Built motion from commit (unavailable).|2.5.14
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x9dad=['phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','interface','userProfileId','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','params','closed','disposition','then','status','unmanaged','json','Forbidden.','catch','headers','authorization','startsWith','Basic','User','find','authenticate','pass','Wrong\x20credentials.','user','Unknown\x20authorization\x20format','query','getUuid','apikey','sub','Setting','findOne','allowedLoginAttempts','apiKeyNonce','nonce','disabled','Invalid\x20API\x20access\x20key','blocked','blockDuration','minutes','User\x20not\x20found.','User\x20object\x20not\x20found.','getLicense','update','Forbidden','isMiddleware','motion.token','redirect','/dashboards/general','send','isNil','generateApiKey','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','length','splice','unshift','encryptString','join','promisify','sign','secret','payload','options','verify','randomBytes','toString','hex','now','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','basic-auth','bluebird','util','secrets','session','role','name','internal','email','userpic','md5secret','faxPause','openchannelPause','pauseType','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','phoneBarAutoAnswer'];(function(_0xbca1b1,_0x33f0ce){var _0x4e1686=function(_0x58a80c){while(--_0x58a80c){_0xbca1b1['push'](_0xbca1b1['shift']());}};_0x4e1686(++_0x33f0ce);}(_0x9dad,0xcb));var _0xd9da=function(_0x35e154,_0x155189){_0x35e154=_0x35e154-0x0;var _0x5c6b27=_0x9dad[_0x35e154];return _0x5c6b27;};'use strict';var db=require(_0xd9da('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0xd9da('0x1'));var licenseUtil=require(_0xd9da('0x2'));var encryptor=require(_0xd9da('0x3'));var _=require(_0xd9da('0x4'));var jwt=require(_0xd9da('0x5'));var expressJwt=require(_0xd9da('0x6'));var compose=require('composable-middleware');var basicAuth=require(_0xd9da('0x7'));var crypto=require('crypto');var BPromise=require(_0xd9da('0x8'));var util=require(_0xd9da('0x9'));var moment=require('moment');var validateJwt=expressJwt({'secret':config[_0xd9da('0xa')][_0xd9da('0xb')]});var userAttributes=['id',_0xd9da('0xc'),'fullname',_0xd9da('0xd'),_0xd9da('0xe'),_0xd9da('0xf'),_0xd9da('0x10'),'permissions',_0xd9da('0x11'),'voicePause','chatPause','mailPause',_0xd9da('0x12'),'smsPause',_0xd9da('0x13'),_0xd9da('0x14'),'showWebBar',_0xd9da('0x15'),_0xd9da('0x16'),_0xd9da('0x17'),_0xd9da('0x18'),_0xd9da('0x19'),'alias',_0xd9da('0x1a'),'phoneBarAutoAnswerDelay',_0xd9da('0x1b'),_0xd9da('0x1c'),_0xd9da('0x1d'),'phoneBarEnableSettings','phoneBarExpires',_0xd9da('0x1e'),_0xd9da('0x1f'),_0xd9da('0x20'),'hotdesk',_0xd9da('0x21'),_0xd9da('0x22'),_0xd9da('0x23')];exports[_0xd9da('0x24')]=function(){return