c623145964a256d5639e384992970932326f5f4d
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xf970=['../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','crypto','bluebird','util','moment','secrets','session','role','fullname','name','userpic','md5secret','voicePause','chatPause','faxPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','userProfileId','privacyEnabled','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','then','status','disposition','unmanaged','json','Unmanaged.','Forbidden.','headers','authorization','Basic','User','find','authenticate','pass','Wrong\x20credentials.','catch','startsWith','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','Setting','allowedLoginAttempts','isEqual','apiKeyNonce','nonce','blocked','blockDuration','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','getLicense','Forbidden','isMiddleware','signToken','setTokenCookie','cookie','motion.token','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','promisify','payload','options','verify','randomBytes','hex','floor','now','toString','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util'];(function(_0x45d1fd,_0x463212){var _0xd0e542=function(_0x23ebc9){while(--_0x23ebc9){_0x45d1fd['push'](_0x45d1fd['shift']());}};_0xd0e542(++_0x463212);}(_0xf970,0x1d9));var _0x0f97=function(_0x3dd15e,_0x1f0015){_0x3dd15e=_0x3dd15e-0x0;var _0x231fd0=_0xf970[_0x3dd15e];return _0x231fd0;};'use strict';var db=require(_0x0f97('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x0f97('0x1'));var licenseUtil=require(_0x0f97('0x2'));var encryptor=require(_0x0f97('0x3'));var _=require(_0x0f97('0x4'));var jwt=require(_0x0f97('0x5'));var expressJwt=require(_0x0f97('0x6'));var compose=require(_0x0f97('0x7'));var basicAuth=require('basic-auth');var crypto=require(_0x0f97('0x8'));var BPromise=require(_0x0f97('0x9'));var util=require(_0x0f97('0xa'));var moment=require(_0x0f97('0xb'));var validateJwt=expressJwt({'secret':config[_0x0f97('0xc')][_0x0f97('0xd')]});var userAttributes=['id',_0x0f97('0xe'),_0x0f97('0xf'),_0x0f97('0x10'),'internal','email',_0x0f97('0x11'),'permissions',_0x0f97('0x12'),_0x0f97('0x13'),_0x0f97('0x14'),'mailPause',_0x0f97('0x15'),'smsPause',_0x0f97('0x16'),_0x0f97('0x17'),_0x0f97('0x18'),_0x0f97('0x19'),_0x0f97('0x1a'),'crudPermissions',_0x0f97('0x1b'),_0x0f97('0x1c'),_0x0f97('0x1d'),_0x0f97('0x1e'),_0x0f97('0x1f'),_0x0f97('0x20'),_0x0f97('0x21'),'phoneBarEnableDtmfTone','phoneBarEnableSettings',_0x0f97('0x22'),_0x0f97('0x23'),_0x0f97('0x24'),_0x0f97('0x25'),'hotdesk','interface',_0x0f97('0x26'),_0x0f97('0x27'),_0x0f97('0x28')];exports[_0x0f97('0x29')]=function(){return this[_0x0f97('0x2a')](!![])[_0x0f97('0x2b')](function(_0x5059ad,_0x54717b,_0x35a341){if(_0x5059ad[_0x0f97('0x2c')]){_0x35a341();}else{return db[_0x0f97('0x2d')][_0x0f97('0x2e')]({'where':{'id':_0x5059ad[_0x0f97('0x2f')]['id']},'attributes':['id',_0x0f97('0x30'),'disposition'],'raw':!![]})[_0x0f97('0x31')](function(_0x15a1ef){if(_0x15a1ef&&_0x15a1ef[_0x0f97('0x30')]){return _0x54717b[_0x0f97('0x32')](_0x15a1ef[_0x0f97('0x33')]===_0x0f97('0x34')?0x195:0x193)[_0x0f97('0x35')]({'message':_0x15a1ef['disposition']===_0x0f97('0x34')?_0x0f97('0x36'):_0x0f97('0x37')});}else{_0x35a341();}})['catch'](function(_0x31d384){_0x35a341(_0x31d384);});}});};exports[_0x0f97('0x2a')]=function isAuthenticated(_0x4ec6d0){return compose()[_0x0f97('0x2b')](function(_0x15df5c,_0x4ef5bc,_0x489e1e){var _0x51aa82;if(_0x15df5c[_0x0f97('0x38')][_0x0f97('0x39')]){if(_['startsWith'](_0x15df5c[_0x0f97('0x38')][_0x0f97('0x39')],_0x0f97('0x3a'))){var _0x30d33d=basicAuth(_0x15df5c);db[_0x0f97('0x3b')][_0x0f97('0x3c')]({'where':{'name':_0x30d33d[_0x0f97('0x10')]}})[_0x0f97('0x31')](function(_0x1e688d){if(!