Built motion from commit f7863d46.|2.5.41
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xec98=['length','splice','unshift','encryptString','join','sign','payload','options','promisify','randomBytes','toString','hex','now','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util','secrets','session','internal','email','userpic','voicePause','chatPause','mailPause','faxPause','openchannelPause','pauseType','showWebBar','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarExpires','phoneBarRemoteControl','hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','selectRecallMeCampaign','use','user','ChatInteraction','findOne','params','closed','then','status','disposition','unmanaged','json','Forbidden.','catch','isAuthenticated','headers','authorization','startsWith','Basic','User','authenticate','Wrong\x20credentials.','Unknown\x20authorization\x20format','apikey','getUuid','find','Setting','allowedLoginAttempts','blockDuration','apiKeyNonce','nonce','disabled','Invalid\x20API\x20access\x20key','minutes','User\x20not\x20found.','canUpdate','getLicense','update','Forbidden','isWebrtcLicence','webrtc','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','role','cookie','redirect','/dashboards/general','isNil','apiKeyIat','regenerateApiKey','query','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','decryptString'];(function(_0x35edc7,_0x544259){var _0x17302a=function(_0x571063){while(--_0x571063){_0x35edc7['push'](_0x35edc7['shift']());}};_0x17302a(++_0x544259);}(_0xec98,0x84));var _0x8ec9=function(_0x108576,_0x12ce70){_0x108576=_0x108576-0x0;var _0x1fe841=_0xec98[_0x108576];return _0x1fe841;};'use strict';var db=require('../../mysqldb')['db'];var config=require('../../config/environment');var hardwareConf=require(_0x8ec9('0x0'));var licenseUtil=require(_0x8ec9('0x1'));var encryptor=require(_0x8ec9('0x2'));var _=require(_0x8ec9('0x3'));var jwt=require(_0x8ec9('0x4'));var expressJwt=require(_0x8ec9('0x5'));var compose=require(_0x8ec9('0x6'));var basicAuth=require(_0x8ec9('0x7'));var crypto=require(_0x8ec9('0x8'));var BPromise=require(_0x8ec9('0x9'));var util=require(_0x8ec9('0xa'));var moment=require('moment');var validateJwt=expressJwt({'secret':config[_0x8ec9('0xb')][_0x8ec9('0xc')]});var userAttributes=['id','role','fullname','name',_0x8ec9('0xd'),_0x8ec9('0xe'),_0x8ec9('0xf'),'permissions','md5secret',_0x8ec9('0x10'),_0x8ec9('0x11'),_0x8ec9('0x12'),_0x8ec9('0x13'),'smsPause',_0x8ec9('0x14'),_0x8ec9('0x15'),_0x8ec9('0x16'),'lastLoginAt',_0x8ec9('0x17'),_0x8ec9('0x18'),_0x8ec9('0x19'),_0x8ec9('0x1a'),'alias',_0x8ec9('0x1b'),_0x8ec9('0x1c'),_0x8ec9('0x1d'),_0x8ec9('0x1e'),'phoneBarEnableDtmfTone','phoneBarEnableSettings',_0x8ec9('0x1f'),'phoneBarPrefixRequired',_0x8ec9('0x20'),'phoneBarRemoteControlPort',_0x8ec9('0x21'),_0x8ec9('0x22'),_0x8ec9('0x23'),_0x8ec9('0x24'),_0x8ec9('0x25'),_0x8ec9('0x26'),_0x8ec9('0x27'),_0x8ec9('0x28'),_0x8ec9('0x29'),'ignorePauseForPreviewCalls',_0x8ec9('0x2a')];exports['isChatInteractionAuthorized']=function(){return