Built motion from commit (unavailable).|2.5.8
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x400c=['split','length','splice','unshift','join','promisify','secret','payload','options','verify','toString','hex','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','express-jwt','composable-middleware','basic-auth','crypto','secrets','session','role','name','internal','permissions','md5secret','voicePause','mailPause','faxPause','smsPause','openchannelPause','pauseType','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','ChatInteraction','findOne','params','closed','then','status','disposition','json','unmanaged','Unmanaged.','catch','headers','authorization','Basic','User','find','authenticate','pass','Wrong\x20credentials.','user','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','query','sub','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','User\x20object\x20not\x20found.','canUpdate','update','Forbidden','isMiddleware','signToken','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','toLowerCase','format'];(function(_0x3c49fb,_0xfbc6ac){var _0x536319=function(_0x488308){while(--_0x488308){_0x3c49fb['push'](_0x3c49fb['shift']());}};_0x536319(++_0xfbc6ac);}(_0x400c,0x161));var _0xc400=function(_0x3ab9ee,_0x4a74b8){_0x3ab9ee=_0x3ab9ee-0x0;var _0x82ee88=_0x400c[_0x3ab9ee];return _0x82ee88;};'use strict';var db=require(_0xc400('0x0'))['db'];var config=require(_0xc400('0x1'));var hardwareConf=require(_0xc400('0x2'));var licenseUtil=require(_0xc400('0x3'));var encryptor=require(_0xc400('0x4'));var _=require(_0xc400('0x5'));var jwt=require('jsonwebtoken');var expressJwt=require(_0xc400('0x6'));var compose=require(_0xc400('0x7'));var basicAuth=require(_0xc400('0x8'));var crypto=require(_0xc400('0x9'));var BPromise=require('bluebird');var util=require('util');var validateJwt=expressJwt({'secret':config[_0xc400('0xa')][_0xc400('0xb')]});var userAttributes=['id',_0xc400('0xc'),'fullname',_0xc400('0xd'),_0xc400('0xe'),'email','userpic',_0xc400('0xf'),_0xc400('0x10'),_0xc400('0x11'),'chatPause',_0xc400('0x12'),_0xc400('0x13'),_0xc400('0x14'),_0xc400('0x15'),_0xc400('0x16'),'showWebBar',_0xc400('0x17'),_0xc400('0x18'),_0xc400('0x19'),_0xc400('0x1a'),_0xc400('0x1b'),'alias',_0xc400('0x1c'),_0xc400('0x1d'),'phoneBarDnd',_0xc400('0x1e'),_0xc400('0x1f'),_0xc400('0x20'),_0xc400('0x21'),'phoneBarPrefixRequired',_0xc400('0x22'),_0xc400('0x23'),_0xc400('0x24'),_0xc400('0x25'),_0xc400('0x26'),_0xc400('0x27')];exports[_0xc400('0x28')]=function(){return this[_0xc400('0x29')](!![])[_0xc400('0x2a')](function(_0x36cc55,_0x7cc361,_0x4251c7){if(_0x36cc55['user']){_0x4251c7();}else{return db[_0xc400('0x2b')][_0xc400('0x2c')]({'where':{'id':_0x36cc55[_0xc400('0x2d')]['id']},'attributes':['id',_0xc400('0x2e'),'disposition'],'raw':!![]})[_0xc400('0x2f')](function(_0x48a628){if(_0x48a628&&_0x48a628[_0xc400('0x2e')]){return _0x7cc361[_0xc400('0x30')](_0x48a628[_0xc400('0x31')]==='unmanaged'?0x195:0x193)[_0xc400('0x32')]({'message':_0x48a628['disposition']===_0xc400('0x33')?_0xc400('0x34'):'Forbidden.'});}else{_0x4251c7();}})[_0xc400('0x35')](function(_0x1ac0e8){_0x4251c7(_0x1ac0e8);});}});};exports['isAuthenticated']=function isAuthenticated(_0x59845b){return compose()[_0xc400('0x2a')](function(_0x13bd3f,_0x428625,_0x1e55ed){if(_0x13bd3f[_0xc400('0x36')][_0xc400('0x37')]){if(_['startsWith'](_0x13bd3f['headers'][_0xc400('0x37')],_0xc400('0x38'))){var _0x52a855=basicAuth(_0x13bd3f);db[_0xc400('0x39')][_0xc400('0x3a')]({'where':{'name':_0x52a855[_0xc400('0xd')]}})[_0xc400('0x2f')](function(_0x964c70){if(!