Built motion from commit ddca4d0d.|2.5.47
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xb07d=['The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','splice','unshift','encryptString','promisify','sign','secret','session','payload','options','verify','randomBytes','toString','hex','floor','now','HS512','../../config/license/util','../encryptor','lodash','jsonwebtoken','basic-auth','crypto','util','moment','secrets','role','fullname','name','internal','userpic','permissions','voicePause','mailPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','interface','privacyEnabled','settingsEnabled','downloadVoiceRecordings','downloadOmnichannelInteractions','ignorePauseForPreviewCalls','selectRecallMeCampaign','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','then','status','unmanaged','Unmanaged.','Forbidden.','catch','authorization','headers','Basic','find','authenticate','pass','json','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','User','sub','Setting','allowedLoginAttempts','blockDuration','apiKeyNonce','nonce','disabled','Invalid\x20API\x20access\x20key','add','minutes','User\x20not\x20found.','canUpdate','getLicense','update','webrtc','Forbidden','isMiddleware','signToken','cookie','motion.token','redirect','/dashboards/general','send','apiKeyIat','generateApiKey','regenerateApiKey','validatePasswordPattern','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','decryptString','split','toLowerCase'];(function(_0x58952f,_0xeed25f){var _0x3217ca=function(_0x3fda09){while(--_0x3fda09){_0x58952f['push'](_0x58952f['shift']());}};_0x3217ca(++_0xeed25f);}(_0xb07d,0x185));var _0xdb07=function(_0x3066cf,_0x1b40ee){_0x3066cf=_0x3066cf-0x0;var _0x1f1a60=_0xb07d[_0x3066cf];return _0x1f1a60;};'use strict';var db=require('../../mysqldb')['db'];var config=require('../../config/environment');var hardwareConf=require('../../config/license/hardware');var licenseUtil=require(_0xdb07('0x0'));var encryptor=require(_0xdb07('0x1'));var _=require(_0xdb07('0x2'));var jwt=require(_0xdb07('0x3'));var expressJwt=require('express-jwt');var compose=require('composable-middleware');var basicAuth=require(_0xdb07('0x4'));var crypto=require(_0xdb07('0x5'));var BPromise=require('bluebird');var util=require(_0xdb07('0x6'));var moment=require(_0xdb07('0x7'));var validateJwt=expressJwt({'secret':config[_0xdb07('0x8')]['session']});var userAttributes=['id',_0xdb07('0x9'),_0xdb07('0xa'),_0xdb07('0xb'),_0xdb07('0xc'),'email',_0xdb07('0xd'),_0xdb07('0xe'),'md5secret',_0xdb07('0xf'),'chatPause',_0xdb07('0x10'),'faxPause',_0xdb07('0x11'),_0xdb07('0x12'),_0xdb07('0x13'),_0xdb07('0x14'),_0xdb07('0x15'),_0xdb07('0x16'),_0xdb07('0x17'),_0xdb07('0x18'),_0xdb07('0x19'),_0xdb07('0x1a'),_0xdb07('0x1b'),_0xdb07('0x1c'),_0xdb07('0x1d'),_0xdb07('0x1e'),'phoneBarEnableDtmfTone','phoneBarEnableSettings',_0xdb07('0x1f'),_0xdb07('0x20'),_0xdb07('0x21'),'phoneBarRemoteControlPort','hotdesk',_0xdb07('0x22'),'userProfileId',_0xdb07('0x23'),_0xdb07('0x24'),'wssPort',_0xdb07('0x25'),_0xdb07('0x26'),'downloadAttachments',_0xdb07('0x27'),_0xdb07('0x28')];exports[_0xdb07('0x29')]=function(){return