_0x1e688d||!_0x1e688d[_0x0f97('0x3d')](_0x30d33d[_0x0f97('0x3e')])){return _0x4ef5bc['status'](0x191)[_0x0f97('0x35')]({'message':_0x0f97('0x3f')});}_0x15df5c[_0x0f97('0x2c')]={'id':_0x1e688d['id']};_0x489e1e();})[_0x0f97('0x40')](function(_0xc2ed81){_0x489e1e(_0xc2ed81);});}else if(_[_0x0f97('0x41')](_0x15df5c[_0x0f97('0x38')][_0x0f97('0x39')],'Bearer')){validateJwt(_0x15df5c,_0x4ef5bc,_0x489e1e);}else{if(_0x4ec6d0){_0x489e1e();}else{return _0x4ef5bc['status'](0x193)[_0x0f97('0x35')]({'message':_0x0f97('0x42')});}}}else if(_0x15df5c[_0x0f97('0x43')][_0x0f97('0x44')]){try{var _0x25bd0e={'audience':hardwareConf[_0x0f97('0x45')](),'issuer':hardwareConf[_0x0f97('0x45')]()};verifyJwt(_0x15df5c[_0x0f97('0x43')][_0x0f97('0x44')],_0x25bd0e)[_0x0f97('0x31')](function(_0x4107ac){return db['User'][_0x0f97('0x3c')]({'where':{'id':_0x4107ac[_0x0f97('0x46')]}})[_0x0f97('0x31')](function(_0x416495){_0x51aa82=_0x416495;return db[_0x0f97('0x47')]['findOne']({'where':{'id':0x1},'attributes':[_0x0f97('0x48'),'blockDuration'],'raw':!![]});})[_0x0f97('0x31')](function(_0x5dc775){if(!_0x51aa82||!_[_0x0f97('0x49')](_0x51aa82[_0x0f97('0x4a')],_0x4107ac[_0x0f97('0x4b')])){return _0x4ef5bc[_0x0f97('0x32')](0x191)[_0x0f97('0x35')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x51aa82['disabled']){return _0x4ef5bc[_0x0f97('0x32')](0x191)[_0x0f97('0x35')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x51aa82[_0x0f97('0x4c')]){if(_0x5dc775[_0x0f97('0x4d')]>0x0){if(moment(_0x51aa82[_0x0f97('0x4e')])[_0x0f97('0x4f')](_0x5dc775['blockDuration'],_0x0f97('0x50'))>moment()){return _0x4ef5bc[_0x0f97('0x32')](0x191)[_0x0f97('0x35')]({'message':_0x0f97('0x51')});}}else{return _0x4ef5bc[_0x0f97('0x32')](0x191)['json']({'message':_0x0f97('0x51')});}}_0x15df5c[_0x0f97('0x2c')]={'id':_0x51aa82['id']};_0x489e1e();});})[_0x0f97('0x40')](function(){return _0x4ef5bc[_0x0f97('0x32')](0x191)[_0x0f97('0x35')]({'message':_0x0f97('0x51')});});}catch(_0x50be3d){_0x489e1e(_0x50be3d);}}else if(_0x4ec6d0){_0x489e1e();}else{return _0x4ef5bc['status'](0x193)[_0x0f97('0x35')]({'message':_0x0f97('0x42')});}})[_0x0f97('0x2b')](function(_0x570700,_0x19b24e,_0xb24a15){if(_0x570700[_0x0f97('0x2c')]){db['User'][_0x0f97('0x3c')]({'where':{'id':_0x570700[_0x0f97('0x2c')]['id']},'attributes':userAttributes})[_0x0f97('0x31')](function(_0x679aea){if(!_0x679aea){return _0x19b24e[_0x0f97('0x32')](0x194)[_0x0f97('0x35')]({'message':_0x0f97('0x52')});}_0x570700[_0x0f97('0x2c')]=_0x679aea;_0xb24a15();})[_0x0f97('0x40')](function(_0x79aa92){_0xb24a15(_0x79aa92);});}else if(_0x4ec6d0){_0xb24a15();}else{return _0x19b24e[_0x0f97('0x32')](0x194)['json']({'message':_0x0f97('0x53')});}});};exports[_0x0f97('0x54')]=function canUpdate(){return compose()['use'](function(_0x299566,_0x57269c,_0x153777){return licenseUtil[_0x0f97('0x55')]()[_0x0f97('0x31')](function(_0x5934b1){if(_0x5934b1['update']){_0x153777();}else{return _0x57269c[_0x0f97('0x32')](0x193)[_0x0f97('0x35')]({'message':_0x0f97('0x56')});}})[_0x0f97('0x40')](function(_0x278a8c){_0x153777(_0x278a8c);});});};exports['isMiddleware']=function(_0x5962a4,_0x5c5e86,_0x401286){_0x5962a4[_0x0f97('0x57')]=!![];return _0x401286();};exports[_0x0f97('0x58')]=function signToken(_0x2a5f07){return signJwt(_0x2a5f07);};exports[_0x0f97('0x59')]=function(_0x2b19a9,_0xd9f44b){if(!