_0x964c70||!_0x964c70[_0xc400('0x3b')](_0x52a855[_0xc400('0x3c')])){return _0x428625['status'](0x191)[_0xc400('0x32')]({'message':_0xc400('0x3d')});}_0x13bd3f[_0xc400('0x3e')]={'id':_0x964c70['id']};_0x1e55ed();})['catch'](function(_0x3d8ba3){_0x1e55ed(_0x3d8ba3);});}else if(_['startsWith'](_0x13bd3f[_0xc400('0x36')][_0xc400('0x37')],_0xc400('0x3f'))){validateJwt(_0x13bd3f,_0x428625,_0x1e55ed);}else{if(_0x59845b){_0x1e55ed();}else{return _0x428625['status'](0x193)[_0xc400('0x32')]({'message':_0xc400('0x40')});}}}else if(_0x13bd3f['query'][_0xc400('0x41')]){try{var _0x5cbd2a={'audience':hardwareConf[_0xc400('0x42')](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x13bd3f[_0xc400('0x43')]['apikey'],_0x5cbd2a)[_0xc400('0x2f')](function(_0x46b910){return db['User'][_0xc400('0x3a')]({'where':{'id':_0x46b910[_0xc400('0x44')]}})[_0xc400('0x2f')](function(_0x8dd097){if(!_0x8dd097||!_[_0xc400('0x45')](_0x8dd097[_0xc400('0x46')],_0x46b910[_0xc400('0x47')])){return _0x428625[_0xc400('0x30')](0x191)[_0xc400('0x32')]({'message':_0xc400('0x48')});}_0x13bd3f[_0xc400('0x3e')]={'id':_0x8dd097['id']};_0x1e55ed();});})[_0xc400('0x35')](function(){return _0x428625[_0xc400('0x30')](0x191)[_0xc400('0x32')]({'message':_0xc400('0x49')});});}catch(_0x1a4379){_0x1e55ed(_0x1a4379);}}else if(_0x59845b){_0x1e55ed();}else{return _0x428625[_0xc400('0x30')](0x193)[_0xc400('0x32')]({'message':_0xc400('0x40')});}})[_0xc400('0x2a')](function(_0x2b07e3,_0x153ed7,_0x4f92a8){if(_0x2b07e3['user']){db[_0xc400('0x39')][_0xc400('0x3a')]({'where':{'id':_0x2b07e3['user']['id']},'attributes':userAttributes})[_0xc400('0x2f')](function(_0x409a7c){if(!_0x409a7c){return _0x153ed7[_0xc400('0x30')](0x194)['json']({'message':'User\x20not\x20found.'});}_0x2b07e3[_0xc400('0x3e')]=_0x409a7c;_0x4f92a8();})[_0xc400('0x35')](function(_0x13bee9){_0x4f92a8(_0x13bee9);});}else if(_0x59845b){_0x4f92a8();}else{return _0x153ed7[_0xc400('0x30')](0x194)['json']({'message':_0xc400('0x4a')});}});};exports[_0xc400('0x4b')]=function canUpdate(){return compose()[_0xc400('0x2a')](function(_0x20b198,_0x4c1956,_0xaf1f89){return licenseUtil['getLicense']()[_0xc400('0x2f')](function(_0x1c9d43){if(_0x1c9d43[_0xc400('0x4c')]){_0xaf1f89();}else{return _0x4c1956[_0xc400('0x30')](0x193)[_0xc400('0x32')]({'message':_0xc400('0x4d')});}})[_0xc400('0x35')](function(_0x5c655a){_0xaf1f89(_0x5c655a);});});};exports[_0xc400('0x4e')]=function(_0x53a7be,_0x3c9627,_0x4bed49){_0x53a7be['isMiddleware']=!![];return _0x4bed49();};exports[_0xc400('0x4f')]=function signToken(_0x2b6cc5){return signJwt(_0x2b6cc5);};exports['setTokenCookie']=function(_0x45a9fb,_0x18a8cc){if(!