this['isAuthenticated'](!![])[_0x8ec9('0x2b')](function(_0x34ae18,_0x5e62e5,_0x19ff80){if(_0x34ae18[_0x8ec9('0x2c')]){_0x19ff80();}else{return db[_0x8ec9('0x2d')][_0x8ec9('0x2e')]({'where':{'id':_0x34ae18[_0x8ec9('0x2f')]['id']},'attributes':['id',_0x8ec9('0x30'),'disposition'],'raw':!![]})[_0x8ec9('0x31')](function(_0x2a45f3){if(_0x2a45f3&&_0x2a45f3[_0x8ec9('0x30')]){return _0x5e62e5[_0x8ec9('0x32')](_0x2a45f3[_0x8ec9('0x33')]===_0x8ec9('0x34')?0x195:0x193)[_0x8ec9('0x35')]({'message':_0x2a45f3[_0x8ec9('0x33')]===_0x8ec9('0x34')?'Unmanaged.':_0x8ec9('0x36')});}else{_0x19ff80();}})[_0x8ec9('0x37')](function(_0x4ac94c){_0x19ff80(_0x4ac94c);});}});};exports[_0x8ec9('0x38')]=function isAuthenticated(_0x4851ce){return compose()['use'](function(_0x5686dc,_0x514401,_0x510f5d){var _0x160f89;if(_0x5686dc[_0x8ec9('0x39')][_0x8ec9('0x3a')]){if(_[_0x8ec9('0x3b')](_0x5686dc[_0x8ec9('0x39')][_0x8ec9('0x3a')],_0x8ec9('0x3c'))){var _0x17f318=basicAuth(_0x5686dc);db[_0x8ec9('0x3d')]['find']({'where':{'name':_0x17f318['name']}})[_0x8ec9('0x31')](function(_0x5a2b6b){if(!_0x5a2b6b||!_0x5a2b6b[_0x8ec9('0x3e')](_0x17f318['pass'])){return _0x514401[_0x8ec9('0x32')](0x191)[_0x8ec9('0x35')]({'message':_0x8ec9('0x3f')});}_0x5686dc[_0x8ec9('0x2c')]={'id':_0x5a2b6b['id']};_0x510f5d();})[_0x8ec9('0x37')](function(_0x5e4534){_0x510f5d(_0x5e4534);});}else if(_[_0x8ec9('0x3b')](_0x5686dc['headers']['authorization'],'Bearer')){validateJwt(_0x5686dc,_0x514401,_0x510f5d);}else{if(_0x4851ce){_0x510f5d();}else{return _0x514401[_0x8ec9('0x32')](0x193)[_0x8ec9('0x35')]({'message':_0x8ec9('0x40')});}}}else if(_0x5686dc['query'][_0x8ec9('0x41')]){try{var _0x33a129={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x8ec9('0x42')]()};verifyJwt(_0x5686dc['query'][_0x8ec9('0x41')],_0x33a129)['then'](function(_0x5b4757){return db['User'][_0x8ec9('0x43')]({'where':{'id':_0x5b4757['sub']}})[_0x8ec9('0x31')](function(_0x1e797d){_0x160f89=_0x1e797d;return db[_0x8ec9('0x44')][_0x8ec9('0x2e')]({'where':{'id':0x1},'attributes':[_0x8ec9('0x45'),_0x8ec9('0x46')],'raw':!![]});})[_0x8ec9('0x31')](function(_0x464a17){if(!_0x160f89||!_['isEqual'](_0x160f89[_0x8ec9('0x47')],_0x5b4757[_0x8ec9('0x48')])){return _0x514401['status'](0x191)[_0x8ec9('0x35')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x160f89[_0x8ec9('0x49')]){return _0x514401[_0x8ec9('0x32')](0x191)[_0x8ec9('0x35')]({'message':_0x8ec9('0x4a')});}if(_0x160f89['blocked']){if(_0x464a17[_0x8ec9('0x46')]>0x0){if(moment(_0x160f89['blockedAt'])['add'](_0x464a17[_0x8ec9('0x46')],_0x8ec9('0x4b'))>moment()){return _0x514401[_0x8ec9('0x32')](0x191)['json']({'message':_0x8ec9('0x4a')});}}else{return _0x514401['status'](0x191)[_0x8ec9('0x35')]({'message':_0x8ec9('0x4a')});}}_0x5686dc['user']={'id':_0x160f89['id']};_0x510f5d();});})[_0x8ec9('0x37')](function(){return _0x514401[_0x8ec9('0x32')](0x191)['json']({'message':_0x8ec9('0x4a')});});}catch(_0x46ff4d){_0x510f5d(_0x46ff4d);}}else if(_0x4851ce){_0x510f5d();}else{return _0x514401[_0x8ec9('0x32')](0x193)[_0x8ec9('0x35')]({'message':_0x8ec9('0x40')});}})[_0x8ec9('0x2b')](function(_0xd82755,_0x5b6ccb,_0x2268d5){if(_0xd82755[_0x8ec9('0x2c')]){db[_0x8ec9('0x3d')]['find']({'where':{'id':_0xd82755[_0x8ec9('0x2c')]['id']},'attributes':userAttributes})[_0x8ec9('0x31')](function(_0x8f540b){if(!_0x8f540b){return _0x5b6ccb[_0x8ec9('0x32')](0x194)[_0x8ec9('0x35')]({'message':_0x8ec9('0x4c')});}_0xd82755[_0x8ec9('0x2c')]=_0x8f540b;_0x2268d5();})[_0x8ec9('0x37')](function(_0x1f5908){_0x2268d5(_0x1f5908);});}else if(_0x4851ce){_0x2268d5();}else{return _0x5b6ccb[_0x8ec9('0x32')](0x194)[_0x8ec9('0x35')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x8ec9('0x4d')]=function canUpdate(){return compose()[_0x8ec9('0x2b')](function(_0x51dc04,_0x18e929,_0x2a135e){return licenseUtil[_0x8ec9('0x4e')]()['then'](function(_0x405fba){if(_0x405fba[_0x8ec9('0x4f')]){_0x2a135e();}else{return _0x18e929[_0x8ec9('0x32')](0x193)[_0x8ec9('0x35')]({'message':_0x8ec9('0x50')});}})['catch'](function(_0x2eb497){_0x2a135e(_0x2eb497);});});};exports[_0x8ec9('0x51')]=function isWebrtcLicence(){return compose()[_0x8ec9('0x2b')](function(_0xc4552f,_0xfbfe93,_0x306b75){return licenseUtil['getLicense']()['then'](function(_0x5a4a2e){if(_0x5a4a2e[_0x8ec9('0x52')]){_0x306b75();}else{return _0xfbfe93[_0x8ec9('0x32')](0x193)['json']({'message':_0x8ec9('0x50')});}})['catch'](function(_0x395211){_0x306b75(_0x395211);});});};exports[_0x8ec9('0x53')]=function(_0x350547,_0x57868f,_0x52433e){_0x350547['isMiddleware']=!![];return _0x52433e();};exports[_0x8ec9('0x54')]=function signToken(_0x3dced0){return signJwt(_0x3dced0);};exports[_0x8ec9('0x55')]=function(_0x2b148b,_0x2ad0d1){if(!_0x2b148b[_0x8ec9('0x2c')]){return _0x2ad0d1['status'](0x194)[_0x8ec9('0x35')]({'message':_0x8ec9('0x56')});}var _0x4d3e1a={'payload':{'id':_0x2b148b['user']['id'],'role':_0x2b148b[_0x8ec9('0x2c')][_0x8ec9('0x57')]},'options':{'expiresIn':0x15180}};return signJwt(_0x4d3e1a)[_0x8ec9('0x31')](function(_0x439822){_0x2ad0d1[_0x8ec9('0x58')]('motion.token',_0x439822);_0x2ad0d1[_0x8ec9('0x59')](_0x8ec9('0x5a'));})[_0x8ec9('0x37')](function(_0x4fc9e3){return _0x2ad0d1[_0x8ec9('0x32')](0x1f4)['send'](_0x4fc9e3);});};exports['retrieveApiKey']=function(_0x5751a7){if(_['isNil'](_0x5751a7['apiKeyNonce'])||_[_0x8ec9('0x5b')](_0x5751a7['apiKeyIat'])){return null;}else{return createJwt(_0x5751a7);}};exports['generateApiKey']=function(_0x3a0b05){_0x3a0b05['apiKeyNonce']=generateNonce();_0x3a0b05[_0x8ec9('0x5c')]=generateIssuedAt();return createJwt(_0x3a0b05);};exports[_0x8ec9('0x5d')]=function(_0x50c9b8,_0xf74ad4){var _0x127dea=_0x50c9b8[_0x8ec9('0x5e')][_0x8ec9('0x41')];if(_0x127dea){var _0x3020cf={'nonce':_0xf74ad4[_0x8ec9('0x47')],'iat':_0xf74ad4[_0x8ec9('0x5c')],'audience':hardwareConf[_0x8ec9('0x42')](),'issuer':hardwareConf[_0x8ec9('0x42')]()};return verifyJwt(_0x127dea,_0x3020cf)[_0x8ec9('0x31')](function(){return generateApiKey(_0xf74ad4);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0x8ec9('0x5f')]=function(_0x5de565){var _0x3e75b9=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x3e75b9[_0x8ec9('0x60')](_0x5de565))throw new db[(_0x8ec9('0x61'))][(_0x8ec9('0x62'))](_0x8ec9('0x63'));return;};exports[_0x8ec9('0x64')]=function(_0x1066c4,_0x1a4f16,_0x569aaf){var _0x323770=encryptor['decryptString'](_0x1a4f16)['split'](',');for(var _0x11786c=0x0;_0x11786c<_0x569aaf;_0x11786c++){if(!_0x323770[_0x11786c])break;if(_0x1066c4[_0x8ec9('0x65')]()===_0x323770[_0x11786c]['toLowerCase']()){var _0x3d130d=util[_0x8ec9('0x66')](_0x8ec9('0x67'),_0x569aaf);if(_0x569aaf===0x1){_0x3d130d='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db['Sequelize'][(_0x8ec9('0x62'))](_0x3d130d);}}return;};exports[_0x8ec9('0x68')]=function(_0x3dd552,_0xb50396){var _0x2a32af=_0xb50396?encryptor[_0x8ec9('0x69')](_0xb50396)['split'](','):[];if(_0x2a32af[_0x8ec9('0x6a')]===0x5){_0x2a32af[_0x8ec9('0x6b')](-0x1,0x1);}_0x2a32af[_0x8ec9('0x6c')](_0x3dd552);return encryptor[_0x8ec9('0x6d')](_0x2a32af[_0x8ec9('0x6e')](','));};function signJwt(_0x76c12d){var _0x9b9fdc=BPromise['promisify'](jwt[_0x8ec9('0x6f')],{'context':jwt});var _0x4fa0a1=_0x76c12d['secret']||config[_0x8ec9('0xb')]['session'];return new BPromise(function(_0x530cb8,_0x15dc21){_0x9b9fdc(_0x76c12d[_0x8ec9('0x70')],_0x4fa0a1,_0x76c12d[_0x8ec9('0x71')])[_0x8ec9('0x31')](function(_0xd94568){_0x530cb8(_0xd94568);})[_0x8ec9('0x37')](function(_0x51c7ca){_0x15dc21(_0x51c7ca);});});}function verifyJwt(_0x64b164,_0x5889f6,_0x43da25){var _0x388774=BPromise[_0x8ec9('0x72')](jwt['verify'],{'context':jwt});var _0x438fec=_0x43da25||config[_0x8ec9('0xb')][_0x8ec9('0xc')];return new BPromise(function(_0x546633,_0xc7be89){_0x388774(_0x64b164,_0x438fec,_0x5889f6)[_0x8ec9('0x31')](function(_0x1fe051){_0x546633(_0x1fe051);})['catch'](function(_0xc66992){_0xc7be89(_0xc66992);});});}function generateNonce(){return crypto[_0x8ec9('0x73')](0x10)[_0x8ec9('0x74')](_0x8ec9('0x75'));}function generateIssuedAt(){return Math['floor'](Date[_0x8ec9('0x76')]()/0x3e8)[_0x8ec9('0x74')]();}function createJwt(_0x488bf0){var _0x4aee57={'payload':{'iat':_0x488bf0[_0x8ec9('0x5c')],'nonce':_0x488bf0[_0x8ec9('0x47')]},'options':{'algorithm':'HS512','subject':_0x488bf0['id'][_0x8ec9('0x74')](),'issuer':hardwareConf[_0x8ec9('0x42')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x4aee57)[_0x8ec9('0x31')](function(_0x532560){return{'iat':_0x488bf0[_0x8ec9('0x5c')],'nonce':_0x488bf0['apiKeyNonce'],'token':_0x532560};});}