Built motion from commit 753c950e.|2.5.42
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xb323=['authorization','startsWith','Basic','find','authenticate','pass','json','Wrong\x20credentials.','user','catch','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','User','sub','Setting','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','update','Forbidden','isWebrtcLicence','getLicense','webrtc','isMiddleware','signToken','setTokenCookie','cookie','motion.token','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','validatePasswordHistory','split','toLowerCase','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','ValidationError','updatePasswordsHistory','decryptString','length','splice','unshift','encryptString','join','payload','verify','randomBytes','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util','moment','secrets','session','role','internal','email','userpic','permissions','md5secret','voicePause','chatPause','faxPause','openchannelPause','pauseType','showWebBar','lastLoginAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','privacyEnabled','settingsEnabled','wssPort','downloadVoiceRecordings','downloadAttachments','ignorePauseForPreviewCalls','selectRecallMeCampaign','isChatInteractionAuthorized','isAuthenticated','use','findOne','closed','disposition','then','status','unmanaged','Unmanaged.','headers'];(function(_0x542305,_0x331f9d){var _0xe21aa9=function(_0x22f7cd){while(--_0x22f7cd){_0x542305['push'](_0x542305['shift']());}};_0xe21aa9(++_0x331f9d);}(_0xb323,0x14c));var _0x3b32=function(_0x556a16,_0x1de76c){_0x556a16=_0x556a16-0x0;var _0x42fb08=_0xb323[_0x556a16];return _0x42fb08;};'use strict';var db=require(_0x3b32('0x0'))['db'];var config=require(_0x3b32('0x1'));var hardwareConf=require(_0x3b32('0x2'));var licenseUtil=require('../../config/license/util');var encryptor=require('../encryptor');var _=require(_0x3b32('0x3'));var jwt=require(_0x3b32('0x4'));var expressJwt=require(_0x3b32('0x5'));var compose=require(_0x3b32('0x6'));var basicAuth=require(_0x3b32('0x7'));var crypto=require(_0x3b32('0x8'));var BPromise=require(_0x3b32('0x9'));var util=require(_0x3b32('0xa'));var moment=require(_0x3b32('0xb'));var validateJwt=expressJwt({'secret':config[_0x3b32('0xc')][_0x3b32('0xd')]});var userAttributes=['id',_0x3b32('0xe'),'fullname','name',_0x3b32('0xf'),_0x3b32('0x10'),_0x3b32('0x11'),_0x3b32('0x12'),_0x3b32('0x13'),_0x3b32('0x14'),_0x3b32('0x15'),'mailPause',_0x3b32('0x16'),'smsPause',_0x3b32('0x17'),_0x3b32('0x18'),_0x3b32('0x19'),_0x3b32('0x1a'),'lastPauseAt',_0x3b32('0x1b'),_0x3b32('0x1c'),_0x3b32('0x1d'),_0x3b32('0x1e'),_0x3b32('0x1f'),_0x3b32('0x20'),'phoneBarDnd',_0x3b32('0x21'),_0x3b32('0x22'),_0x3b32('0x23'),'phoneBarExpires',_0x3b32('0x24'),_0x3b32('0x25'),_0x3b32('0x26'),_0x3b32('0x27'),'interface','userProfileId',_0x3b32('0x28'),_0x3b32('0x29'),_0x3b32('0x2a'),_0x3b32('0x2b'),'downloadOmnichannelInteractions',_0x3b32('0x2c'),_0x3b32('0x2d'),_0x3b32('0x2e')];exports[_0x3b32('0x2f')]=function(){return