Built motion from commit 14588770.|2.5.38
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xe57f=['nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockedAt','add','Invalid\x20API\x20access\x20key','User','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','getLicense','update','Forbidden','webrtc','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyNonce','apiKeyIat','generateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','split','length','splice','unshift','encryptString','join','sign','secret','payload','options','promisify','verify','secrets','floor','toString','HS512','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','composable-middleware','basic-auth','crypto','bluebird','util','moment','session','role','fullname','name','internal','email','userpic','permissions','md5secret','faxPause','smsPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarDnd','phoneBarEnableSettings','phoneBarExpires','phoneBarRemoteControl','phoneBarRemoteControlPort','interface','userProfileId','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','selectRecallMeCampaign','isChatInteractionAuthorized','isAuthenticated','use','ChatInteraction','params','closed','disposition','then','status','unmanaged','json','Unmanaged.','Forbidden.','catch','headers','startsWith','authorization','find','authenticate','pass','Wrong\x20credentials.','user','Unknown\x20authorization\x20format','getUuid','query','apikey','sub','Setting','findOne','allowedLoginAttempts','blockDuration','isEqual'];(function(_0x1de5df,_0x828ae3){var _0x3f1c30=function(_0x5c790b){while(--_0x5c790b){_0x1de5df['push'](_0x1de5df['shift']());}};_0x3f1c30(++_0x828ae3);}(_0xe57f,0x1c8));var _0xfe57=function(_0x4565bf,_0x5ad9d6){_0x4565bf=_0x4565bf-0x0;var _0x5610ba=_0xe57f[_0x4565bf];return _0x5610ba;};'use strict';var db=require('../../mysqldb')['db'];var config=require(_0xfe57('0x0'));var hardwareConf=require(_0xfe57('0x1'));var licenseUtil=require(_0xfe57('0x2'));var encryptor=require(_0xfe57('0x3'));var _=require(_0xfe57('0x4'));var jwt=require(_0xfe57('0x5'));var expressJwt=require('express-jwt');var compose=require(_0xfe57('0x6'));var basicAuth=require(_0xfe57('0x7'));var crypto=require(_0xfe57('0x8'));var BPromise=require(_0xfe57('0x9'));var util=require(_0xfe57('0xa'));var moment=require(_0xfe57('0xb'));var validateJwt=expressJwt({'secret':config['secrets'][_0xfe57('0xc')]});var userAttributes=['id',_0xfe57('0xd'),_0xfe57('0xe'),_0xfe57('0xf'),_0xfe57('0x10'),_0xfe57('0x11'),_0xfe57('0x12'),_0xfe57('0x13'),_0xfe57('0x14'),'voicePause','chatPause','mailPause',_0xfe57('0x15'),_0xfe57('0x16'),'openchannelPause',_0xfe57('0x17'),_0xfe57('0x18'),_0xfe57('0x19'),_0xfe57('0x1a'),_0xfe57('0x1b'),_0xfe57('0x1c'),_0xfe57('0x1d'),_0xfe57('0x1e'),_0xfe57('0x1f'),'phoneBarAutoAnswerDelay',_0xfe57('0x20'),'phoneBarEnableRecording','phoneBarEnableDtmfTone',_0xfe57('0x21'),_0xfe57('0x22'),'phoneBarPrefixRequired',_0xfe57('0x23'),_0xfe57('0x24'),'hotdesk',_0xfe57('0x25'),_0xfe57('0x26'),'privacyEnabled','settingsEnabled',_0xfe57('0x27'),_0xfe57('0x28'),_0xfe57('0x29'),_0xfe57('0x2a'),'ignorePauseForPreviewCalls',_0xfe57('0x2b')];exports[_0xfe57('0x2c')]=function(){return