this[_0xdb07('0x2a')](!![])[_0xdb07('0x2b')](function(_0x2e8855,_0x4dd616,_0x2119ec){if(_0x2e8855[_0xdb07('0x2c')]){_0x2119ec();}else{return db[_0xdb07('0x2d')][_0xdb07('0x2e')]({'where':{'id':_0x2e8855[_0xdb07('0x2f')]['id']},'attributes':['id',_0xdb07('0x30'),_0xdb07('0x31')],'raw':!![]})[_0xdb07('0x32')](function(_0x111593){if(_0x111593&&_0x111593[_0xdb07('0x30')]){return _0x4dd616[_0xdb07('0x33')](_0x111593[_0xdb07('0x31')]==='unmanaged'?0x195:0x193)['json']({'message':_0x111593['disposition']===_0xdb07('0x34')?_0xdb07('0x35'):_0xdb07('0x36')});}else{_0x2119ec();}})[_0xdb07('0x37')](function(_0x39a7ff){_0x2119ec(_0x39a7ff);});}});};exports[_0xdb07('0x2a')]=function isAuthenticated(_0x31b14d){return compose()[_0xdb07('0x2b')](function(_0x4a287c,_0x197aec,_0x2587a2){var _0x6ee434;if(_0x4a287c['headers'][_0xdb07('0x38')]){if(_['startsWith'](_0x4a287c[_0xdb07('0x39')][_0xdb07('0x38')],_0xdb07('0x3a'))){var _0x237577=basicAuth(_0x4a287c);db['User'][_0xdb07('0x3b')]({'where':{'name':_0x237577[_0xdb07('0xb')]}})[_0xdb07('0x32')](function(_0x2539b4){if(!_0x2539b4||!_0x2539b4[_0xdb07('0x3c')](_0x237577[_0xdb07('0x3d')])){return _0x197aec['status'](0x191)[_0xdb07('0x3e')]({'message':_0xdb07('0x3f')});}_0x4a287c[_0xdb07('0x2c')]={'id':_0x2539b4['id']};_0x2587a2();})[_0xdb07('0x37')](function(_0x16104f){_0x2587a2(_0x16104f);});}else if(_['startsWith'](_0x4a287c[_0xdb07('0x39')][_0xdb07('0x38')],_0xdb07('0x40'))){validateJwt(_0x4a287c,_0x197aec,_0x2587a2);}else{if(_0x31b14d){_0x2587a2();}else{return _0x197aec[_0xdb07('0x33')](0x193)[_0xdb07('0x3e')]({'message':_0xdb07('0x41')});}}}else if(_0x4a287c[_0xdb07('0x42')]['apikey']){try{var _0x296381={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0xdb07('0x43')]()};verifyJwt(_0x4a287c[_0xdb07('0x42')][_0xdb07('0x44')],_0x296381)[_0xdb07('0x32')](function(_0x7b3e37){return db[_0xdb07('0x45')][_0xdb07('0x3b')]({'where':{'id':_0x7b3e37[_0xdb07('0x46')]}})[_0xdb07('0x32')](function(_0x52dc4f){_0x6ee434=_0x52dc4f;return db[_0xdb07('0x47')][_0xdb07('0x2e')]({'where':{'id':0x1},'attributes':[_0xdb07('0x48'),_0xdb07('0x49')],'raw':!![]});})[_0xdb07('0x32')](function(_0x5ca224){if(!_0x6ee434||!_['isEqual'](_0x6ee434[_0xdb07('0x4a')],_0x7b3e37[_0xdb07('0x4b')])){return _0x197aec[_0xdb07('0x33')](0x191)['json']({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x6ee434[_0xdb07('0x4c')]){return _0x197aec[_0xdb07('0x33')](0x191)['json']({'message':_0xdb07('0x4d')});}if(_0x6ee434['blocked']){if(_0x5ca224[_0xdb07('0x49')]>0x0){if(moment(_0x6ee434['blockedAt'])[_0xdb07('0x4e')](_0x5ca224['blockDuration'],_0xdb07('0x4f'))>moment()){return _0x197aec[_0xdb07('0x33')](0x191)[_0xdb07('0x3e')]({'message':_0xdb07('0x4d')});}}else{return _0x197aec[_0xdb07('0x33')](0x191)[_0xdb07('0x3e')]({'message':_0xdb07('0x4d')});}}_0x4a287c[_0xdb07('0x2c')]={'id':_0x6ee434['id']};_0x2587a2();});})['catch'](function(){return _0x197aec[_0xdb07('0x33')](0x191)[_0xdb07('0x3e')]({'message':_0xdb07('0x4d')});});}catch(_0xbf7dea){_0x2587a2(_0xbf7dea);}}else if(_0x31b14d){_0x2587a2();}else{return _0x197aec[_0xdb07('0x33')](0x193)[_0xdb07('0x3e')]({'message':_0xdb07('0x41')});}})[_0xdb07('0x2b')](function(_0xb7c9bf,_0x352159,_0x431902){if(_0xb7c9bf['user']){db[_0xdb07('0x45')][_0xdb07('0x3b')]({'where':{'id':_0xb7c9bf[_0xdb07('0x2c')]['id']},'attributes':userAttributes})[_0xdb07('0x32')](function(_0x2d3d64){if(!_0x2d3d64){return _0x352159[_0xdb07('0x33')](0x194)[_0xdb07('0x3e')]({'message':_0xdb07('0x50')});}_0xb7c9bf[_0xdb07('0x2c')]=_0x2d3d64;_0x431902();})[_0xdb07('0x37')](function(_0x9c4a71){_0x431902(_0x9c4a71);});}else if(_0x31b14d){_0x431902();}else{return _0x352159[_0xdb07('0x33')](0x194)[_0xdb07('0x3e')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0xdb07('0x51')]=function canUpdate(){return compose()[_0xdb07('0x2b')](function(_0x4fc605,_0x29f86f,_0x1c7188){return licenseUtil[_0xdb07('0x52')]()[_0xdb07('0x32')](function(_0x549d82){if(_0x549d82[_0xdb07('0x53')]){_0x1c7188();}else{return _0x29f86f[_0xdb07('0x33')](0x193)['json']({'message':'Forbidden'});}})[_0xdb07('0x37')](function(_0x35e680){_0x1c7188(_0x35e680);});});};exports['isWebrtcLicence']=function isWebrtcLicence(){return compose()[_0xdb07('0x2b')](function(_0x1e9728,_0x15da49,_0x333728){return licenseUtil['getLicense']()[_0xdb07('0x32')](function(_0x5f289e){if(_0x5f289e[_0xdb07('0x54')]){_0x333728();}else{return _0x15da49[_0xdb07('0x33')](0x193)[_0xdb07('0x3e')]({'message':_0xdb07('0x55')});}})[_0xdb07('0x37')](function(_0x1d82f5){_0x333728(_0x1d82f5);});});};exports[_0xdb07('0x56')]=function(_0x62028a,_0x493aaf,_0x216dde){_0x62028a[_0xdb07('0x56')]=!![];return _0x216dde();};exports[_0xdb07('0x57')]=function signToken(_0x5e14fc){return signJwt(_0x5e14fc);};exports['setTokenCookie']=function(_0x464ee4,_0x162e6c){if(!_0x464ee4[_0xdb07('0x2c')]){return _0x162e6c[_0xdb07('0x33')](0x194)['json']({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x509619={'payload':{'id':_0x464ee4[_0xdb07('0x2c')]['id'],'role':_0x464ee4[_0xdb07('0x2c')][_0xdb07('0x9')]},'options':{'expiresIn':0x15180}};return signJwt(_0x509619)[_0xdb07('0x32')](function(_0x5280c8){_0x162e6c[_0xdb07('0x58')](_0xdb07('0x59'),_0x5280c8);_0x162e6c[_0xdb07('0x5a')](_0xdb07('0x5b'));})[_0xdb07('0x37')](function(_0x48d6d4){return _0x162e6c['status'](0x1f4)[_0xdb07('0x5c')](_0x48d6d4);});};exports['retrieveApiKey']=function(_0x55af11){if(_['isNil'](_0x55af11[_0xdb07('0x4a')])||_['isNil'](_0x55af11[_0xdb07('0x5d')])){return null;}else{return createJwt(_0x55af11);}};exports[_0xdb07('0x5e')]=function(_0x477290){_0x477290[_0xdb07('0x4a')]=generateNonce();_0x477290[_0xdb07('0x5d')]=generateIssuedAt();return