Built motion from commit (unavailable).|2.4.21
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x1d7c=['getUuid','promisify','sign','secret','payload','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','lodash','basic-auth','crypto','bluebird','secrets','session','role','fullname','name','internal','email','userpic','permissions','md5secret','voicePause','mailPause','pauseType','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','alias','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','isChatInteractionAuthorized','use','user','ChatInteraction','findOne','params','closed','disposition','then','status','unmanaged','json','Forbidden.','isAuthenticated','headers','authorization','User','authenticate','Wrong\x20credentials.','catch','Bearer','Unknown\x20authorization\x20format','query','apikey','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','find','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','motion.token','redirect','/dashboards/general','retrieveApiKey','isNil','apiKeyNonce','apiKeyIat','generateApiKey'];(function(_0x29c01c,_0x55d008){var _0x4377d4=function(_0x164989){while(--_0x164989){_0x29c01c['push'](_0x29c01c['shift']());}};_0x4377d4(++_0x55d008);}(_0x1d7c,0xc0));var _0xc1d7=function(_0xc471d2,_0x26ab16){_0xc471d2=_0xc471d2-0x0;var _0x334c68=_0x1d7c[_0xc471d2];return _0x334c68;};'use strict';var db=require(_0xc1d7('0x0'))['db'];var config=require(_0xc1d7('0x1'));var hardwareConf=require(_0xc1d7('0x2'));var _=require(_0xc1d7('0x3'));var jwt=require('jsonwebtoken');var expressJwt=require('express-jwt');var compose=require('composable-middleware');var basicAuth=require(_0xc1d7('0x4'));var crypto=require(_0xc1d7('0x5'));var BPromise=require(_0xc1d7('0x6'));var validateJwt=expressJwt({'secret':config[_0xc1d7('0x7')][_0xc1d7('0x8')]});var userAttributes=['id',_0xc1d7('0x9'),_0xc1d7('0xa'),_0xc1d7('0xb'),_0xc1d7('0xc'),_0xc1d7('0xd'),_0xc1d7('0xe'),_0xc1d7('0xf'),_0xc1d7('0x10'),_0xc1d7('0x11'),'chatPause',_0xc1d7('0x12'),'faxPause','smsPause','openchannelPause',_0xc1d7('0x13'),'showWebBar',_0xc1d7('0x14'),_0xc1d7('0x15'),_0xc1d7('0x16'),_0xc1d7('0x17'),'passwordResetAt',_0xc1d7('0x18'),'phoneBarAutoAnswer',_0xc1d7('0x19'),_0xc1d7('0x1a'),_0xc1d7('0x1b'),'phoneBarEnableDtmfTone','phoneBarEnableSettings',_0xc1d7('0x1c'),_0xc1d7('0x1d'),_0xc1d7('0x1e'),_0xc1d7('0x1f'),_0xc1d7('0x20'),_0xc1d7('0x21'),_0xc1d7('0x22')];exports[_0xc1d7('0x23')]=function(){return this['isAuthenticated'](!![])[_0xc1d7('0x24')](function(_0x55c389,_0x232425,_0x3451e0){if(_0x55c389[_0xc1d7('0x25')]){_0x3451e0();}else{return db[_0xc1d7('0x26')][_0xc1d7('0x27')]({'where':{'id':_0x55c389[_0xc1d7('0x28')]['id']},'attributes':['id',_0xc1d7('0x29'),_0xc1d7('0x2a')],'raw':!![]})[_0xc1d7('0x2b')](function(_0x31de0d){if(_0x31de0d&&_0x31de0d[_0xc1d7('0x29')]){return _0x232425[_0xc1d7('0x2c')](_0x31de0d['disposition']===_0xc1d7('0x2d')?0x195:0x193)[_0xc1d7('0x2e')]({'message':_0x31de0d['disposition']===_0xc1d7('0x2d')?'Unmanaged.':_0xc1d7('0x2f')});}else{_0x3451e0();}})['catch'](function(_0x1eb9ff){_0x3451e0(_0x1eb9ff);});}});};exports[_0xc1d7('0x30')]=function isAuthenticated(_0x52fab9){return compose()['use'](function(_0x5509eb,_0x1c3e49,_0x1a286d){if(_0x5509eb[_0xc1d7('0x31')][_0xc1d7('0x32')]){if(_['startsWith'](_0x5509eb[_0xc1d7('0x31')][_0xc1d7('0x32')],'Basic')){var _0x2d58a9=basicAuth(_0x5509eb);db[_0xc1d7('0x33')]['find']({'where':{'name':_0x2d58a9[_0xc1d7('0xb')]}})['then'](function(_0xbaf5f5){if(!_0xbaf5f5||!_0xbaf5f5[_0xc1d7('0x34')](_0x2d58a9['pass'])){return _0x1c3e49[_0xc1d7('0x2c')](0x191)[_0xc1d7('0x2e')]({'message':_0xc1d7('0x35')});}_0x5509eb[_0xc1d7('0x25')]={'id':_0xbaf5f5['id']};_0x1a286d();})[_0xc1d7('0x36')](function(_0x211ad6){_0x1a286d(_0x211ad6);});}else if(_['startsWith'](_0x5509eb[_0xc1d7('0x31')][_0xc1d7('0x32')],_0xc1d7('0x37'))){validateJwt(_0x5509eb,_0x1c3e49,_0x1a286d);}else{if(_0x52fab9){_0x1a286d();}else{return _0x1c3e49['status'](0x193)[_0xc1d7('0x2e')]({'message':_0xc1d7('0x38')});}}}else if(_0x5509eb[_0xc1d7('0x39')]['apikey']){try{var _0x3a9a0b={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x5509eb[_0xc1d7('0x39')][_0xc1d7('0x3a')],_0x3a9a0b)[_0xc1d7('0x2b')](function(_0x3f7c31){return db[_0xc1d7('0x33')]['find']({'where':{'id':_0x3f7c31['sub']}})[_0xc1d7('0x2b')](function(_0x70a009){if(!_0x70a009||!_['isEqual'](_0x70a009['apiKeyNonce'],_0x3f7c31[_0xc1d7('0x3b')])){return _0x1c3e49[_0xc1d7('0x2c')](0x191)[_0xc1d7('0x2e')]({'message':_0xc1d7('0x3c')});}_0x5509eb[_0xc1d7('0x25')]={'id':_0x70a009['id']};_0x1a286d();});})['catch'](function(){return _0x1c3e49['status'](0x191)['json']({'message':_0xc1d7('0x3d')});});}catch(_0x5c5522){_0x1a286d(_0x5c5522);}}else if(_0x52fab9){_0x1a286d();}else{return _0x1c3e49['status'](0x193)[_0xc1d7('0x2e')]({'message':_0xc1d7('0x38')});}})[_0xc1d7('0x24')](function(_0x189179,_0x48d13e,_0x22c70e){if(_0x189179[_0xc1d7('0x25')]){db['User'][_0xc1d7('0x3e')]({'where':{'id':_0x189179[_0xc1d7('0x25')]['id']},'attributes':userAttributes})['then'](function(_0x5d8c2f){if(!_0x5d8c2f){return _0x48d13e[_0xc1d7('0x2c')](0x194)[_0xc1d7('0x2e')]({'message':_0xc1d7('0x3f')});}_0x189179[_0xc1d7('0x25')]=_0x5d8c2f;_0x22c70e();})['catch'](function(_0x48a357){_0x22c70e(_0x48a357);});}else if(_0x52fab9){_0x22c70e();}else{return _0x48d13e[_0xc1d7('0x2c')](0x194)['json']({'message':_0xc1d7('0x40')});}});};exports[_0xc1d7('0x41')]=function canUpdate(){return compose()['use'](function(_0xc81cf,_0x59e600,_0x239633){return require('../../config/license/util')[_0xc1d7('0x42')]()[_0xc1d7('0x2b')](function(_0x4b8797){if(_0x4b8797[_0xc1d7('0x43')]){_0x239633();}else{return _0x59e600[_0xc1d7('0x2c')](0x193)[_0xc1d7('0x2e')]({'message':_0xc1d7('0x44')});}})[_0xc1d7('0x36')](function(_0x52b67b){_0x239633(_0x52b67b);});});};exports[_0xc1d7('0x45')]=function(_0x5d28ec,_0x3756ee,_0xbf877c){_0x5d28ec[_0xc1d7('0x45')]=!![];return _0xbf877c();};exports[_0xc1d7('0x46')]=function signToken(_0x1feca7){return signJwt(_0x1feca7);};exports[_0xc1d7('0x47')]=function(_0x2dcda0,_0xb7d2c8){if(!