Built motion from commit b5996064.|2.6.21
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xf4f4=['isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','params','closed','disposition','then','status','unmanaged','json','Unmanaged.','catch','headers','authorization','User','find','Wrong\x20credentials.','startsWith','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','query','sub','Setting','findOne','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blocked','blockedAt','add','minutes','User\x20object\x20not\x20found.','canUpdate','getLicense','update','Forbidden','webrtc','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','isNil','apiKeyIat','generateApiKey','regenerateApiKey','validatePasswordPattern','test','ValidationError','validatePasswordHistory','decryptString','split','toLowerCase','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','Sequelize','updatePasswordsHistory','length','splice','unshift','encryptString','join','sign','secret','payload','promisify','verify','randomBytes','toString','hex','floor','now','../../mysqldb','../../config/environment','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','basic-auth','bluebird','util','moment','secrets','session','role','fullname','name','email','userpic','permissions','md5secret','voicePause','chatPause','mailPause','faxPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','alias','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarExpires','hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','ignorePauseForPreviewCalls','selectRecallMeCampaign','chatAutoanswer','emailAutoanswer','emailAutoanswerDelay','smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer','openchannelAutoanswerDelay','faxAutoanswer','faxAutoanswerDelay','whatsappAutoanswer','whatsappAutoanswerDelay','messengerSoundNotification'];(function(_0x174168,_0x5d99fe){var _0x345954=function(_0x275185){while(--_0x275185){_0x174168['push'](_0x174168['shift']());}};_0x345954(++_0x5d99fe);}(_0xf4f4,0xe3));var _0x4f4f=function(_0x5c17f1,_0x22a531){_0x5c17f1=_0x5c17f1-0x0;var _0x20deae=_0xf4f4[_0x5c17f1];return _0x20deae;};'use strict';var db=require(_0x4f4f('0x0'))['db'];var config=require(_0x4f4f('0x1'));var hardwareConf=require('../../config/license/hardware');var licenseUtil=require(_0x4f4f('0x2'));var encryptor=require(_0x4f4f('0x3'));var _=require(_0x4f4f('0x4'));var jwt=require(_0x4f4f('0x5'));var expressJwt=require(_0x4f4f('0x6'));var compose=require('composable-middleware');var basicAuth=require(_0x4f4f('0x7'));var crypto=require('crypto');var BPromise=require(_0x4f4f('0x8'));var util=require(_0x4f4f('0x9'));var moment=require(_0x4f4f('0xa'));var validateJwt=expressJwt({'secret':config[_0x4f4f('0xb')][_0x4f4f('0xc')]});var