this[_0xfe57('0x2d')](!![])[_0xfe57('0x2e')](function(_0x57846d,_0xae285,_0x3c4f04){if(_0x57846d['user']){_0x3c4f04();}else{return db[_0xfe57('0x2f')]['findOne']({'where':{'id':_0x57846d[_0xfe57('0x30')]['id']},'attributes':['id',_0xfe57('0x31'),_0xfe57('0x32')],'raw':!![]})[_0xfe57('0x33')](function(_0x281a39){if(_0x281a39&&_0x281a39[_0xfe57('0x31')]){return _0xae285[_0xfe57('0x34')](_0x281a39['disposition']===_0xfe57('0x35')?0x195:0x193)[_0xfe57('0x36')]({'message':_0x281a39[_0xfe57('0x32')]===_0xfe57('0x35')?_0xfe57('0x37'):_0xfe57('0x38')});}else{_0x3c4f04();}})[_0xfe57('0x39')](function(_0x153246){_0x3c4f04(_0x153246);});}});};exports[_0xfe57('0x2d')]=function isAuthenticated(_0x58f4d9){return compose()[_0xfe57('0x2e')](function(_0x4e0e9d,_0x3a88e4,_0x1679d5){var _0x57a2c9;if(_0x4e0e9d[_0xfe57('0x3a')]['authorization']){if(_[_0xfe57('0x3b')](_0x4e0e9d['headers'][_0xfe57('0x3c')],'Basic')){var _0x58ef6e=basicAuth(_0x4e0e9d);db['User'][_0xfe57('0x3d')]({'where':{'name':_0x58ef6e[_0xfe57('0xf')]}})[_0xfe57('0x33')](function(_0x21e8b3){if(!_0x21e8b3||!_0x21e8b3[_0xfe57('0x3e')](_0x58ef6e[_0xfe57('0x3f')])){return _0x3a88e4[_0xfe57('0x34')](0x191)[_0xfe57('0x36')]({'message':_0xfe57('0x40')});}_0x4e0e9d[_0xfe57('0x41')]={'id':_0x21e8b3['id']};_0x1679d5();})[_0xfe57('0x39')](function(_0x59a2ab){_0x1679d5(_0x59a2ab);});}else if(_['startsWith'](_0x4e0e9d[_0xfe57('0x3a')][_0xfe57('0x3c')],'Bearer')){validateJwt(_0x4e0e9d,_0x3a88e4,_0x1679d5);}else{if(_0x58f4d9){_0x1679d5();}else{return _0x3a88e4[_0xfe57('0x34')](0x193)[_0xfe57('0x36')]({'message':_0xfe57('0x42')});}}}else if(_0x4e0e9d['query']['apikey']){try{var _0x112a26={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0xfe57('0x43')]()};verifyJwt(_0x4e0e9d[_0xfe57('0x44')][_0xfe57('0x45')],_0x112a26)[_0xfe57('0x33')](function(_0x231456){return db['User'][_0xfe57('0x3d')]({'where':{'id':_0x231456[_0xfe57('0x46')]}})[_0xfe57('0x33')](function(_0x394bb2){_0x57a2c9=_0x394bb2;return db[_0xfe57('0x47')][_0xfe57('0x48')]({'where':{'id':0x1},'attributes':[_0xfe57('0x49'),_0xfe57('0x4a')],'raw':!![]});})[_0xfe57('0x33')](function(_0x4dc3ef){if(!_0x57a2c9||!_[_0xfe57('0x4b')](_0x57a2c9['apiKeyNonce'],_0x231456[_0xfe57('0x4c')])){return _0x3a88e4['status'](0x191)['json']({'message':_0xfe57('0x4d')});}if(_0x57a2c9[_0xfe57('0x4e')]){return _0x3a88e4[_0xfe57('0x34')](0x191)[_0xfe57('0x36')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x57a2c9[_0xfe57('0x4f')]){if(_0x4dc3ef[_0xfe57('0x4a')]>0x0){if(moment(_0x57a2c9[_0xfe57('0x50')])[_0xfe57('0x51')](_0x4dc3ef[_0xfe57('0x4a')],'minutes')>moment()){return _0x3a88e4[_0xfe57('0x34')](0x191)[_0xfe57('0x36')]({'message':_0xfe57('0x52')});}}else{return _0x3a88e4['status'](0x191)[_0xfe57('0x36')]({'message':'Invalid\x20API\x20access\x20key'});}}_0x4e0e9d[_0xfe57('0x41')]={'id':_0x57a2c9['id']};_0x1679d5();});})[_0xfe57('0x39')](function(){return _0x3a88e4['status'](0x191)[_0xfe57('0x36')]({'message':_0xfe57('0x52')});});}catch(_0x468627){_0x1679d5(_0x468627);}}else if(_0x58f4d9){_0x1679d5();}else{return _0x3a88e4[_0xfe57('0x34')](0x193)['json']({'message':_0xfe57('0x42')});}})['use'](function(_0x4e7384,_0x5eb8a3,_0x15a72a){if(_0x4e7384['user']){db[_0xfe57('0x53')][_0xfe57('0x3d')]({'where':{'id':_0x4e7384[_0xfe57('0x41')]['id']},'attributes':userAttributes})[_0xfe57('0x33')](function(_0x7ad5ba){if(!_0x7ad5ba){return _0x5eb8a3[_0xfe57('0x34')](0x194)[_0xfe57('0x36')]({'message':_0xfe57('0x54')});}_0x4e7384[_0xfe57('0x41')]=_0x7ad5ba;_0x15a72a();})[_0xfe57('0x39')](function(_0x442cc3){_0x15a72a(_0x442cc3);});}else if(_0x58f4d9){_0x15a72a();}else{return _0x5eb8a3[_0xfe57('0x34')](0x194)[_0xfe57('0x36')]({'message':_0xfe57('0x55')});}});};exports[_0xfe57('0x56')]=function canUpdate(){return compose()[_0xfe57('0x2e')](function(_0x4d7c89,_0x1e8719,_0x400ba8){return licenseUtil[_0xfe57('0x57')]()[_0xfe57('0x33')](function(_0x369c2e){if(_0x369c2e[_0xfe57('0x58')]){_0x400ba8();}else{return _0x1e8719['status'](0x193)['json']({'message':_0xfe57('0x59')});}})[_0xfe57('0x39')](function(_0x5daf06){_0x400ba8(_0x5daf06);});});};exports['isWebrtcLicence']=function isWebrtcLicence(){return compose()[_0xfe57('0x2e')](function(_0x1a566d,_0x5b531f,_0x19ac0b){return licenseUtil[_0xfe57('0x57')]()[_0xfe57('0x33')](function(_0x1cd1aa){if(_0x1cd1aa[_0xfe57('0x5a')]){_0x19ac0b();}else{return _0x5b531f[_0xfe57('0x34')](0x193)['json']({'message':_0xfe57('0x59')});}})[_0xfe57('0x39')](function(_0x1442e){_0x19ac0b(_0x1442e);});});};exports[_0xfe57('0x5b')]=function(_0x853b36,_0x5a7792,_0x8254c5){_0x853b36[_0xfe57('0x5b')]=!![];return _0x8254c5();};exports[_0xfe57('0x5c')]=function signToken(_0x517d34){return signJwt(_0x517d34);};exports[_0xfe57('0x5d')]=function(_0x30145a,_0x358c10){if(!_0x30145a[_0xfe57('0x41')]){return _0x358c10[_0xfe57('0x34')](0x194)['json']({'message':_0xfe57('0x5e')});}var _0x49a373={'payload':{'id':_0x30145a['user']['id'],'role':_0x30145a['user'][_0xfe57('0xd')]},'options':{'expiresIn':0x15180}};return signJwt(_0x49a373)['then'](function(_0xeb8d20){_0x358c10[_0xfe57('0x5f')](_0xfe57('0x60'),_0xeb8d20);_0x358c10[_0xfe57('0x61')](_0xfe57('0x62'));})[_0xfe57('0x39')](function(_0x350da4){return _0x358c10[_0xfe57('0x34')](0x1f4)[_0xfe57('0x63')](_0x350da4);});};exports[_0xfe57('0x64')]=function(_0x17de64){if(_[_0xfe57('0x65')](_0x17de64[_0xfe57('0x66')])||_[_0xfe57('0x65')](_0x17de64[_0xfe57('0x67')])){return null;}else{return createJwt(_0x17de64);}};exports[_0xfe57('0x68')]=function(_0x4e74a4){_0x4e74a4['apiKeyNonce']=generateNonce();_0x4e74a4[_0xfe57('0x67')]=generateIssuedAt();return