ae4d2b3aea41b8f22480bc7c626c3553514ab495
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x9be4=['secret','secrets','payload','options','verify','toString','hex','now','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','lodash','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util','session','role','name','userpic','permissions','md5secret','faxPause','smsPause','openchannelPause','lastLoginAt','crudPermissions','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','user','params','disposition','then','closed','status','unmanaged','json','Unmanaged.','Forbidden.','catch','headers','authorization','startsWith','Basic','User','pass','Bearer','apikey','getUuid','query','find','isEqual','Unknown\x20authorization\x20format','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','motion.token','/dashboards/general','send','retrieveApiKey','isNil','apiKeyNonce','apiKeyIat','generateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','Sequelize','ValidationError','validatePasswordHistory','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','split','length','encryptString','join','promisify','sign'];(function(_0x4d613c,_0x55f220){var _0x301fe3=function(_0x5eec0b){while(--_0x5eec0b){_0x4d613c['push'](_0x4d613c['shift']());}};_0x301fe3(++_0x55f220);}(_0x9be4,0x147));var _0x49be=function(_0x41693d,_0x56c364){_0x41693d=_0x41693d-0x0;var _0x591802=_0x9be4[_0x41693d];return _0x591802;};'use strict';var db=require(_0x49be('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x49be('0x1'));var licenseUtil=require(_0x49be('0x2'));var encryptor=require(_0x49be('0x3'));var _=require(_0x49be('0x4'));var jwt=require('jsonwebtoken');var expressJwt=require(_0x49be('0x5'));var compose=require(_0x49be('0x6'));var basicAuth=require(_0x49be('0x7'));var crypto=require(_0x49be('0x8'));var BPromise=require(_0x49be('0x9'));var util=require(_0x49be('0xa'));var validateJwt=expressJwt({'secret':config['secrets'][_0x49be('0xb')]});var userAttributes=['id',_0x49be('0xc'),'fullname',_0x49be('0xd'),'internal','email',_0x49be('0xe'),_0x49be('0xf'),_0x49be('0x10'),'voicePause','chatPause','mailPause',_0x49be('0x11'),_0x49be('0x12'),_0x49be('0x13'),'pauseType','showWebBar',_0x49be('0x14'),'lastPauseAt',_0x49be('0x15'),'allowmessenger','passwordResetAt',_0x49be('0x16'),_0x49be('0x17'),_0x49be('0x18'),_0x49be('0x19'),_0x49be('0x1a'),_0x49be('0x1b'),_0x49be('0x1c'),_0x49be('0x1d'),_0x49be('0x1e'),_0x49be('0x1f'),_0x49be('0x20'),_0x49be('0x21'),_0x49be('0x22'),_0x49be('0x23'),_0x49be('0x24')];exports[_0x49be('0x25')]=function(){return this[_0x49be('0x26')](!![])[_0x49be('0x27')](function(_0x9aa859,_0x55f24b,_0x23e426){if(_0x9aa859[_0x49be('0x28')]){_0x23e426();}else{return db['ChatInteraction']['findOne']({'where':{'id':_0x9aa859[_0x49be('0x29')]['id']},'attributes':['id','closed',_0x49be('0x2a')],'raw':!![]})[_0x49be('0x2b')](function(_0x180025){if(_0x180025&&_0x180025[_0x49be('0x2c')]){return _0x55f24b[_0x49be('0x2d')](_0x180025[_0x49be('0x2a')]===_0x49be('0x2e')?0x195:0x193)[_0x49be('0x2f')]({'message':_0x180025[_0x49be('0x2a')]===_0x49be('0x2e')?