_0x45a9fb[_0xc400('0x3e')]){return _0x18a8cc[_0xc400('0x30')](0x194)[_0xc400('0x32')]({'message':_0xc400('0x50')});}var _0x4d6263={'payload':{'id':_0x45a9fb['user']['id'],'role':_0x45a9fb[_0xc400('0x3e')][_0xc400('0xc')]},'options':{'expiresIn':0x15180}};return signJwt(_0x4d6263)['then'](function(_0x2c750b){_0x18a8cc[_0xc400('0x51')](_0xc400('0x52'),_0x2c750b);_0x18a8cc[_0xc400('0x53')](_0xc400('0x54'));})[_0xc400('0x35')](function(_0x884558){return _0x18a8cc['status'](0x1f4)[_0xc400('0x55')](_0x884558);});};exports[_0xc400('0x56')]=function(_0x10915d){if(_[_0xc400('0x57')](_0x10915d[_0xc400('0x46')])||_[_0xc400('0x57')](_0x10915d[_0xc400('0x58')])){return null;}else{return createJwt(_0x10915d);}};exports[_0xc400('0x59')]=function(_0x4a2eb4){_0x4a2eb4['apiKeyNonce']=generateNonce();_0x4a2eb4['apiKeyIat']=generateIssuedAt();return createJwt(_0x4a2eb4);};exports['regenerateApiKey']=function(_0x21b127,_0x18a9a9){var _0x5132bb=_0x21b127['query']['apikey'];if(_0x5132bb){var _0x143485={'nonce':_0x18a9a9['apiKeyNonce'],'iat':_0x18a9a9[_0xc400('0x58')],'audience':hardwareConf[_0xc400('0x42')](),'issuer':hardwareConf[_0xc400('0x42')]()};return verifyJwt(_0x5132bb,_0x143485)[_0xc400('0x2f')](function(){return generateApiKey(_0x18a9a9);});}else{throw{'message':_0xc400('0x5a')};}};exports[_0xc400('0x5b')]=function(_0xfae7ce){var _0x1c874d=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x1c874d[_0xc400('0x5c')](_0xfae7ce))throw new db[(_0xc400('0x5d'))][(_0xc400('0x5e'))](_0xc400('0x5f'));return;};exports[_0xc400('0x60')]=function(_0x340b6c,_0x52b62e,_0x664cba){var _0x3f5585=encryptor['decryptString'](_0x52b62e)['split'](',');for(var _0x3b232f=0x0;_0x3b232f<_0x664cba;_0x3b232f++){if(!_0x3f5585[_0x3b232f])break;if(_0x340b6c['toLowerCase']()===_0x3f5585[_0x3b232f][_0xc400('0x61')]()){var _0x5da4a3=util[_0xc400('0x62')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x664cba);if(_0x664cba===0x1){_0x5da4a3='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db['Sequelize'][(_0xc400('0x5e'))](_0x5da4a3);}}return;};exports['updatePasswordsHistory']=function(_0x1635bb,_0x56e22d){var _0x28c324=_0x56e22d?encryptor['decryptString'](_0x56e22d)[_0xc400('0x63')](','):[];if(_0x28c324[_0xc400('0x64')]===0x5){_0x28c324[_0xc400('0x65')](-0x1,0x1);}_0x28c324[_0xc400('0x66')](_0x1635bb);return encryptor['encryptString'](_0x28c324[_0xc400('0x67')](','));};function signJwt(_0x5c4113){var _0x17a6cd=BPromise[_0xc400('0x68')](jwt['sign'],{'context':jwt});var _0x2fa2ee=_0x5c4113[_0xc400('0x69')]||config['secrets'][_0xc400('0xb')];return new BPromise(function(_0x35247d,_0x42eb45){_0x17a6cd(_0x5c4113[_0xc400('0x6a')],_0x2fa2ee,_0x5c4113[_0xc400('0x6b')])['then'](function(_0x5f0b46){_0x35247d(_0x5f0b46);})[_0xc400('0x35')](function(_0x17383c){_0x42eb45(_0x17383c);});});}function verifyJwt(_0xe13469,_0x556c7c,_0x3972b1){var _0x21ab84=BPromise['promisify'](jwt[_0xc400('0x6c')],{'context':jwt});var _0x1a417a=_0x3972b1||config[_0xc400('0xa')][_0xc400('0xb')];return new BPromise(function(_0x5c43d0,_0x92085a){_0x21ab84(_0xe13469,_0x1a417a,_0x556c7c)[_0xc400('0x2f')](function(_0x942c24){_0x5c43d0(_0x942c24);})[_0xc400('0x35')](function(_0x5b454c){_0x92085a(_0x5b454c);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0xc400('0x6d')](_0xc400('0x6e'));}function generateIssuedAt(){return Math['floor'](Date[_0xc400('0x6f')]()/0x3e8)[_0xc400('0x6d')]();}function createJwt(_0xed80f6){var _0x722bd1={'payload':{'iat':_0xed80f6['apiKeyIat'],'nonce':_0xed80f6[_0xc400('0x46')]},'options':{'algorithm':_0xc400('0x70'),'subject':_0xed80f6['id'][_0xc400('0x6d')](),'issuer':hardwareConf[_0xc400('0x42')](),'audience':hardwareConf[_0xc400('0x42')]()}};return signJwt(_0x722bd1)[_0xc400('0x2f')](function(_0x326801){return{'iat':_0xed80f6[_0xc400('0x58')],'nonce':_0xed80f6[_0xc400('0x46')],'token':_0x326801};});}