d2f7e18dfe1aef26380bc2000e3fa66a79a8140f
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xfd36=['isChatInteractionAuthorized','use','user','ChatInteraction','params','closed','disposition','then','status','unmanaged','json','Unmanaged.','Forbidden.','catch','isAuthenticated','authorization','Basic','authenticate','Wrong\x20credentials.','startsWith','headers','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','User','find','sub','Setting','findOne','allowedLoginAttempts','blockDuration','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blockedAt','add','minutes','User\x20not\x20found.','canUpdate','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','validatePasswordHistory','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','ValidationError','length','splice','encryptString','secret','payload','options','secrets','randomBytes','toString','hex','floor','now','../../mysqldb','../../config/environment','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','moment','session','role','fullname','name','email','permissions','md5secret','chatPause','mailPause','faxPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','alias','phoneBarAutoAnswerDelay','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','interface','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','ignorePauseForPreviewCalls'];(function(_0x3dd15e,_0x1f0015){var _0x231fd0=function(_0x4f680a){while(--_0x4f680a){_0x3dd15e['push'](_0x3dd15e['shift']());}};_0x231fd0(++_0x1f0015);}(_0xfd36,0xc4));var _0x6fd3=function(_0x120d59,_0x2fd61c){_0x120d59=_0x120d59-0x0;var _0x382163=_0xfd36[_0x120d59];return _0x382163;};'use strict';var db=require(_0x6fd3('0x0'))['db'];var config=require(_0x6fd3('0x1'));var hardwareConf=require('../../config/license/hardware');var licenseUtil=require(_0x6fd3('0x2'));var encryptor=require(_0x6fd3('0x3'));var _=require(_0x6fd3('0x4'));var jwt=require(_0x6fd3('0x5'));var expressJwt=require(_0x6fd3('0x6'));var compose=require(_0x6fd3('0x7'));var basicAuth=require(_0x6fd3('0x8'));var crypto=require(_0x6fd3('0x9'));var BPromise=require(_0x6fd3('0xa'));var util=require('util');var moment=require(_0x6fd3('0xb'));var validateJwt=expressJwt({'secret':config['secrets'][_0x6fd3('0xc')]});var userAttributes=['id',_0x6fd3('0xd'),_0x6fd3('0xe'),_0x6fd3('0xf'),'internal',_0x6fd3('0x10'),'userpic',_0x6fd3('0x11'),_0x6fd3('0x12'),'voicePause',_0x6fd3('0x13'),_0x6fd3('0x14'),_0x6fd3('0x15'),'smsPause',_0x6fd3('0x16'),_0x6fd3('0x17'),_0x6fd3('0x18'),_0x6fd3('0x19'),_0x6fd3('0x1a'),'crudPermissions','allowmessenger','passwordResetAt',_0x6fd3('0x1b'),'phoneBarAutoAnswer',_0x6fd3('0x1c'),'phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone',_0x6fd3('0x1d'),_0x6fd3('0x1e'),_0x6fd3('0x1f'),_0x6fd3('0x20'),_0x6fd3('0x21'),'hotdesk',_0x6fd3('0x22'),'userProfileId','privacyEnabled','settingsEnabled',_0x6fd3('0x23'),_0x6fd3('0x24'),_0x6fd3('0x25'),_0x6fd3('0x26'),_0x6fd3('0x27'),'selectRecallMeCampaign'];exports[_0x6fd3('0x28')]=function(){return