_0x49be('0x30'):_0x49be('0x31')});}else{_0x23e426();}})[_0x49be('0x32')](function(_0x563f84){_0x23e426(_0x563f84);});}});};exports[_0x49be('0x26')]=function isAuthenticated(_0x18c158){return compose()[_0x49be('0x27')](function(_0x3c8b33,_0xf9bc06,_0x346181){if(_0x3c8b33[_0x49be('0x33')][_0x49be('0x34')]){if(_[_0x49be('0x35')](_0x3c8b33['headers'][_0x49be('0x34')],_0x49be('0x36'))){var _0x370f4a=basicAuth(_0x3c8b33);db[_0x49be('0x37')]['find']({'where':{'name':_0x370f4a[_0x49be('0xd')]}})[_0x49be('0x2b')](function(_0x26e1f5){if(!_0x26e1f5||!_0x26e1f5['authenticate'](_0x370f4a[_0x49be('0x38')])){return _0xf9bc06['status'](0x191)[_0x49be('0x2f')]({'message':'Wrong\x20credentials.'});}_0x3c8b33[_0x49be('0x28')]={'id':_0x26e1f5['id']};_0x346181();})['catch'](function(_0x4cb1a1){_0x346181(_0x4cb1a1);});}else if(_[_0x49be('0x35')](_0x3c8b33[_0x49be('0x33')]['authorization'],_0x49be('0x39'))){validateJwt(_0x3c8b33,_0xf9bc06,_0x346181);}else{if(_0x18c158){_0x346181();}else{return _0xf9bc06['status'](0x193)[_0x49be('0x2f')]({'message':'Unknown\x20authorization\x20format'});}}}else if(_0x3c8b33['query'][_0x49be('0x3a')]){try{var _0x42c9ab={'audience':hardwareConf[_0x49be('0x3b')](),'issuer':hardwareConf[_0x49be('0x3b')]()};verifyJwt(_0x3c8b33[_0x49be('0x3c')][_0x49be('0x3a')],_0x42c9ab)['then'](function(_0x330bf5){return db[_0x49be('0x37')][_0x49be('0x3d')]({'where':{'id':_0x330bf5['sub']}})[_0x49be('0x2b')](function(_0x2c5835){if(!_0x2c5835||!_[_0x49be('0x3e')](_0x2c5835['apiKeyNonce'],_0x330bf5['nonce'])){return _0xf9bc06[_0x49be('0x2d')](0x191)[_0x49be('0x2f')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}_0x3c8b33['user']={'id':_0x2c5835['id']};_0x346181();});})[_0x49be('0x32')](function(){return _0xf9bc06[_0x49be('0x2d')](0x191)[_0x49be('0x2f')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0xa3c809){_0x346181(_0xa3c809);}}else if(_0x18c158){_0x346181();}else{return _0xf9bc06['status'](0x193)[_0x49be('0x2f')]({'message':_0x49be('0x3f')});}})[_0x49be('0x27')](function(_0x48c7ca,_0x5e359b,_0x1d43a7){if(_0x48c7ca[_0x49be('0x28')]){db[_0x49be('0x37')][_0x49be('0x3d')]({'where':{'id':_0x48c7ca[_0x49be('0x28')]['id']},'attributes':userAttributes})['then'](function(_0x11b9fe){if(!_0x11b9fe){return _0x5e359b[_0x49be('0x2d')](0x194)[_0x49be('0x2f')]({'message':_0x49be('0x40')});}_0x48c7ca['user']=_0x11b9fe;_0x1d43a7();})['catch'](function(_0x5d97c2){_0x1d43a7(_0x5d97c2);});}else if(_0x18c158){_0x1d43a7();}else{return _0x5e359b[_0x49be('0x2d')](0x194)[_0x49be('0x2f')]({'message':_0x49be('0x41')});}});};exports[_0x49be('0x42')]=function canUpdate(){return compose()['use'](function(_0x47ece5,_0x34deb0,_0x1532ae){return licenseUtil[_0x49be('0x43')]()[_0x49be('0x2b')](function(_0x4c3c7f){if(_0x4c3c7f[_0x49be('0x44')]){_0x1532ae();}else{return _0x34deb0[_0x49be('0x2d')](0x193)[_0x49be('0x2f')]({'message':_0x49be('0x45')});}})[_0x49be('0x32')](function(_0x390112){_0x1532ae(_0x390112);});});};exports[_0x49be('0x46')]=function(_0x268b6d,_0x5b0af7,_0x28c1c1){_0x268b6d[_0x49be('0x46')]=!![];return _0x28c1c1();};exports[_0x49be('0x47')]=function signToken(_0x4feaeb){return signJwt(_0x4feaeb);};exports[_0x49be('0x48')]=function(_0x5041d2,_0x63d227){if(!