this[_0x3b32('0x30')](!![])[_0x3b32('0x31')](function(_0x398c54,_0x4b11eb,_0x16cea4){if(_0x398c54['user']){_0x16cea4();}else{return db['ChatInteraction'][_0x3b32('0x32')]({'where':{'id':_0x398c54['params']['id']},'attributes':['id',_0x3b32('0x33'),_0x3b32('0x34')],'raw':!![]})[_0x3b32('0x35')](function(_0x180eb7){if(_0x180eb7&&_0x180eb7[_0x3b32('0x33')]){return _0x4b11eb[_0x3b32('0x36')](_0x180eb7[_0x3b32('0x34')]==='unmanaged'?0x195:0x193)['json']({'message':_0x180eb7[_0x3b32('0x34')]===_0x3b32('0x37')?_0x3b32('0x38'):'Forbidden.'});}else{_0x16cea4();}})['catch'](function(_0x3bf15c){_0x16cea4(_0x3bf15c);});}});};exports['isAuthenticated']=function isAuthenticated(_0x5d3849){return compose()[_0x3b32('0x31')](function(_0x27dfb4,_0x50bf9b,_0x538f54){var _0x40a106;if(_0x27dfb4[_0x3b32('0x39')][_0x3b32('0x3a')]){if(_[_0x3b32('0x3b')](_0x27dfb4[_0x3b32('0x39')][_0x3b32('0x3a')],_0x3b32('0x3c'))){var _0x2a6fb0=basicAuth(_0x27dfb4);db['User'][_0x3b32('0x3d')]({'where':{'name':_0x2a6fb0['name']}})[_0x3b32('0x35')](function(_0x18a6bd){if(!_0x18a6bd||!_0x18a6bd[_0x3b32('0x3e')](_0x2a6fb0[_0x3b32('0x3f')])){return _0x50bf9b['status'](0x191)[_0x3b32('0x40')]({'message':_0x3b32('0x41')});}_0x27dfb4[_0x3b32('0x42')]={'id':_0x18a6bd['id']};_0x538f54();})[_0x3b32('0x43')](function(_0x100915){_0x538f54(_0x100915);});}else if(_['startsWith'](_0x27dfb4[_0x3b32('0x39')][_0x3b32('0x3a')],_0x3b32('0x44'))){validateJwt(_0x27dfb4,_0x50bf9b,_0x538f54);}else{if(_0x5d3849){_0x538f54();}else{return _0x50bf9b[_0x3b32('0x36')](0x193)[_0x3b32('0x40')]({'message':_0x3b32('0x45')});}}}else if(_0x27dfb4[_0x3b32('0x46')][_0x3b32('0x47')]){try{var _0x6fac64={'audience':hardwareConf[_0x3b32('0x48')](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x27dfb4[_0x3b32('0x46')][_0x3b32('0x47')],_0x6fac64)[_0x3b32('0x35')](function(_0x196073){return db[_0x3b32('0x49')][_0x3b32('0x3d')]({'where':{'id':_0x196073[_0x3b32('0x4a')]}})[_0x3b32('0x35')](function(_0xccfb54){_0x40a106=_0xccfb54;return db[_0x3b32('0x4b')][_0x3b32('0x32')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts',_0x3b32('0x4c')],'raw':!![]});})['then'](function(_0x45740e){if(!_0x40a106||!_[_0x3b32('0x4d')](_0x40a106[_0x3b32('0x4e')],_0x196073[_0x3b32('0x4f')])){return _0x50bf9b[_0x3b32('0x36')](0x191)[_0x3b32('0x40')]({'message':_0x3b32('0x50')});}if(_0x40a106[_0x3b32('0x51')]){return _0x50bf9b['status'](0x191)[_0x3b32('0x40')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x40a106[_0x3b32('0x52')]){if(_0x45740e[_0x3b32('0x4c')]>0x0){if(moment(_0x40a106[_0x3b32('0x53')])[_0x3b32('0x54')](_0x45740e['blockDuration'],_0x3b32('0x55'))>moment()){return _0x50bf9b[_0x3b32('0x36')](0x191)[_0x3b32('0x40')]({'message':_0x3b32('0x56')});}}else{return _0x50bf9b[_0x3b32('0x36')](0x191)[_0x3b32('0x40')]({'message':_0x3b32('0x56')});}}_0x27dfb4[_0x3b32('0x42')]={'id':_0x40a106['id']};_0x538f54();});})[_0x3b32('0x43')](function(){return _0x50bf9b[_0x3b32('0x36')](0x191)[_0x3b32('0x40')]({'message':_0x3b32('0x56')});});}catch(_0x20d971){_0x538f54(_0x20d971);}}else if(_0x5d3849){_0x538f54();}else{return _0x50bf9b[_0x3b32('0x36')](0x193)[_0x3b32('0x40')]({'message':_0x3b32('0x45')});}})[_0x3b32('0x31')](function(_0x389006,_0x2169fc,_0x2deca8){if(_0x389006[_0x3b32('0x42')]){db[_0x3b32('0x49')][_0x3b32('0x3d')]({'where':{'id':_0x389006['user']['id']},'attributes':userAttributes})[_0x3b32('0x35')](function(_0x30d759){if(!_0x30d759){return _0x2169fc[_0x3b32('0x36')](0x194)[_0x3b32('0x40')]({'message':_0x3b32('0x57')});}_0x389006[_0x3b32('0x42')]=_0x30d759;_0x2deca8();})[_0x3b32('0x43')](function(_0x414b6f){_0x2deca8(_0x414b6f);});}else if(_0x5d3849){_0x2deca8();}else{return _0x2169fc[_0x3b32('0x36')](0x194)[_0x3b32('0x40')]({'message':_0x3b32('0x58')});}});};exports[_0x3b32('0x59')]=function canUpdate(){return compose()[_0x3b32('0x31')](function(_0x4790fa,_0x207bd0,_0x4a1f3e){return licenseUtil['getLicense']()[_0x3b32('0x35')](function(_0x1e6ad5){if(_0x1e6ad5[_0x3b32('0x5a')]){_0x4a1f3e();}else{return _0x207bd0[_0x3b32('0x36')](0x193)[_0x3b32('0x40')]({'message':_0x3b32('0x5b')});}})[_0x3b32('0x43')](function(_0x23d0a1){_0x4a1f3e(_0x23d0a1);});});};exports[_0x3b32('0x5c')]=function isWebrtcLicence(){return compose()[_0x3b32('0x31')](function(_0x26fc17,_0x34f5bb,_0x7bd625){return licenseUtil[_0x3b32('0x5d')]()['then'](function(_0x4d7ff1){if(_0x4d7ff1[_0x3b32('0x5e')]){_0x7bd625();}else{return _0x34f5bb[_0x3b32('0x36')](0x193)[_0x3b32('0x40')]({'message':_0x3b32('0x5b')});}})[_0x3b32('0x43')](function(_0x3bf71c){_0x7bd625(_0x3bf71c);});});};exports[_0x3b32('0x5f')]=function(_0x387c4d,_0x21047f,_0x1afb22){_0x387c4d[_0x3b32('0x5f')]=!![];return _0x1afb22();};exports[_0x3b32('0x60')]=function signToken(_0x520bb7){return signJwt(_0x520bb7);};exports[_0x3b32('0x61')]=function(_0x1f0f6e,_0x3ddf84){if(!_0x1f0f6e[_0x3b32('0x42')]){return _0x3ddf84['status'](0x194)[_0x3b32('0x40')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x55f1ae={'payload':{'id':_0x1f0f6e[_0x3b32('0x42')]['id'],'role':_0x1f0f6e['user']['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x55f1ae)[_0x3b32('0x35')](function(_0x1a1b52){_0x3ddf84[_0x3b32('0x62')](_0x3b32('0x63'),_0x1a1b52);_0x3ddf84['redirect'](_0x3b32('0x64'));})[_0x3b32('0x43')](function(_0x36e3c7){return _0x3ddf84[_0x3b32('0x36')](0x1f4)[_0x3b32('0x65')](_0x36e3c7);});};exports[_0x3b32('0x66')]=function(_0x5c8f1d){if(_[_0x3b32('0x67')](_0x5c8f1d[_0x3b32('0x4e')])||_[_0x3b32('0x67')](_0x5c8f1d[_0x3b32('0x68')])){return null;}else{return createJwt(_0x5c8f1d);}};exports['generateApiKey']=function(_0x22f867){_0x22f867[_0x3b32('0x4e')]=generateNonce();_0x22f867[_0x3b32('0x68')]=generateIssuedAt();return createJwt(_0x22f867);};exports[_0x3b32('0x69')]=function(_0x171783,_0x1bc31b){var _0x18bf1d=_0x171783[_0x3b32('0x46')][_0x3b32('0x47')];if(_0x18bf1d){var _0x5197c5={'nonce':_0x1bc31b[_0x3b32('0x4e')],'iat':_0x1bc31b['apiKeyIat'],'audience':hardwareConf[_0x3b32('0x48')](),'issuer':hardwareConf['getUuid']()};return verifyJwt(_0x18bf1d,_0x5197c5)['then'](function(){return generateApiKey(_0x1bc31b);});}else{throw{'message':_0x3b32('0x6a')};}};exports[_0x3b32('0x6b')]=function(_0x54c67e){var _0x4ee37b=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x4ee37b[_0x3b32('0x6c')](_0x54c67e))throw new db[(_0x3b32('0x6d'))]['ValidationError']('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x3b32('0x6e')]=function(_0x8f4325,_0x2a2275,_0x146c93){var _0x1dc5aa=encryptor['decryptString'](_0x2a2275)[_0x3b32('0x6f')](',');for(var _0x3de72c=0x0;_0x3de72c<_0x146c93;_0x3de72c++){if(!_0x1dc5aa[_0x3de72c])break;if(_0x8f4325[_0x3b32('0x70')]()===_0x1dc5aa[_0x3de72c][_0x3b32('0x70')]()){var _0x152ca1=util['format'](_0x3b32('0x71'),_0x146c93);if(_0x146c93===0x1){_0x152ca1='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x3b32('0x6d'))][(_0x3b32('0x72'))](_0x152ca1);}}return;};exports[_0x3b32('0x73')]=function(_0x3edc91,_0x28142d){var _0x3a6e5a=_0x28142d?encryptor[_0x3b32('0x74')](_0x28142d)['split'](','):[];if(_0x3a6e5a[_0x3b32('0x75')]===0x5){_0x3a6e5a[_0x3b32('0x76')](-0x1,0x1);}_0x3a6e5a[_0x3b32('0x77')](_0x3edc91);return encryptor[_0x3b32('0x78')](_0x3a6e5a[_0x3b32('0x79')](','));};function signJwt(_0x4e426a){var _0x4d5d8b=BPromise['promisify'](jwt['sign'],{'context':jwt});var _0x4e63c7=_0x4e426a['secret']||config['secrets'][_0x3b32('0xd')];return new BPromise(function(_0x143452,_0x5553b5){_0x4d5d8b(_0x4e426a[_0x3b32('0x7a')],_0x4e63c7,_0x4e426a['options'])[_0x3b32('0x35')](function(_0x14fded){_0x143452(_0x14fded);})[_0x3b32('0x43')](function(_0x55156e){_0x5553b5(_0x55156e);});});}function verifyJwt(_0x3c65ec,_0x35ac39,_0x2a778a){var _0x1dc90a=BPromise['promisify'](jwt[_0x3b32('0x7b')],{'context':jwt});var _0x2a482d=_0x2a778a||config['secrets'][_0x3b32('0xd')];return new BPromise(function(_0x5f3da9,_0x4e1dda){_0x1dc90a(_0x3c65ec,_0x2a482d,_0x35ac39)[_0x3b32('0x35')](function(_0x3b9c5e){_0x5f3da9(_0x3b9c5e);})[_0x3b32('0x43')](function(_0x1719c5){_0x4e1dda(_0x1719c5);});});}function generateNonce(){return crypto[_0x3b32('0x7c')](0x10)[_0x3b32('0x7d')](_0x3b32('0x7e'));}function generateIssuedAt(){return Math[_0x3b32('0x7f')](Date[_0x3b32('0x80')]()/0x3e8)[_0x3b32('0x7d')]();}function createJwt(_0x1d214b){var _0x129566={'payload':{'iat':_0x1d214b[_0x3b32('0x68')],'nonce':_0x1d214b[_0x3b32('0x4e')]},'options':{'algorithm':_0x3b32('0x81'),'subject':_0x1d214b['id']['toString'](),'issuer':hardwareConf[_0x3b32('0x48')](),'audience':hardwareConf[_0x3b32('0x48')]()}};return signJwt(_0x129566)[_0x3b32('0x35')](function(_0xf2ce5d){return{'iat':_0x1d214b[_0x3b32('0x68')],'nonce':_0x1d214b[_0x3b32('0x4e')],'token':_0xf2ce5d};});}