then'](function(_0x277aba){if(_0x277aba&&_0x277aba[_0x5cfa('0x3f')]&&!_0xee04b3[_0x5cfa('0x40')][_0x5cfa('0x41')]){return _0x987cc4['status'](_0x277aba[_0x5cfa('0x42')]==='unmanaged'?0x195:0x193)[_0x5cfa('0x43')]({'message':_0x277aba[_0x5cfa('0x42')]===_0x5cfa('0x44')?_0x5cfa('0x45'):'Forbidden.'});}else{_0x495750();}})[_0x5cfa('0x46')](function(_0x5e5e05){_0x495750(_0x5e5e05);});}});};exports[_0x5cfa('0x3a')]=function isAuthenticated(_0x4df2a2){return compose()[_0x5cfa('0x3b')](function(_0xd1f5c6,_0x5a962c,_0x390625){var _0x50941a;if(_0xd1f5c6[_0x5cfa('0x47')][_0x5cfa('0x48')]){if(_[_0x5cfa('0x49')](_0xd1f5c6[_0x5cfa('0x47')][_0x5cfa('0x48')],'Basic')){var _0x49fed1=basicAuth(_0xd1f5c6);db['User'][_0x5cfa('0x4a')]({'where':{'name':_0x49fed1['name']}})['then'](function(_0x4f307f){if(!_0x4f307f||!_0x4f307f[_0x5cfa('0x4b')](_0x49fed1['pass'])){return _0x5a962c[_0x5cfa('0x4c')](0x191)[_0x5cfa('0x43')]({'message':_0x5cfa('0x4d')});}_0xd1f5c6[_0x5cfa('0x3c')]={'id':_0x4f307f['id']};_0x390625();})[_0x5cfa('0x46')](function(_0x2c63bb){_0x390625(_0x2c63bb);});}else if(_['startsWith'](_0xd1f5c6[_0x5cfa('0x47')][_0x5cfa('0x48')],'Bearer')){validateJwt(_0xd1f5c6,_0x5a962c,_0x390625);}else{if(_0x4df2a2){_0x390625();}else{return _0x5a962c['status'](0x193)[_0x5cfa('0x43')]({'message':_0x5cfa('0x4e')});}}}else if(_0xd1f5c6['query'][_0x5cfa('0x4f')]){try{var _0x2b1514={'audience':hardwareConf[_0x5cfa('0x50')](),'issuer':hardwareConf[_0x5cfa('0x50')]()};verifyJwt(_0xd1f5c6['query'][_0x5cfa('0x4f')],_0x2b1514)['then'](function(_0x24404c){return db['User'][_0x5cfa('0x4a')]({'where':{'id':_0x24404c[_0x5cfa('0x51')]}})[_0x5cfa('0x52')](function(_0x149564){_0x50941a=_0x149564;return db[_0x5cfa('0x53')][_0x5cfa('0x54')]({'where':{'id':0x1},'attributes':[_0x5cfa('0x55'),_0x5cfa('0x56')],'raw':!![]});})[_0x5cfa('0x52')](function(_0x3712d0){if(!_0x50941a||!_[_0x5cfa('0x57')](_0x50941a[_0x5cfa('0x58')],_0x24404c[_0x5cfa('0x59')])){return _0x5a962c['status'](0x191)[_0x5cfa('0x43')]({'message':_0x5cfa('0x5a')});}if(_0x50941a[_0x5cfa('0x5b')]){return _0x5a962c[_0x5cfa('0x4c')](0x191)[_0x5cfa('0x43')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x50941a[_0x5cfa('0x5c')]){if(_0x3712d0[_0x5cfa('0x56')]>0x0){if(moment(_0x50941a[_0x5cfa('0x5d')])[_0x5cfa('0x5e')](_0x3712d0[_0x5cfa('0x56')],_0x5cfa('0x5f'))>moment()){return _0x5a962c['status'](0x191)[_0x5cfa('0x43')]({'message':_0x5cfa('0x60')});}}else{return _0x5a962c[_0x5cfa('0x4c')](0x191)[_0x5cfa('0x43')]({'message':_0x5cfa('0x60')});}}_0xd1f5c6['user']={'id':_0x50941a['id']};_0x390625();});})[_0x5cfa('0x46')](function(){return _0x5a962c[_0x5cfa('0x4c')](0x191)[_0x5cfa('0x43')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x4f9703){_0x390625(_0x4f9703);}}else if(_0x4df2a2){_0x390625();}else{return _0x5a962c[_0x5cfa('0x4c')](0x193)[_0x5cfa('0x43')]({'message':_0x5cfa('0x4e')});}})[_0x5cfa('0x3b')](function(_0x374624,_0x1cf6e2,_0x4b6c85){if(_0x374624[_0x5cfa('0x3c')]){db[_0x5cfa('0x61')][_0x5cfa('0x4a')]({'where':{'id':_0x374624[_0x5cfa('0x3c')]['id']},'attributes':userAttributes})['then'](function(_0x1b81d6){if(!