this[_0xd9da('0x25')](!![])[_0xd9da('0x26')](function(_0x276524,_0x26f9f8,_0x4157f0){if(_0x276524['user']){_0x4157f0();}else{return db['ChatInteraction']['findOne']({'where':{'id':_0x276524[_0xd9da('0x27')]['id']},'attributes':['id',_0xd9da('0x28'),_0xd9da('0x29')],'raw':!![]})[_0xd9da('0x2a')](function(_0x59490b){if(_0x59490b&&_0x59490b[_0xd9da('0x28')]){return _0x26f9f8[_0xd9da('0x2b')](_0x59490b['disposition']===_0xd9da('0x2c')?0x195:0x193)[_0xd9da('0x2d')]({'message':_0x59490b[_0xd9da('0x29')]===_0xd9da('0x2c')?'Unmanaged.':_0xd9da('0x2e')});}else{_0x4157f0();}})[_0xd9da('0x2f')](function(_0x4238c4){_0x4157f0(_0x4238c4);});}});};exports[_0xd9da('0x25')]=function isAuthenticated(_0x3473a8){return compose()[_0xd9da('0x26')](function(_0x32cac0,_0x40193c,_0x4921c5){var _0x3524d0;if(_0x32cac0[_0xd9da('0x30')][_0xd9da('0x31')]){if(_[_0xd9da('0x32')](_0x32cac0[_0xd9da('0x30')]['authorization'],_0xd9da('0x33'))){var _0x286e3f=basicAuth(_0x32cac0);db[_0xd9da('0x34')][_0xd9da('0x35')]({'where':{'name':_0x286e3f[_0xd9da('0xd')]}})[_0xd9da('0x2a')](function(_0x5133a3){if(!_0x5133a3||!_0x5133a3[_0xd9da('0x36')](_0x286e3f[_0xd9da('0x37')])){return _0x40193c[_0xd9da('0x2b')](0x191)[_0xd9da('0x2d')]({'message':_0xd9da('0x38')});}_0x32cac0[_0xd9da('0x39')]={'id':_0x5133a3['id']};_0x4921c5();})[_0xd9da('0x2f')](function(_0xa66541){_0x4921c5(_0xa66541);});}else if(_[_0xd9da('0x32')](_0x32cac0[_0xd9da('0x30')][_0xd9da('0x31')],'Bearer')){validateJwt(_0x32cac0,_0x40193c,_0x4921c5);}else{if(_0x3473a8){_0x4921c5();}else{return _0x40193c[_0xd9da('0x2b')](0x193)['json']({'message':_0xd9da('0x3a')});}}}else if(_0x32cac0[_0xd9da('0x3b')]['apikey']){try{var _0x599a85={'audience':hardwareConf[_0xd9da('0x3c')](),'issuer':hardwareConf[_0xd9da('0x3c')]()};verifyJwt(_0x32cac0[_0xd9da('0x3b')][_0xd9da('0x3d')],_0x599a85)['then'](function(_0x1686e0){return db[_0xd9da('0x34')]['find']({'where':{'id':_0x1686e0[_0xd9da('0x3e')]}})['then'](function(_0x1e1bea){_0x3524d0=_0x1e1bea;return db[_0xd9da('0x3f')][_0xd9da('0x40')]({'where':{'id':0x1},'attributes':[_0xd9da('0x41'),'blockDuration'],'raw':!![]});})['then'](function(_0x3e63c9){if(!_0x3524d0||!_['isEqual'](_0x3524d0[_0xd9da('0x42')],_0x1686e0[_0xd9da('0x43')])){return _0x40193c[_0xd9da('0x2b')](0x191)[_0xd9da('0x2d')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x3524d0[_0xd9da('0x44')]){return _0x40193c[_0xd9da('0x2b')](0x191)[_0xd9da('0x2d')]({'message':_0xd9da('0x45')});}if(_0x3524d0[_0xd9da('0x46')]){if(_0x3e63c9[_0xd9da('0x47')]>0x0){if(moment(_0x3524d0['blockedAt'])['add'](_0x3e63c9[_0xd9da('0x47')],_0xd9da('0x48'))>moment()){return _0x40193c[_0xd9da('0x2b')](0x191)[_0xd9da('0x2d')]({'message':'Invalid\x20API\x20access\x20key'});}}else{return _0x40193c[_0xd9da('0x2b')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}}_0x32cac0[_0xd9da('0x39')]={'id':_0x3524d0['id']};_0x4921c5();});})[_0xd9da('0x2f')](function(){return _0x40193c[_0xd9da('0x2b')](0x191)[_0xd9da('0x2d')]({'message':_0xd9da('0x45')});});}catch(_0x2a8047){_0x4921c5(_0x2a8047);}}else if(_0x3473a8){_0x4921c5();}else{return _0x40193c[_0xd9da('0x2b')](0x193)[_0xd9da('0x2d')]({'message':_0xd9da('0x3a')});}})[_0xd9da('0x26')](function(_0x16518b,_0x25f292,_0x170421){if(_0x16518b['user']){db[_0xd9da('0x34')][_0xd9da('0x35')]({'where':{'id':_0x16518b[_0xd9da('0x39')]['id']},'attributes':userAttributes})[_0xd9da('0x2a')](function(_0x3c2726){if(!_0x3c2726){return _0x25f292[_0xd9da('0x2b')](0x194)['json']({'message':_0xd9da('0x49')});}_0x16518b[_0xd9da('0x39')]=_0x3c2726;_0x170421();})[_0xd9da('0x2f')](function(_0x34756a){_0x170421(_0x34756a);});}else if(_0x3473a8){_0x170421();}else{return _0x25f292[_0xd9da('0x2b')](0x194)['json']({'message':_0xd9da('0x4a')});}});};exports['canUpdate']=function canUpdate(){return compose()[_0xd9da('0x26')](function(_0x35f272,_0x277a24,_0x308dfc){return licenseUtil[_0xd9da('0x4b')]()[_0xd9da('0x2a')](function(_0x84e4cb){if(_0x84e4cb[_0xd9da('0x4c')]){_0x308dfc();}else{return _0x277a24[_0xd9da('0x2b')](0x193)[_0xd9da('0x2d')]({'message':_0xd9da('0x4d')});}})[_0xd9da('0x2f')](function(_0x1e24c1){_0x308dfc(_0x1e24c1);});});};exports[_0xd9da('0x4e')]=function(_0x4bd06f,_0x5d7862,_0x55b75a){_0x4bd06f['isMiddleware']=!![];return _0x55b75a();};exports['signToken']=function signToken(_0x5158db){return signJwt(_0x5158db);};exports['setTokenCookie']=function(_0x3dd699,_0x171974){if(!_0x3dd699['user']){return _0x171974['status'](0x194)['json']({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x2259e3={'payload':{'id':_0x3dd699[_0xd9da('0x39')]['id'],'role':_0x3dd699[_0xd9da('0x39')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x2259e3)[_0xd9da('0x2a')](function(_0x25cbcd){_0x171974['cookie'](_0xd9da('0x4f'),_0x25cbcd);_0x171974[_0xd9da('0x50')](_0xd9da('0x51'));})[_0xd9da('0x2f')](function(_0x2e6835){return _0x171974[_0xd9da('0x2b')](0x1f4)[_0xd9da('0x52')](_0x2e6835);});};exports['retrieveApiKey']=function(_0x3b3623){if(_[_0xd9da('0x53')](_0x3b3623['apiKeyNonce'])||_[_0xd9da('0x53')](_0x3b3623['apiKeyIat'])){return null;}else{return createJwt(_0x3b3623);}};exports[_0xd9da('0x54')]=function(_0x20031a){_0x20031a['apiKeyNonce']=generateNonce();_0x20031a[_0xd9da('0x55')]=generateIssuedAt();return createJwt(_0x20031a);};exports[_0xd9da('0x56')]=function(_0x557a82,_0x192621){var _0x56ef5c=_0x557a82[_0xd9da('0x3b')]['apikey'];if(_0x56ef5c){var _0x2de14c={'nonce':_0x192621[_0xd9da('0x42')],'iat':_0x192621[_0xd9da('0x55')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0xd9da('0x3c')]()};return verifyJwt(_0x56ef5c,_0x2de14c)['then'](function(){return generateApiKey(_0x192621);});}else{throw{'message':_0xd9da('0x57')};}};exports['validatePasswordPattern']=function(_0xcc271d){var _0x1f59cd=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x1f59cd[_0xd9da('0x58')](_0xcc271d))throw new db[(_0xd9da('0x59'))][(_0xd9da('0x5a'))](_0xd9da('0x5b'));return;};exports[_0xd9da('0x5c')]=function(_0x27fc94,_0x526404,_0x5335d8){var _0x591667=encryptor[_0xd9da('0x5d')](_0x526404)[_0xd9da('0x5e')](',');for(var _0x36e31b=0x0;_0x36e31b<_0x5335d8;_0x36e31b++){if(!_0x591667[_0x36e31b])break;if(_0x27fc94['toLowerCase']()===_0x591667[_0x36e31b][_0xd9da('0x5f')]()){var _0x3d3bcd=util[_0xd9da('0x60')](_0xd9da('0x61'),_0x5335d8);if(_0x5335d8===0x1){_0x3d3bcd=_0xd9da('0x62');}throw new db[(_0xd9da('0x59'))][(_0xd9da('0x5a'))](_0x3d3bcd);}}return;};exports['updatePasswordsHistory']=function(_0x2d5dc1,_0x3c7df8){var _0x5a2ce7=_0x3c7df8?encryptor[_0xd9da('0x5d')](_0x3c7df8)[_0xd9da('0x5e')](','):[];if(_0x5a2ce7[_0xd9da('0x63')]===0x5){_0x5a2ce7[_0xd9da('0x64')](-0x1,0x1);}_0x5a2ce7[_0xd9da('0x65')](_0x2d5dc1);return encryptor[_0xd9da('0x66')](_0x5a2ce7[_0xd9da('0x67')](','));};function signJwt(_0x57707a){var _0x17ee45=BPromise[_0xd9da('0x68')](jwt[_0xd9da('0x69')],{'context':jwt});var _0x50a9b1=_0x57707a[_0xd9da('0x6a')]||config[_0xd9da('0xa')][_0xd9da('0xb')];return new BPromise(function(_0x387bc7,_0x5826a1){_0x17ee45(_0x57707a[_0xd9da('0x6b')],_0x50a9b1,_0x57707a[_0xd9da('0x6c')])[_0xd9da('0x2a')](function(_0x4ec527){_0x387bc7(_0x4ec527);})[_0xd9da('0x2f')](function(_0x2141dc){_0x5826a1(_0x2141dc);});});}function verifyJwt(_0x4e18eb,_0x2b5e6e,_0x3805c3){var _0x342ce0=BPromise[_0xd9da('0x68')](jwt[_0xd9da('0x6d')],{'context':jwt});var _0x55cb19=_0x3805c3||config[_0xd9da('0xa')][_0xd9da('0xb')];return new BPromise(function(_0x36e747,_0x577781){_0x342ce0(_0x4e18eb,_0x55cb19,_0x2b5e6e)['then'](function(_0x42c5b7){_0x36e747(_0x42c5b7);})[_0xd9da('0x2f')](function(_0x5bc0ea){_0x577781(_0x5bc0ea);});});}function generateNonce(){return crypto[_0xd9da('0x6e')](0x10)[_0xd9da('0x6f')](_0xd9da('0x70'));}function generateIssuedAt(){return Math['floor'](Date[_0xd9da('0x71')]()/0x3e8)[_0xd9da('0x6f')]();}function createJwt(_0x5e4c02){var _0x7b2857={'payload':{'iat':_0x5e4c02[_0xd9da('0x55')],'nonce':_0x5e4c02['apiKeyNonce']},'options':{'algorithm':_0xd9da('0x72'),'subject':_0x5e4c02['id'][_0xd9da('0x6f')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0xd9da('0x3c')]()}};return signJwt(_0x7b2857)['then'](function(_0x3bb56f){return{'iat':_0x5e4c02[_0xd9da('0x55')],'nonce':_0x5e4c02['apiKeyNonce'],'token':_0x3bb56f};});}