_0x2b19a9[_0x0f97('0x2c')]){return _0xd9f44b['status'](0x194)[_0x0f97('0x35')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x16ef4d={'payload':{'id':_0x2b19a9[_0x0f97('0x2c')]['id'],'role':_0x2b19a9[_0x0f97('0x2c')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x16ef4d)['then'](function(_0x3bbdbc){_0xd9f44b[_0x0f97('0x5a')](_0x0f97('0x5b'),_0x3bbdbc);_0xd9f44b['redirect']('/dashboards/general');})['catch'](function(_0xa32a1d){return _0xd9f44b[_0x0f97('0x32')](0x1f4)[_0x0f97('0x5c')](_0xa32a1d);});};exports[_0x0f97('0x5d')]=function(_0x13e08c){if(_[_0x0f97('0x5e')](_0x13e08c[_0x0f97('0x4a')])||_[_0x0f97('0x5e')](_0x13e08c[_0x0f97('0x5f')])){return null;}else{return createJwt(_0x13e08c);}};exports[_0x0f97('0x60')]=function(_0x55eba){_0x55eba['apiKeyNonce']=generateNonce();_0x55eba[_0x0f97('0x5f')]=generateIssuedAt();return createJwt(_0x55eba);};exports['regenerateApiKey']=function(_0x5480e1,_0x408c5f){var _0x5d0fec=_0x5480e1[_0x0f97('0x43')][_0x0f97('0x44')];if(_0x5d0fec){var _0x31929a={'nonce':_0x408c5f[_0x0f97('0x4a')],'iat':_0x408c5f[_0x0f97('0x5f')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf['getUuid']()};return verifyJwt(_0x5d0fec,_0x31929a)[_0x0f97('0x31')](function(){return generateApiKey(_0x408c5f);});}else{throw{'message':_0x0f97('0x61')};}};exports['validatePasswordPattern']=function(_0x1a5d99){var _0x2a29ff=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x2a29ff[_0x0f97('0x62')](_0x1a5d99))throw new db[(_0x0f97('0x63'))]['ValidationError'](_0x0f97('0x64'));return;};exports[_0x0f97('0x65')]=function(_0x376880,_0xcf9bfc,_0x185238){var _0x2a30b1=encryptor[_0x0f97('0x66')](_0xcf9bfc)[_0x0f97('0x67')](',');for(var _0x2c8a73=0x0;_0x2c8a73<_0x185238;_0x2c8a73++){if(!_0x2a30b1[_0x2c8a73])break;if(_0x376880[_0x0f97('0x68')]()===_0x2a30b1[_0x2c8a73][_0x0f97('0x68')]()){var _0x736610=util[_0x0f97('0x69')](_0x0f97('0x6a'),_0x185238);if(_0x185238===0x1){_0x736610='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x0f97('0x63'))]['ValidationError'](_0x736610);}}return;};exports[_0x0f97('0x6b')]=function(_0x21ae61,_0x19484d){var _0x5716c5=_0x19484d?encryptor[_0x0f97('0x66')](_0x19484d)[_0x0f97('0x67')](','):[];if(_0x5716c5[_0x0f97('0x6c')]===0x5){_0x5716c5['splice'](-0x1,0x1);}_0x5716c5['unshift'](_0x21ae61);return encryptor['encryptString'](_0x5716c5['join'](','));};function signJwt(_0x375285){var _0x6f08c1=BPromise[_0x0f97('0x6d')](jwt['sign'],{'context':jwt});var _0x3e4a26=_0x375285['secret']||config[_0x0f97('0xc')][_0x0f97('0xd')];return new BPromise(function(_0x20890c,_0x8410d8){_0x6f08c1(_0x375285[_0x0f97('0x6e')],_0x3e4a26,_0x375285[_0x0f97('0x6f')])[_0x0f97('0x31')](function(_0x10a44f){_0x20890c(_0x10a44f);})[_0x0f97('0x40')](function(_0x59a646){_0x8410d8(_0x59a646);});});}function verifyJwt(_0x2e2103,_0xbd80c1,_0x406210){var _0x9c4705=BPromise[_0x0f97('0x6d')](jwt[_0x0f97('0x70')],{'context':jwt});var _0x47d67=_0x406210||config[_0x0f97('0xc')]['session'];return new BPromise(function(_0x40b7d6,_0xddbd8d){_0x9c4705(_0x2e2103,_0x47d67,_0xbd80c1)['then'](function(_0x35d089){_0x40b7d6(_0x35d089);})[_0x0f97('0x40')](function(_0xc744ed){_0xddbd8d(_0xc744ed);});});}function generateNonce(){return crypto[_0x0f97('0x71')](0x10)['toString'](_0x0f97('0x72'));}function generateIssuedAt(){return Math[_0x0f97('0x73')](Date[_0x0f97('0x74')]()/0x3e8)[_0x0f97('0x75')]();}function createJwt(_0x320b96){var _0x27d98c={'payload':{'iat':_0x320b96[_0x0f97('0x5f')],'nonce':_0x320b96[_0x0f97('0x4a')]},'options':{'algorithm':_0x0f97('0x76'),'subject':_0x320b96['id'][_0x0f97('0x75')](),'issuer':hardwareConf[_0x0f97('0x45')](),'audience':hardwareConf[_0x0f97('0x45')]()}};return signJwt(_0x27d98c)[_0x0f97('0x31')](function(_0x2fa000){return{'iat':_0x320b96['apiKeyIat'],'nonce':_0x320b96[_0x0f97('0x4a')],'token':_0x2fa000};});}