userAttributes=['id',_0x4f4f('0xd'),_0x4f4f('0xe'),_0x4f4f('0xf'),'internal',_0x4f4f('0x10'),_0x4f4f('0x11'),_0x4f4f('0x12'),_0x4f4f('0x13'),_0x4f4f('0x14'),_0x4f4f('0x15'),_0x4f4f('0x16'),_0x4f4f('0x17'),'smsPause','openchannelPause',_0x4f4f('0x18'),_0x4f4f('0x19'),_0x4f4f('0x1a'),_0x4f4f('0x1b'),_0x4f4f('0x1c'),_0x4f4f('0x1d'),'passwordResetAt',_0x4f4f('0x1e'),'phoneBarAutoAnswer',_0x4f4f('0x1f'),_0x4f4f('0x20'),_0x4f4f('0x21'),_0x4f4f('0x22'),'phoneBarEnableSettings',_0x4f4f('0x23'),'phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort',_0x4f4f('0x24'),_0x4f4f('0x25'),_0x4f4f('0x26'),_0x4f4f('0x27'),_0x4f4f('0x28'),_0x4f4f('0x29'),_0x4f4f('0x2a'),_0x4f4f('0x2b'),_0x4f4f('0x2c'),_0x4f4f('0x2d'),_0x4f4f('0x2e'),_0x4f4f('0x2f'),'chatAutoanswerDelay',_0x4f4f('0x30'),_0x4f4f('0x31'),_0x4f4f('0x32'),_0x4f4f('0x33'),_0x4f4f('0x34'),_0x4f4f('0x35'),_0x4f4f('0x36'),_0x4f4f('0x37'),_0x4f4f('0x38'),_0x4f4f('0x39'),_0x4f4f('0x3a')];exports[_0x4f4f('0x3b')]=function(){return this[_0x4f4f('0x3c')](!![])[_0x4f4f('0x3d')](function(_0x5bda88,_0x4f7261,_0x525529){if(_0x5bda88[_0x4f4f('0x3e')]){_0x525529();}else{return db[_0x4f4f('0x3f')]['findOne']({'where':{'id':_0x5bda88[_0x4f4f('0x40')]['id']},'attributes':['id',_0x4f4f('0x41'),_0x4f4f('0x42')],'raw':!![]})[_0x4f4f('0x43')](function(_0x113ff7){if(_0x113ff7&&_0x113ff7[_0x4f4f('0x41')]){return _0x4f7261[_0x4f4f('0x44')](_0x113ff7['disposition']===_0x4f4f('0x45')?0x195:0x193)[_0x4f4f('0x46')]({'message':_0x113ff7[_0x4f4f('0x42')]===_0x4f4f('0x45')?_0x4f4f('0x47'):'Forbidden.'});}else{_0x525529();}})[_0x4f4f('0x48')](function(_0xaf3de1){_0x525529(_0xaf3de1);});}});};exports[_0x4f4f('0x3c')]=function isAuthenticated(_0x5deda9){return compose()['use'](function(_0x4c2490,_0x73b8bb,_0x5b4f6a){var _0x354266;if(_0x4c2490[_0x4f4f('0x49')][_0x4f4f('0x4a')]){if(_['startsWith'](_0x4c2490[_0x4f4f('0x49')][_0x4f4f('0x4a')],'Basic')){var _0x413b71=basicAuth(_0x4c2490);db[_0x4f4f('0x4b')][_0x4f4f('0x4c')]({'where':{'name':_0x413b71['name']}})[_0x4f4f('0x43')](function(_0x343c75){if(!_0x343c75||!_0x343c75['authenticate'](_0x413b71['pass'])){return _0x73b8bb[_0x4f4f('0x44')](0x191)[_0x4f4f('0x46')]({'message':_0x4f4f('0x4d')});}_0x4c2490[_0x4f4f('0x3e')]={'id':_0x343c75['id']};_0x5b4f6a();})[_0x4f4f('0x48')](function(_0x8d0f53){_0x5b4f6a(_0x8d0f53);});}else if(_[_0x4f4f('0x4e')](_0x4c2490[_0x4f4f('0x49')][_0x4f4f('0x4a')],_0x4f4f('0x4f'))){validateJwt(_0x4c2490,_0x73b8bb,_0x5b4f6a);}else{if(_0x5deda9){_0x5b4f6a();}else{return _0x73b8bb['status'](0x193)['json']({'message':_0x4f4f('0x50')});}}}else if(_0x4c2490['query'][_0x4f4f('0x51')]){try{var _0x423c89={'audience':hardwareConf[_0x4f4f('0x52')](),'issuer':hardwareConf[_0x4f4f('0x52')]()};verifyJwt(_0x4c2490[_0x4f4f('0x53')][_0x4f4f('0x51')],_0x423c89)[_0x4f4f('0x43')](function(_0x24834a){return db[_0x4f4f('0x4b')][_0x4f4f('0x4c')]({'where':{'id':_0x24834a[_0x4f4f('0x54')]}})[_0x4f4f('0x43')](function(_0x492fac){_0x354266=_0x492fac;return db[_0x4f4f('0x55')][_0x4f4f('0x56')]({'where':{'id':0x1},'attributes':[_0x4f4f('0x57'),_0x4f4f('0x58')],'raw':!![]});})[_0x4f4f('0x43')](function(_0x34fe84){if(!_0x354266||!