_0x1b81d6){return _0x1cf6e2['status'](0x194)['json']({'message':_0x5cfa('0x62')});}_0x374624[_0x5cfa('0x3c')]=_0x1b81d6;_0x4b6c85();})[_0x5cfa('0x46')](function(_0x1d1047){_0x4b6c85(_0x1d1047);});}else if(_0x4df2a2){_0x4b6c85();}else{return _0x1cf6e2[_0x5cfa('0x4c')](0x194)['json']({'message':_0x5cfa('0x63')});}});};exports[_0x5cfa('0x64')]=function canUpdate(){return compose()[_0x5cfa('0x3b')](function(_0x49eaca,_0x2ffc21,_0x4bbfa9){return licenseUtil[_0x5cfa('0x65')]()[_0x5cfa('0x52')](function(_0x565932){if(_0x565932[_0x5cfa('0x66')]){_0x4bbfa9();}else{return _0x2ffc21[_0x5cfa('0x4c')](0x193)[_0x5cfa('0x43')]({'message':'Forbidden'});}})[_0x5cfa('0x46')](function(_0x634a8e){_0x4bbfa9(_0x634a8e);});});};exports[_0x5cfa('0x67')]=function isWebrtcLicence(){return compose()[_0x5cfa('0x3b')](function(_0x333243,_0x4daa6c,_0x13c687){return licenseUtil['getLicense']()['then'](function(_0x1501d8){if(_0x1501d8[_0x5cfa('0x68')]){_0x13c687();}else{return _0x4daa6c['status'](0x193)[_0x5cfa('0x43')]({'message':_0x5cfa('0x69')});}})[_0x5cfa('0x46')](function(_0x3c3fdb){_0x13c687(_0x3c3fdb);});});};exports[_0x5cfa('0x6a')]=function(_0x30e028,_0x61807b,_0x26864c){_0x30e028[_0x5cfa('0x6a')]=!![];return _0x26864c();};exports[_0x5cfa('0x6b')]=function signToken(_0x10c8bd){return signJwt(_0x10c8bd);};exports[_0x5cfa('0x6c')]=function(_0x4c977d,_0x193733){if(!_0x4c977d[_0x5cfa('0x3c')]){return _0x193733[_0x5cfa('0x4c')](0x194)[_0x5cfa('0x43')]({'message':_0x5cfa('0x6d')});}var _0x10fee7={'payload':{'id':_0x4c977d[_0x5cfa('0x3c')]['id'],'role':_0x4c977d[_0x5cfa('0x3c')][_0x5cfa('0x6e')]},'options':{'expiresIn':0x15180}};return signJwt(_0x10fee7)[_0x5cfa('0x52')](function(_0x126601){_0x193733[_0x5cfa('0x6f')](_0x5cfa('0x70'),_0x126601);_0x193733['redirect'](_0x5cfa('0x71'));})[_0x5cfa('0x46')](function(_0xbe080b){return _0x193733[_0x5cfa('0x4c')](0x1f4)[_0x5cfa('0x72')](_0xbe080b);});};exports['retrieveApiKey']=function(_0x257ba0){if(_[_0x5cfa('0x73')](_0x257ba0[_0x5cfa('0x58')])||_['isNil'](_0x257ba0[_0x5cfa('0x74')])){return null;}else{return createJwt(_0x257ba0);}};exports[_0x5cfa('0x75')]=function(_0x4a2d41){_0x4a2d41[_0x5cfa('0x58')]=generateNonce();_0x4a2d41[_0x5cfa('0x74')]=generateIssuedAt();return createJwt(_0x4a2d41);};exports[_0x5cfa('0x76')]=function(_0x44eb73,_0x444d7e){var _0x363122=_0x44eb73['query'][_0x5cfa('0x4f')];if(_0x363122){var _0x491628={'nonce':_0x444d7e[_0x5cfa('0x58')],'iat':_0x444d7e[_0x5cfa('0x74')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x5cfa('0x50')]()};return verifyJwt(_0x363122,_0x491628)[_0x5cfa('0x52')](function(){return generateApiKey(_0x444d7e);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0x5cfa('0x77')]=function(_0xb8a484){var _0x29a76b=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x29a76b[_0x5cfa('0x78')](_0xb8a484))throw new db[(_0x5cfa('0x79'))]['ValidationError'](_0x5cfa('0x7a'));return;};exports[_0x5cfa('0x7b')]=function(_0x55391a,_0x2c813f,_0x457733){var _0x3c5342=encryptor[_0x5cfa('0x7c')](_0x2c813f)[_0x5cfa('0x7d')](',');for(var _0x328727=0x0;_0x328727<_0x457733;_0x328727++){if(!_0x3c5342[_0x328727])break;if(_0x55391a[_0x5cfa('0x7e')]()===_0x3c5342[_0x328727]['toLowerCase']()){var _0x4558bd=util[_0x5cfa('0x7f')](_0x5cfa('0x80'),_0x457733);if(_0x457733===0x1){_0x4558bd='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x5cfa('0x79'))][(_0x5cfa('0x81'))](_0x4558bd);}}return;};exports['updatePasswordsHistory']=function(_0x3a3a0b,_0x449c43){var _0x2f0e3a=_0x449c43?encryptor[_0x5cfa('0x7c')](_0x449c43)[_0x5cfa('0x7d')](','):[];if(_0x2f0e3a[_0x5cfa('0x82')]===0x5){_0x2f0e3a['splice'](-0x1,0x1);}_0x2f0e3a['unshift'](_0x3a3a0b);return encryptor[_0x5cfa('0x83')](_0x2f0e3a[_0x5cfa('0x84')](','));};function signJwt(_0x524424){var _0x4b719c=BPromise[_0x5cfa('0x85')](jwt[_0x5cfa('0x86')],{'context':jwt});var _0x48ef34=_0x524424[_0x5cfa('0x87')]||config[_0x5cfa('0x88')][_0x5cfa('0xa')];return new BPromise(function(_0x2dd751,_0x46ed33){_0x4b719c(_0x524424[_0x5cfa('0x89')],_0x48ef34,_0x524424[_0x5cfa('0x8a')])['then'](function(_0x290ef3){_0x2dd751(_0x290ef3);})[_0x5cfa('0x46')](function(_0x3df447){_0x46ed33(_0x3df447);});});}function verifyJwt(_0x45240c,_0xa11097,_0x486527){var _0x71a2cd=BPromise[_0x5cfa('0x85')](jwt['verify'],{'context':jwt});var _0x557fdd=_0x486527||config['secrets'][_0x5cfa('0xa')];return new BPromise(function(_0x1fc844,_0x1a19ee){_0x71a2cd(_0x45240c,_0x557fdd,_0xa11097)[_0x5cfa('0x52')](function(_0x33c7e3){_0x1fc844(_0x33c7e3);})[_0x5cfa('0x46')](function(_0x50855b){_0x1a19ee(_0x50855b);});});}function generateNonce(){return crypto[_0x5cfa('0x8b')](0x10)[_0x5cfa('0x8c')](_0x5cfa('0x8d'));}function generateIssuedAt(){return Math[_0x5cfa('0x8e')](Date[_0x5cfa('0x8f')]()/0x3e8)[_0x5cfa('0x8c')]();}function createJwt(_0x15a54d){var _0x28c239={'payload':{'iat':_0x15a54d[_0x5cfa('0x74')],'nonce':_0x15a54d[_0x5cfa('0x58')]},'options':{'algorithm':_0x5cfa('0x90'),'subject':_0x15a54d['id'][_0x5cfa('0x8c')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x5cfa('0x50')]()}};return signJwt(_0x28c239)[_0x5cfa('0x52')](function(_0x29eefe){return{'iat':_0x15a54d['apiKeyIat'],'nonce':_0x15a54d['apiKeyNonce'],'token':_0x29eefe};});}