_0x5041d2['user']){return _0x63d227[_0x49be('0x2d')](0x194)[_0x49be('0x2f')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x285a80={'payload':{'id':_0x5041d2[_0x49be('0x28')]['id'],'role':_0x5041d2[_0x49be('0x28')][_0x49be('0xc')]},'options':{'expiresIn':0x15180}};return signJwt(_0x285a80)[_0x49be('0x2b')](function(_0x148af2){_0x63d227['cookie'](_0x49be('0x49'),_0x148af2);_0x63d227['redirect'](_0x49be('0x4a'));})[_0x49be('0x32')](function(_0x13a0b3){return _0x63d227[_0x49be('0x2d')](0x1f4)[_0x49be('0x4b')](_0x13a0b3);});};exports[_0x49be('0x4c')]=function(_0x1b3fa6){if(_[_0x49be('0x4d')](_0x1b3fa6[_0x49be('0x4e')])||_[_0x49be('0x4d')](_0x1b3fa6[_0x49be('0x4f')])){return null;}else{return createJwt(_0x1b3fa6);}};exports[_0x49be('0x50')]=function(_0x5a523b){_0x5a523b['apiKeyNonce']=generateNonce();_0x5a523b[_0x49be('0x4f')]=generateIssuedAt();return createJwt(_0x5a523b);};exports['regenerateApiKey']=function(_0x45d0b4,_0x43664b){var _0x55d245=_0x45d0b4['query']['apikey'];if(_0x55d245){var _0x12839f={'nonce':_0x43664b[_0x49be('0x4e')],'iat':_0x43664b[_0x49be('0x4f')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x49be('0x3b')]()};return verifyJwt(_0x55d245,_0x12839f)[_0x49be('0x2b')](function(){return generateApiKey(_0x43664b);});}else{throw{'message':_0x49be('0x51')};}};exports[_0x49be('0x52')]=function(_0x13bab0){var _0x93bbc3=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x93bbc3['test'](_0x13bab0))throw new db[(_0x49be('0x53'))][(_0x49be('0x54'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x49be('0x55')]=function(_0x4c7a89,_0x3f6831,_0x10640a){var _0x27cc70=encryptor[_0x49be('0x56')](_0x3f6831)['split'](',');for(var _0x4be476=0x0;_0x4be476<_0x10640a;_0x4be476++){if(!_0x27cc70[_0x4be476])break;if(_0x4c7a89[_0x49be('0x57')]()===_0x27cc70[_0x4be476]['toLowerCase']()){var _0x48ddd7=util[_0x49be('0x58')](_0x49be('0x59'),_0x10640a);if(_0x10640a===0x1){_0x48ddd7='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db['Sequelize']['ValidationError'](_0x48ddd7);}}return;};exports[_0x49be('0x5a')]=function(_0x3bb2a2,_0xb7d780){var _0x3e79d2=_0xb7d780?encryptor[_0x49be('0x56')](_0xb7d780)[_0x49be('0x5b')](','):[];if(_0x3e79d2[_0x49be('0x5c')]===0x5){_0x3e79d2['splice'](-0x1,0x1);}_0x3e79d2['unshift'](_0x3bb2a2);return encryptor[_0x49be('0x5d')](_0x3e79d2[_0x49be('0x5e')](','));};function signJwt(_0x2601ce){var _0x3a7c85=BPromise[_0x49be('0x5f')](jwt[_0x49be('0x60')],{'context':jwt});var _0x143df3=_0x2601ce[_0x49be('0x61')]||config[_0x49be('0x62')][_0x49be('0xb')];return new BPromise(function(_0x405347,_0x25716a){_0x3a7c85(_0x2601ce[_0x49be('0x63')],_0x143df3,_0x2601ce[_0x49be('0x64')])['then'](function(_0x5571a6){_0x405347(_0x5571a6);})[_0x49be('0x32')](function(_0x32e63f){_0x25716a(_0x32e63f);});});}function verifyJwt(_0x9e7526,_0x42dd05,_0x84083c){var _0x26c3bb=BPromise['promisify'](jwt[_0x49be('0x65')],{'context':jwt});var _0x5863fd=_0x84083c||config[_0x49be('0x62')][_0x49be('0xb')];return new BPromise(function(_0x208a7a,_0x48c111){_0x26c3bb(_0x9e7526,_0x5863fd,_0x42dd05)[_0x49be('0x2b')](function(_0x308ed4){_0x208a7a(_0x308ed4);})['catch'](function(_0x56337c){_0x48c111(_0x56337c);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0x49be('0x66')](_0x49be('0x67'));}function generateIssuedAt(){return Math['floor'](Date[_0x49be('0x68')]()/0x3e8)[_0x49be('0x66')]();}function createJwt(_0x50801e){var _0x59c254={'payload':{'iat':_0x50801e['apiKeyIat'],'nonce':_0x50801e['apiKeyNonce']},'options':{'algorithm':_0x49be('0x69'),'subject':_0x50801e['id'][_0x49be('0x66')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x49be('0x3b')]()}};return signJwt(_0x59c254)[_0x49be('0x2b')](function(_0x429fc8){return{'iat':_0x50801e['apiKeyIat'],'nonce':_0x50801e[_0x49be('0x4e')],'token':_0x429fc8};});}