createJwt(_0x4e74a4);};exports['regenerateApiKey']=function(_0x160b7b,_0x5d1453){var _0x1c0258=_0x160b7b[_0xfe57('0x44')]['apikey'];if(_0x1c0258){var _0x9c1b2a={'nonce':_0x5d1453[_0xfe57('0x66')],'iat':_0x5d1453['apiKeyIat'],'audience':hardwareConf[_0xfe57('0x43')](),'issuer':hardwareConf[_0xfe57('0x43')]()};return verifyJwt(_0x1c0258,_0x9c1b2a)['then'](function(){return generateApiKey(_0x5d1453);});}else{throw{'message':_0xfe57('0x69')};}};exports[_0xfe57('0x6a')]=function(_0x3f9059){var _0x416ef0=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x416ef0['test'](_0x3f9059))throw new db[(_0xfe57('0x6b'))][(_0xfe57('0x6c'))](_0xfe57('0x6d'));return;};exports[_0xfe57('0x6e')]=function(_0x356d16,_0x4cfbab,_0x51abb9){var _0x269b49=encryptor[_0xfe57('0x6f')](_0x4cfbab)['split'](',');for(var _0x1953d7=0x0;_0x1953d7<_0x51abb9;_0x1953d7++){if(!_0x269b49[_0x1953d7])break;if(_0x356d16[_0xfe57('0x70')]()===_0x269b49[_0x1953d7][_0xfe57('0x70')]()){var _0xcdf901=util[_0xfe57('0x71')](_0xfe57('0x72'),_0x51abb9);if(_0x51abb9===0x1){_0xcdf901=_0xfe57('0x73');}throw new db[(_0xfe57('0x6b'))][(_0xfe57('0x6c'))](_0xcdf901);}}return;};exports[_0xfe57('0x74')]=function(_0xfbe27d,_0x5e86cf){var _0x2e87c1=_0x5e86cf?encryptor['decryptString'](_0x5e86cf)[_0xfe57('0x75')](','):[];if(_0x2e87c1[_0xfe57('0x76')]===0x5){_0x2e87c1[_0xfe57('0x77')](-0x1,0x1);}_0x2e87c1[_0xfe57('0x78')](_0xfbe27d);return encryptor[_0xfe57('0x79')](_0x2e87c1[_0xfe57('0x7a')](','));};function signJwt(_0x3f13f8){var _0x24a30d=BPromise['promisify'](jwt[_0xfe57('0x7b')],{'context':jwt});var _0x7d33f2=_0x3f13f8[_0xfe57('0x7c')]||config['secrets'][_0xfe57('0xc')];return new BPromise(function(_0x299bab,_0xa0e60a){_0x24a30d(_0x3f13f8[_0xfe57('0x7d')],_0x7d33f2,_0x3f13f8[_0xfe57('0x7e')])['then'](function(_0x1724c1){_0x299bab(_0x1724c1);})[_0xfe57('0x39')](function(_0xd4f862){_0xa0e60a(_0xd4f862);});});}function verifyJwt(_0x82fd25,_0x25faa5,_0x45e2d4){var _0x495c0e=BPromise[_0xfe57('0x7f')](jwt[_0xfe57('0x80')],{'context':jwt});var _0x1aebed=_0x45e2d4||config[_0xfe57('0x81')][_0xfe57('0xc')];return new BPromise(function(_0x266f14,_0x429470){_0x495c0e(_0x82fd25,_0x1aebed,_0x25faa5)[_0xfe57('0x33')](function(_0x14e87f){_0x266f14(_0x14e87f);})[_0xfe57('0x39')](function(_0x4730c7){_0x429470(_0x4730c7);});});}function generateNonce(){return crypto['randomBytes'](0x10)['toString']('hex');}function generateIssuedAt(){return Math[_0xfe57('0x82')](Date['now']()/0x3e8)[_0xfe57('0x83')]();}function createJwt(_0x326c6b){var _0x1e566b={'payload':{'iat':_0x326c6b[_0xfe57('0x67')],'nonce':_0x326c6b[_0xfe57('0x66')]},'options':{'algorithm':_0xfe57('0x84'),'subject':_0x326c6b['id'][_0xfe57('0x83')](),'issuer':hardwareConf[_0xfe57('0x43')](),'audience':hardwareConf[_0xfe57('0x43')]()}};return signJwt(_0x1e566b)[_0xfe57('0x33')](function(_0x172614){return{'iat':_0x326c6b[_0xfe57('0x67')],'nonce':_0x326c6b['apiKeyNonce'],'token':_0x172614};});}