this['isAuthenticated'](!![])[_0x6fd3('0x29')](function(_0x442b17,_0x2cd108,_0x2232b3){if(_0x442b17[_0x6fd3('0x2a')]){_0x2232b3();}else{return db[_0x6fd3('0x2b')]['findOne']({'where':{'id':_0x442b17[_0x6fd3('0x2c')]['id']},'attributes':['id',_0x6fd3('0x2d'),_0x6fd3('0x2e')],'raw':!![]})[_0x6fd3('0x2f')](function(_0x3f0dff){if(_0x3f0dff&&_0x3f0dff[_0x6fd3('0x2d')]){return _0x2cd108[_0x6fd3('0x30')](_0x3f0dff[_0x6fd3('0x2e')]===_0x6fd3('0x31')?0x195:0x193)[_0x6fd3('0x32')]({'message':_0x3f0dff[_0x6fd3('0x2e')]==='unmanaged'?_0x6fd3('0x33'):_0x6fd3('0x34')});}else{_0x2232b3();}})[_0x6fd3('0x35')](function(_0x3d2517){_0x2232b3(_0x3d2517);});}});};exports[_0x6fd3('0x36')]=function isAuthenticated(_0x2bcf0d){return compose()[_0x6fd3('0x29')](function(_0x156d1f,_0x6cb685,_0x3a005a){var _0x3c977a;if(_0x156d1f['headers'][_0x6fd3('0x37')]){if(_['startsWith'](_0x156d1f['headers'][_0x6fd3('0x37')],_0x6fd3('0x38'))){var _0x587b73=basicAuth(_0x156d1f);db['User']['find']({'where':{'name':_0x587b73[_0x6fd3('0xf')]}})[_0x6fd3('0x2f')](function(_0x1771cb){if(!_0x1771cb||!_0x1771cb[_0x6fd3('0x39')](_0x587b73['pass'])){return _0x6cb685[_0x6fd3('0x30')](0x191)[_0x6fd3('0x32')]({'message':_0x6fd3('0x3a')});}_0x156d1f['user']={'id':_0x1771cb['id']};_0x3a005a();})[_0x6fd3('0x35')](function(_0x4cf5fd){_0x3a005a(_0x4cf5fd);});}else if(_[_0x6fd3('0x3b')](_0x156d1f[_0x6fd3('0x3c')][_0x6fd3('0x37')],_0x6fd3('0x3d'))){validateJwt(_0x156d1f,_0x6cb685,_0x3a005a);}else{if(_0x2bcf0d){_0x3a005a();}else{return _0x6cb685['status'](0x193)[_0x6fd3('0x32')]({'message':_0x6fd3('0x3e')});}}}else if(_0x156d1f[_0x6fd3('0x3f')][_0x6fd3('0x40')]){try{var _0x105086={'audience':hardwareConf[_0x6fd3('0x41')](),'issuer':hardwareConf[_0x6fd3('0x41')]()};verifyJwt(_0x156d1f[_0x6fd3('0x3f')][_0x6fd3('0x40')],_0x105086)[_0x6fd3('0x2f')](function(_0x34d4c4){return db[_0x6fd3('0x42')][_0x6fd3('0x43')]({'where':{'id':_0x34d4c4[_0x6fd3('0x44')]}})[_0x6fd3('0x2f')](function(_0x545cc1){_0x3c977a=_0x545cc1;return db[_0x6fd3('0x45')][_0x6fd3('0x46')]({'where':{'id':0x1},'attributes':[_0x6fd3('0x47'),_0x6fd3('0x48')],'raw':!![]});})['then'](function(_0x562eef){if(!_0x3c977a||!_['isEqual'](_0x3c977a[_0x6fd3('0x49')],_0x34d4c4[_0x6fd3('0x4a')])){return _0x6cb685[_0x6fd3('0x30')](0x191)[_0x6fd3('0x32')]({'message':_0x6fd3('0x4b')});}if(_0x3c977a[_0x6fd3('0x4c')]){return _0x6cb685[_0x6fd3('0x30')](0x191)[_0x6fd3('0x32')]({'message':_0x6fd3('0x4d')});}if(_0x3c977a['blocked']){if(_0x562eef['blockDuration']>0x0){if(moment(_0x3c977a[_0x6fd3('0x4e')])[_0x6fd3('0x4f')](_0x562eef[_0x6fd3('0x48')],_0x6fd3('0x50'))>moment()){return _0x6cb685['status'](0x191)[_0x6fd3('0x32')]({'message':_0x6fd3('0x4d')});}}else{return _0x6cb685['status'](0x191)['json']({'message':_0x6fd3('0x4d')});}}_0x156d1f['user']={'id':_0x3c977a['id']};_0x3a005a();});})[_0x6fd3('0x35')](function(){return _0x6cb685['status'](0x191)['json']({'message':_0x6fd3('0x4d')});});}catch(_0x5e02d1){_0x3a005a(_0x5e02d1);}}else if(_0x2bcf0d){_0x3a005a();}else{return _0x6cb685[_0x6fd3('0x30')](0x193)['json']({'message':_0x6fd3('0x3e')});}})[_0x6fd3('0x29')](function(_0x55f8fc,_0x4eb99a,_0x5840c8){if(_0x55f8fc['user']){db[_0x6fd3('0x42')][_0x6fd3('0x43')]({'where':{'id':_0x55f8fc[_0x6fd3('0x2a')]['id']},'attributes':userAttributes})['then'](function(_0x45993e){if(!_0x45993e){return _0x4eb99a['status'](0x194)[_0x6fd3('0x32')]({'message':_0x6fd3('0x51')});}_0x55f8fc[_0x6fd3('0x2a')]=_0x45993e;_0x5840c8();})['catch'](function(_0x1297bc){_0x5840c8(_0x1297bc);});}else if(_0x2bcf0d){_0x5840c8();}else{return _0x4eb99a[_0x6fd3('0x30')](0x194)[_0x6fd3('0x32')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x6fd3('0x52')]=function canUpdate(){return compose()[_0x6fd3('0x29')](function(_0x2c9bb3,_0x13e33c,_0x4c372a){return licenseUtil[_0x6fd3('0x53')]()[_0x6fd3('0x2f')](function(_0x127048){if(_0x127048[_0x6fd3('0x54')]){_0x4c372a();}else{return _0x13e33c['status'](0x193)[_0x6fd3('0x32')]({'message':'Forbidden'});}})[_0x6fd3('0x35')](function(_0x4751c6){_0x4c372a(_0x4751c6);});});};exports['isWebrtcLicence']=function isWebrtcLicence(){return compose()[_0x6fd3('0x29')](function(_0x3d974e,_0x500219,_0x39a68b){return licenseUtil[_0x6fd3('0x53')]()[_0x6fd3('0x2f')](function(_0x29038f){if(_0x29038f['webrtc']){_0x39a68b();}else{return _0x500219[_0x6fd3('0x30')](0x193)[_0x6fd3('0x32')]({'message':_0x6fd3('0x55')});}})['catch'](function(_0x25bdc1){_0x39a68b(_0x25bdc1);});});};exports[_0x6fd3('0x56')]=function(_0x58fb72,_0x8e1ae,_0x4b7ba1){_0x58fb72[_0x6fd3('0x56')]=!![];return _0x4b7ba1();};exports[_0x6fd3('0x57')]=function signToken(_0x4e4fb8){return signJwt(_0x4e4fb8);};exports[_0x6fd3('0x58')]=function(_0x3b5c56,_0x35a1fd){if(!_0x3b5c56['user']){return _0x35a1fd[_0x6fd3('0x30')](0x194)[_0x6fd3('0x32')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x536153={'payload':{'id':_0x3b5c56['user']['id'],'role':_0x3b5c56[_0x6fd3('0x2a')][_0x6fd3('0xd')]},'options':{'expiresIn':0x15180}};return signJwt(_0x536153)[_0x6fd3('0x2f')](function(_0x19af8c){_0x35a1fd['cookie']('motion.token',_0x19af8c);_0x35a1fd[_0x6fd3('0x59')](_0x6fd3('0x5a'));})[_0x6fd3('0x35')](function(_0x243426){return _0x35a1fd[_0x6fd3('0x30')](0x1f4)[_0x6fd3('0x5b')](_0x243426);});};exports[_0x6fd3('0x5c')]=function(_0x2d518e){if(_[_0x6fd3('0x5d')](_0x2d518e['apiKeyNonce'])||_[_0x6fd3('0x5d')](_0x2d518e[_0x6fd3('0x5e')])){return null;}else{return createJwt(_0x2d518e);}};exports[_0x6fd3('0x5f')]=function(_0x1ff765){_0x1ff765[_0x6fd3('0x49')]=generateNonce();_0x1ff765[_0x6fd3('0x5e')]=generateIssuedAt();return createJwt(_0x1ff765);};exports['regenerateApiKey']=function(_0x2aabda,_0xf91ec0){var _0x4b02b0=_0x2aabda[_0x6fd3('0x3f')][_0x6fd3('0x40')];if(_0x4b02b0){var _0x453631={'nonce':_0xf91ec0[_0x6fd3('0x49')],'iat':_0xf91ec0[_0x6fd3('0x5e')],'audience':hardwareConf[_0x6fd3('0x41')](),'issuer':hardwareConf[_0x6fd3('0x41')]()};return verifyJwt(_0x4b02b0,_0x453631)['then'](function(){return generateApiKey(_0xf91ec0);});}else{throw{'message':_0x6fd3('0x60')};}};exports[_0x6fd3('0x61')]=function(_0x11838f){var _0xc5f2af=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0xc5f2af[_0x6fd3('0x62')](_0x11838f))throw new db[(_0x6fd3('0x63'))]['ValidationError']('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x6fd3('0x64')]=function(_0x594cb3,_0x55f6cf,_0x20459b){var _0x59f5a9=encryptor[_0x6fd3('0x65')](_0x55f6cf)['split'](',');for(var _0x4ff11f=0x0;_0x4ff11f<_0x20459b;_0x4ff11f++){if(!_0x59f5a9[_0x4ff11f])break;if(_0x594cb3[_0x6fd3('0x66')]()===_0x59f5a9[_0x4ff11f]['toLowerCase']()){var _0x586bc1=util[_0x6fd3('0x67')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x20459b);if(_0x20459b===0x1){_0x586bc1=_0x6fd3('0x68');}throw new db[(_0x6fd3('0x63'))][(_0x6fd3('0x69'))](_0x586bc1);}}return;};exports['updatePasswordsHistory']=function(_0x25cd3b,_0xb4c458){var _0x434613=_0xb4c458?encryptor[_0x6fd3('0x65')](_0xb4c458)['split'](','):[];if(_0x434613[_0x6fd3('0x6a')]===0x5){_0x434613[_0x6fd3('0x6b')](-0x1,0x1);}_0x434613['unshift'](_0x25cd3b);return encryptor[_0x6fd3('0x6c')](_0x434613['join'](','));};function signJwt(_0x4f246a){var _0x52de29=BPromise['promisify'](jwt['sign'],{'context':jwt});var _0x192e6b=_0x4f246a[_0x6fd3('0x6d')]||config['secrets'][_0x6fd3('0xc')];return new BPromise(function(_0x4fc04e,_0x1bbef7){_0x52de29(_0x4f246a[_0x6fd3('0x6e')],_0x192e6b,_0x4f246a[_0x6fd3('0x6f')])[_0x6fd3('0x2f')](function(_0x3585af){_0x4fc04e(_0x3585af);})[_0x6fd3('0x35')](function(_0x62d92c){_0x1bbef7(_0x62d92c);});});}function verifyJwt(_0x3e0696,_0x1999f8,_0x46502e){var _0x202c41=BPromise['promisify'](jwt['verify'],{'context':jwt});var _0x4ddc5d=_0x46502e||config[_0x6fd3('0x70')][_0x6fd3('0xc')];return new BPromise(function(_0x155c46,_0xc37bd9){_0x202c41(_0x3e0696,_0x4ddc5d,_0x1999f8)[_0x6fd3('0x2f')](function(_0x378185){_0x155c46(_0x378185);})[_0x6fd3('0x35')](function(_0x54a9a2){_0xc37bd9(_0x54a9a2);});});}function generateNonce(){return crypto[_0x6fd3('0x71')](0x10)[_0x6fd3('0x72')](_0x6fd3('0x73'));}function generateIssuedAt(){return Math[_0x6fd3('0x74')](Date[_0x6fd3('0x75')]()/0x3e8)['toString']();}function createJwt(_0x27e0c5){var _0x3d34a4={'payload':{'iat':_0x27e0c5[_0x6fd3('0x5e')],'nonce':_0x27e0c5[_0x6fd3('0x49')]},'options':{'algorithm':'HS512','subject':_0x27e0c5['id'][_0x6fd3('0x72')](),'issuer':hardwareConf[_0x6fd3('0x41')](),'audience':hardwareConf[_0x6fd3('0x41')]()}};return signJwt(_0x3d34a4)['then'](function(_0x7922b7){return{'iat':_0x27e0c5[_0x6fd3('0x5e')],'nonce':_0x27e0c5['apiKeyNonce'],'token':_0x7922b7};});}