_0x2dcda0[_0xc1d7('0x25')]){return _0xb7d2c8[_0xc1d7('0x2c')](0x194)[_0xc1d7('0x2e')]({'message':_0xc1d7('0x48')});}var _0x2187f3={'payload':{'id':_0x2dcda0[_0xc1d7('0x25')]['id'],'role':_0x2dcda0[_0xc1d7('0x25')][_0xc1d7('0x9')]},'options':{'expiresIn':0x15180}};return signJwt(_0x2187f3)[_0xc1d7('0x2b')](function(_0x1b0d6b){_0xb7d2c8['cookie'](_0xc1d7('0x49'),_0x1b0d6b);_0xb7d2c8[_0xc1d7('0x4a')](_0xc1d7('0x4b'));})['catch'](function(_0x471f9){return _0xb7d2c8[_0xc1d7('0x2c')](0x1f4)['send'](_0x471f9);});};exports[_0xc1d7('0x4c')]=function(_0x3d7cbe){if(_[_0xc1d7('0x4d')](_0x3d7cbe[_0xc1d7('0x4e')])||_[_0xc1d7('0x4d')](_0x3d7cbe[_0xc1d7('0x4f')])){return null;}else{return createJwt(_0x3d7cbe);}};exports[_0xc1d7('0x50')]=function(_0x4c0d9f){_0x4c0d9f[_0xc1d7('0x4e')]=generateNonce();_0x4c0d9f[_0xc1d7('0x4f')]=generateIssuedAt();return createJwt(_0x4c0d9f);};exports['regenerateApiKey']=function(_0x2d17c3,_0x428f49){var _0x7acbde=_0x2d17c3['query'][_0xc1d7('0x3a')];if(_0x7acbde){var _0x8f7249={'nonce':_0x428f49[_0xc1d7('0x4e')],'iat':_0x428f49['apiKeyIat'],'audience':hardwareConf[_0xc1d7('0x51')](),'issuer':hardwareConf[_0xc1d7('0x51')]()};return verifyJwt(_0x7acbde,_0x8f7249)[_0xc1d7('0x2b')](function(){return generateApiKey(_0x428f49);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};function signJwt(_0x50a5e9){var _0x2a17f7=BPromise[_0xc1d7('0x52')](jwt[_0xc1d7('0x53')],{'context':jwt});var _0x2b759c=_0x50a5e9[_0xc1d7('0x54')]||config[_0xc1d7('0x7')][_0xc1d7('0x8')];return new BPromise(function(_0x4beeac,_0xf2f4b1){_0x2a17f7(_0x50a5e9[_0xc1d7('0x55')],_0x2b759c,_0x50a5e9['options'])['then'](function(_0x21e1f5){_0x4beeac(_0x21e1f5);})[_0xc1d7('0x36')](function(_0x49d1f2){_0xf2f4b1(_0x49d1f2);});});}function verifyJwt(_0x2f44cd,_0x46179c,_0x5b5b30){var _0x3b51a0=BPromise[_0xc1d7('0x52')](jwt['verify'],{'context':jwt});var _0x3fb019=_0x5b5b30||config[_0xc1d7('0x7')][_0xc1d7('0x8')];return new BPromise(function(_0x3c3a75,_0x52797c){_0x3b51a0(_0x2f44cd,_0x3fb019,_0x46179c)['then'](function(_0xb36ddd){_0x3c3a75(_0xb36ddd);})[_0xc1d7('0x36')](function(_0x7fc648){_0x52797c(_0x7fc648);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0xc1d7('0x56')](_0xc1d7('0x57'));}function generateIssuedAt(){return Math[_0xc1d7('0x58')](Date[_0xc1d7('0x59')]()/0x3e8)[_0xc1d7('0x56')]();}function createJwt(_0x1aadaa){var _0x469c6e={'payload':{'iat':_0x1aadaa[_0xc1d7('0x4f')],'nonce':_0x1aadaa[_0xc1d7('0x4e')]},'options':{'algorithm':_0xc1d7('0x5a'),'subject':_0x1aadaa['id'][_0xc1d7('0x56')](),'issuer':hardwareConf[_0xc1d7('0x51')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x469c6e)[_0xc1d7('0x2b')](function(_0x9404d7){return{'iat':_0x1aadaa[_0xc1d7('0x4f')],'nonce':_0x1aadaa['apiKeyNonce'],'token':_0x9404d7};});}