_[_0x4f4f('0x59')](_0x354266[_0x4f4f('0x5a')],_0x24834a[_0x4f4f('0x5b')])){return _0x73b8bb['status'](0x191)[_0x4f4f('0x46')]({'message':_0x4f4f('0x5c')});}if(_0x354266[_0x4f4f('0x5d')]){return _0x73b8bb['status'](0x191)['json']({'message':_0x4f4f('0x5e')});}if(_0x354266[_0x4f4f('0x5f')]){if(_0x34fe84[_0x4f4f('0x58')]>0x0){if(moment(_0x354266[_0x4f4f('0x60')])[_0x4f4f('0x61')](_0x34fe84[_0x4f4f('0x58')],_0x4f4f('0x62'))>moment()){return _0x73b8bb[_0x4f4f('0x44')](0x191)[_0x4f4f('0x46')]({'message':_0x4f4f('0x5e')});}}else{return _0x73b8bb[_0x4f4f('0x44')](0x191)[_0x4f4f('0x46')]({'message':'Invalid\x20API\x20access\x20key'});}}_0x4c2490[_0x4f4f('0x3e')]={'id':_0x354266['id']};_0x5b4f6a();});})[_0x4f4f('0x48')](function(){return _0x73b8bb[_0x4f4f('0x44')](0x191)[_0x4f4f('0x46')]({'message':_0x4f4f('0x5e')});});}catch(_0x598d65){_0x5b4f6a(_0x598d65);}}else if(_0x5deda9){_0x5b4f6a();}else{return _0x73b8bb['status'](0x193)[_0x4f4f('0x46')]({'message':_0x4f4f('0x50')});}})[_0x4f4f('0x3d')](function(_0xa8f1a5,_0x4a4184,_0x1aaf2c){if(_0xa8f1a5['user']){db[_0x4f4f('0x4b')]['find']({'where':{'id':_0xa8f1a5['user']['id']},'attributes':userAttributes})[_0x4f4f('0x43')](function(_0x4f3a0f){if(!_0x4f3a0f){return _0x4a4184[_0x4f4f('0x44')](0x194)[_0x4f4f('0x46')]({'message':'User\x20not\x20found.'});}_0xa8f1a5[_0x4f4f('0x3e')]=_0x4f3a0f;_0x1aaf2c();})[_0x4f4f('0x48')](function(_0x4e782c){_0x1aaf2c(_0x4e782c);});}else if(_0x5deda9){_0x1aaf2c();}else{return _0x4a4184[_0x4f4f('0x44')](0x194)[_0x4f4f('0x46')]({'message':_0x4f4f('0x63')});}});};exports[_0x4f4f('0x64')]=function canUpdate(){return compose()[_0x4f4f('0x3d')](function(_0x62b468,_0xb0d1b2,_0x15f0a1){return licenseUtil[_0x4f4f('0x65')]()[_0x4f4f('0x43')](function(_0x475969){if(_0x475969[_0x4f4f('0x66')]){_0x15f0a1();}else{return _0xb0d1b2[_0x4f4f('0x44')](0x193)[_0x4f4f('0x46')]({'message':_0x4f4f('0x67')});}})['catch'](function(_0x636b63){_0x15f0a1(_0x636b63);});});};exports['isWebrtcLicence']=function isWebrtcLicence(){return compose()['use'](function(_0x31349a,_0x4363c9,_0x5cf4da){return licenseUtil[_0x4f4f('0x65')]()[_0x4f4f('0x43')](function(_0xea9617){if(_0xea9617[_0x4f4f('0x68')]){_0x5cf4da();}else{return _0x4363c9[_0x4f4f('0x44')](0x193)['json']({'message':_0x4f4f('0x67')});}})[_0x4f4f('0x48')](function(_0x30674f){_0x5cf4da(_0x30674f);});});};exports[_0x4f4f('0x69')]=function(_0x196426,_0x433787,_0x29314b){_0x196426[_0x4f4f('0x69')]=!![];return _0x29314b();};exports[_0x4f4f('0x6a')]=function signToken(_0x540b3c){return signJwt(_0x540b3c);};exports[_0x4f4f('0x6b')]=function(_0xd3b763,_0x4b33a5){if(!_0xd3b763['user']){return _0x4b33a5['status'](0x194)[_0x4f4f('0x46')]({'message':_0x4f4f('0x6c')});}var _0x3a2ae3={'payload':{'id':_0xd3b763['user']['id'],'role':_0xd3b763[_0x4f4f('0x3e')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x3a2ae3)[_0x4f4f('0x43')](function(_0x1c181e){_0x4b33a5[_0x4f4f('0x6d')](_0x4f4f('0x6e'),_0x1c181e);_0x4b33a5[_0x4f4f('0x6f')](_0x4f4f('0x70'));})[_0x4f4f('0x48')](function(_0x88054a){return _0x4b33a5[_0x4f4f('0x44')](0x1f4)['send'](_0x88054a);});};exports['retrieveApiKey']=function(_0x36cfcf){if(_[_0x4f4f('0x71')](_0x36cfcf['apiKeyNonce'])||_['isNil'](_0x36cfcf[_0x4f4f('0x72')])){return null;}else{return