createJwt(_0x477290);};exports[_0xdb07('0x5f')]=function(_0x16a688,_0x372898){var _0x236090=_0x16a688[_0xdb07('0x42')][_0xdb07('0x44')];if(_0x236090){var _0x246201={'nonce':_0x372898[_0xdb07('0x4a')],'iat':_0x372898['apiKeyIat'],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf['getUuid']()};return verifyJwt(_0x236090,_0x246201)[_0xdb07('0x32')](function(){return generateApiKey(_0x372898);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0xdb07('0x60')]=function(_0x37207c){var _0x57fa3c=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x57fa3c['test'](_0x37207c))throw new db[(_0xdb07('0x61'))][(_0xdb07('0x62'))](_0xdb07('0x63'));return;};exports['validatePasswordHistory']=function(_0x4b20fa,_0x57aac6,_0x5076ed){var _0x201483=encryptor[_0xdb07('0x64')](_0x57aac6)[_0xdb07('0x65')](',');for(var _0x3cc6b4=0x0;_0x3cc6b4<_0x5076ed;_0x3cc6b4++){if(!_0x201483[_0x3cc6b4])break;if(_0x4b20fa[_0xdb07('0x66')]()===_0x201483[_0x3cc6b4][_0xdb07('0x66')]()){var _0x436647=util['format'](_0xdb07('0x67'),_0x5076ed);if(_0x5076ed===0x1){_0x436647=_0xdb07('0x68');}throw new db[(_0xdb07('0x61'))]['ValidationError'](_0x436647);}}return;};exports[_0xdb07('0x69')]=function(_0x764828,_0x242b7d){var _0x2e55f6=_0x242b7d?encryptor['decryptString'](_0x242b7d)['split'](','):[];if(_0x2e55f6[_0xdb07('0x6a')]===0x5){_0x2e55f6[_0xdb07('0x6b')](-0x1,0x1);}_0x2e55f6[_0xdb07('0x6c')](_0x764828);return encryptor[_0xdb07('0x6d')](_0x2e55f6['join'](','));};function signJwt(_0x25a021){var _0x3161f6=BPromise[_0xdb07('0x6e')](jwt[_0xdb07('0x6f')],{'context':jwt});var _0x224a84=_0x25a021[_0xdb07('0x70')]||config[_0xdb07('0x8')][_0xdb07('0x71')];return new BPromise(function(_0x21057d,_0x131e7f){_0x3161f6(_0x25a021[_0xdb07('0x72')],_0x224a84,_0x25a021[_0xdb07('0x73')])[_0xdb07('0x32')](function(_0x133ae5){_0x21057d(_0x133ae5);})[_0xdb07('0x37')](function(_0x405675){_0x131e7f(_0x405675);});});}function verifyJwt(_0x495263,_0x18882d,_0x58d229){var _0x37df2e=BPromise[_0xdb07('0x6e')](jwt[_0xdb07('0x74')],{'context':jwt});var _0x1efa1a=_0x58d229||config[_0xdb07('0x8')]['session'];return new BPromise(function(_0x2bd9ec,_0x2a83e7){_0x37df2e(_0x495263,_0x1efa1a,_0x18882d)['then'](function(_0xa64473){_0x2bd9ec(_0xa64473);})[_0xdb07('0x37')](function(_0x5306fe){_0x2a83e7(_0x5306fe);});});}function generateNonce(){return crypto[_0xdb07('0x75')](0x10)[_0xdb07('0x76')](_0xdb07('0x77'));}function generateIssuedAt(){return Math[_0xdb07('0x78')](Date[_0xdb07('0x79')]()/0x3e8)[_0xdb07('0x76')]();}function createJwt(_0x4340f2){var _0xfa24c2={'payload':{'iat':_0x4340f2[_0xdb07('0x5d')],'nonce':_0x4340f2[_0xdb07('0x4a')]},'options':{'algorithm':_0xdb07('0x7a'),'subject':_0x4340f2['id'][_0xdb07('0x76')](),'issuer':hardwareConf[_0xdb07('0x43')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0xfa24c2)['then'](function(_0x58e4d7){return{'iat':_0x4340f2['apiKeyIat'],'nonce':_0x4340f2['apiKeyNonce'],'token':_0x58e4d7};});}