createJwt(_0x36cfcf);}};exports[_0x4f4f('0x73')]=function(_0x15fd73){_0x15fd73['apiKeyNonce']=generateNonce();_0x15fd73['apiKeyIat']=generateIssuedAt();return createJwt(_0x15fd73);};exports[_0x4f4f('0x74')]=function(_0x3205ef,_0x179998){var _0x3bd569=_0x3205ef[_0x4f4f('0x53')][_0x4f4f('0x51')];if(_0x3bd569){var _0xe66fc={'nonce':_0x179998[_0x4f4f('0x5a')],'iat':_0x179998[_0x4f4f('0x72')],'audience':hardwareConf[_0x4f4f('0x52')](),'issuer':hardwareConf[_0x4f4f('0x52')]()};return verifyJwt(_0x3bd569,_0xe66fc)['then'](function(){return generateApiKey(_0x179998);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0x4f4f('0x75')]=function(_0x136d83){var _0x161943=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x161943[_0x4f4f('0x76')](_0x136d83))throw new db['Sequelize'][(_0x4f4f('0x77'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x4f4f('0x78')]=function(_0x3f57c2,_0x1c6489,_0x4901f5){var _0x550342=encryptor[_0x4f4f('0x79')](_0x1c6489)[_0x4f4f('0x7a')](',');for(var _0x4f26af=0x0;_0x4f26af<_0x4901f5;_0x4f26af++){if(!_0x550342[_0x4f26af])break;if(_0x3f57c2[_0x4f4f('0x7b')]()===_0x550342[_0x4f26af][_0x4f4f('0x7b')]()){var _0x1d48fb=util['format'](_0x4f4f('0x7c'),_0x4901f5);if(_0x4901f5===0x1){_0x1d48fb=_0x4f4f('0x7d');}throw new db[(_0x4f4f('0x7e'))]['ValidationError'](_0x1d48fb);}}return;};exports[_0x4f4f('0x7f')]=function(_0x5418cd,_0x35701d){var _0x3b637d=_0x35701d?encryptor[_0x4f4f('0x79')](_0x35701d)[_0x4f4f('0x7a')](','):[];if(_0x3b637d[_0x4f4f('0x80')]===0x5){_0x3b637d[_0x4f4f('0x81')](-0x1,0x1);}_0x3b637d[_0x4f4f('0x82')](_0x5418cd);return encryptor[_0x4f4f('0x83')](_0x3b637d[_0x4f4f('0x84')](','));};function signJwt(_0x36f369){var _0x269e0d=BPromise['promisify'](jwt[_0x4f4f('0x85')],{'context':jwt});var _0x297c9c=_0x36f369[_0x4f4f('0x86')]||config['secrets'][_0x4f4f('0xc')];return new BPromise(function(_0x43908e,_0x151c75){_0x269e0d(_0x36f369[_0x4f4f('0x87')],_0x297c9c,_0x36f369['options'])[_0x4f4f('0x43')](function(_0x213163){_0x43908e(_0x213163);})[_0x4f4f('0x48')](function(_0x24928a){_0x151c75(_0x24928a);});});}function verifyJwt(_0x157af6,_0x5e2ef4,_0xe105e9){var _0x484ae2=BPromise[_0x4f4f('0x88')](jwt[_0x4f4f('0x89')],{'context':jwt});var _0x2da4ea=_0xe105e9||config[_0x4f4f('0xb')][_0x4f4f('0xc')];return new BPromise(function(_0x23366b,_0x4bbbf6){_0x484ae2(_0x157af6,_0x2da4ea,_0x5e2ef4)['then'](function(_0x15c86f){_0x23366b(_0x15c86f);})['catch'](function(_0x4252fa){_0x4bbbf6(_0x4252fa);});});}function generateNonce(){return crypto[_0x4f4f('0x8a')](0x10)[_0x4f4f('0x8b')](_0x4f4f('0x8c'));}function generateIssuedAt(){return Math[_0x4f4f('0x8d')](Date[_0x4f4f('0x8e')]()/0x3e8)[_0x4f4f('0x8b')]();}function createJwt(_0x346ebb){var _0x356224={'payload':{'iat':_0x346ebb[_0x4f4f('0x72')],'nonce':_0x346ebb[_0x4f4f('0x5a')]},'options':{'algorithm':'HS512','subject':_0x346ebb['id']['toString'](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x4f4f('0x52')]()}};return signJwt(_0x356224)[_0x4f4f('0x43')](function(_0x49c7c4){return{'iat':_0x346ebb[_0x4f4f('0x72')],'nonce':_0x346ebb[_0x4f4f('0x5a')],'token':_0x49c7c4};});}