Built motion from commit (unavailable).|2.5.23
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xaf97=['fullname','name','internal','email','userpic','voicePause','chatPause','mailPause','smsPause','openchannelPause','pauseType','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','closed','disposition','then','status','unmanaged','Forbidden.','headers','authorization','startsWith','Basic','User','pass','json','Wrong\x20credentials.','catch','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','find','sub','Setting','findOne','allowedLoginAttempts','blockDuration','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blocked','add','minutes','canUpdate','getLicense','update','isMiddleware','signToken','cookie','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','test','Sequelize','ValidationError','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','encryptString','join','promisify','sign','secret','session','payload','options','randomBytes','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','jsonwebtoken','express-jwt','composable-middleware','basic-auth','bluebird','util','moment','secrets','role'];(function(_0x199572,_0x33e667){var _0x13cfa3=function(_0x53c075){while(--_0x53c075){_0x199572['push'](_0x199572['shift']());}};_0x13cfa3(++_0x33e667);}(_0xaf97,0x15a));var _0x7af9=function(_0x46fbb4,_0x549ac1){_0x46fbb4=_0x46fbb4-0x0;var _0x5b82c2=_0xaf97[_0x46fbb4];return _0x5b82c2;};'use strict';var db=require(_0x7af9('0x0'))['db'];var config=require(_0x7af9('0x1'));var hardwareConf=require(_0x7af9('0x2'));var licenseUtil=require(_0x7af9('0x3'));var encryptor=require(_0x7af9('0x4'));var _=require('lodash');var jwt=require(_0x7af9('0x5'));var expressJwt=require(_0x7af9('0x6'));var compose=require(_0x7af9('0x7'));var basicAuth=require(_0x7af9('0x8'));var crypto=require('crypto');var BPromise=require(_0x7af9('0x9'));var util=require(_0x7af9('0xa'));var moment=require(_0x7af9('0xb'));var validateJwt=expressJwt({'secret':config[_0x7af9('0xc')]['session']});var userAttributes=['id',_0x7af9('0xd'),_0x7af9('0xe'),_0x7af9('0xf'),_0x7af9('0x10'),_0x7af9('0x11'),_0x7af9('0x12'),'permissions','md5secret',_0x7af9('0x13'),_0x7af9('0x14'),_0x7af9('0x15'),'faxPause',_0x7af9('0x16'),_0x7af9('0x17'),_0x7af9('0x18'),'showWebBar',_0x7af9('0x19'),_0x7af9('0x1a'),_0x7af9('0x1b'),_0x7af9('0x1c'),_0x7af9('0x1d'),'alias',_0x7af9('0x1e'),_0x7af9('0x1f'),_0x7af9('0x20'),_0x7af9('0x21'),'phoneBarEnableDtmfTone',_0x7af9('0x22'),_0x7af9('0x23'),_0x7af9('0x24'),_0x7af9('0x25'),_0x7af9('0x26'),_0x7af9('0x27'),_0x7af9('0x28'),_0x7af9('0x29'),'privacyEnabled','settingsEnabled'];exports[_0x7af9('0x2a')]=function(){return this[_0x7af9('0x2b')](!![])[_0x7af9('0x2c')](function(_0x44534f,_0xda9840,_0xb33650){if(_0x44534f[_0x7af9('0x2d')]){_0xb33650();}else{return db[_0x7af9('0x2e')]['findOne']({'where':{'id':_0x44534f['params']['id']},'attributes':['id',_0x7af9('0x2f'),_0x7af9('0x30')],'raw':!![]})[_0x7af9('0x31')](function(_0x2a1bd1){if(_0x2a1bd1&&_0x2a1bd1['closed']){return _0xda9840[_0x7af9('0x32')](_0x2a1bd1[_0x7af9('0x30')]===_0x7af9('0x33')?0x195:0x193)['json']({'message':_0x2a1bd1[_0x7af9('0x30')]===_0x7af9('0x33')?'Unmanaged.':_0x7af9('0x34')});}else{_0xb33650();}})['catch'](function(_0x27ab13){_0xb33650(_0x27ab13);});}});};exports['isAuthenticated']=function isAuthenticated(_0xb5e376){return compose()[_0x7af9('0x2c')](function(_0x341a54,_0xc4e367,_0x5cfbe9){var _0x2f5b78;if(_0x341a54[_0x7af9('0x35')][_0x7af9('0x36')]){if(_[_0x7af9('0x37')](_0x341a54['headers'][_0x7af9('0x36')],_0x7af9('0x38'))){var _0x1ac268=basicAuth(_0x341a54);db[_0x7af9('0x39')]['find']({'where':{'name':_0x1ac268[_0x7af9('0xf')]}})[_0x7af9('0x31')](function(_0x408763){if(!_0x408763||!_0x408763['authenticate'](_0x1ac268[_0x7af9('0x3a')])){return _0xc4e367[_0x7af9('0x32')](0x191)[_0x7af9('0x3b')]({'message':_0x7af9('0x3c')});}_0x341a54[_0x7af9('0x2d')]={'id':_0x408763['id']};_0x5cfbe9();})[_0x7af9('0x3d')](function(_0x223469){_0x5cfbe9(_0x223469);});}else if(_[_0x7af9('0x37')](_0x341a54[_0x7af9('0x35')][_0x7af9('0x36')],_0x7af9('0x3e'))){validateJwt(_0x341a54,_0xc4e367,_0x5cfbe9);}else{if(_0xb5e376){_0x5cfbe9();}else{return _0xc4e367[_0x7af9('0x32')](0x193)['json']({'message':_0x7af9('0x3f')});}}}else if(_0x341a54[_0x7af9('0x40')][_0x7af9('0x41')]){try{var _0x1b9ff5={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x7af9('0x42')]()};verifyJwt(_0x341a54[_0x7af9('0x40')][_0x7af9('0x41')],_0x1b9ff5)['then'](function(_0x48386f){return db[_0x7af9('0x39')][_0x7af9('0x43')]({'where':{'id':_0x48386f[_0x7af9('0x44')]}})[_0x7af9('0x31')](function(_0x945200){_0x2f5b78=_0x945200;return db[_0x7af9('0x45')][_0x7af9('0x46')]({'where':{'id':0x1},'attributes':[_0x7af9('0x47'),_0x7af9('0x48')],'raw':!![]});})[_0x7af9('0x31')](function(_0x29dd07){if(!_0x2f5b78||!_['isEqual'](_0x2f5b78[_0x7af9('0x49')],_0x48386f[_0x7af9('0x4a')])){return _0xc4e367['status'](0x191)[_0x7af9('0x3b')]({'message':_0x7af9('0x4b')});}if(_0x2f5b78[_0x7af9('0x4c')]){return _0xc4e367['status'](0x191)[_0x7af9('0x3b')]({'message':_0x7af9('0x4d')});}if(_0x2f5b78[_0x7af9('0x4e')]){if(_0x29dd07[_0x7af9('0x48')]>0x0){if(moment(_0x2f5b78['blockedAt'])[_0x7af9('0x4f')](_0x29dd07[_0x7af9('0x48')],_0x7af9('0x50'))>moment()){return _0xc4e367['status'](0x191)['json']({'message':_0x7af9('0x4d')});}}else{return _0xc4e367[_0x7af9('0x32')](0x191)[_0x7af9('0x3b')]({'message':_0x7af9('0x4d')});}}_0x341a54['user']={'id':_0x2f5b78['id']};_0x5cfbe9();});})[_0x7af9('0x3d')](function(){return _0xc4e367[_0x7af9('0x32')](0x191)[_0x7af9('0x3b')]({'message':_0x7af9('0x4d')});});}catch(_0x2940b3){_0x5cfbe9(_0x2940b3);}}else if(_0xb5e376){_0x5cfbe9();}else{return _0xc4e367['status'](0x193)[_0x7af9('0x3b')]({'message':_0x7af9('0x3f')});}})['use'](function(_0x446a5c,_0xd8e33f,_0x2d0f4b){if(_0x446a5c[_0x7af9('0x2d')]){db['User'][_0x7af9('0x43')]({'where':{'id':_0x446a5c['user']['id']},'attributes':userAttributes})['then'](function(_0x59e378){if(!_0x59e378){return _0xd8e33f[_0x7af9('0x32')](0x194)[_0x7af9('0x3b')]({'message':'User\x20not\x20found.'});}_0x446a5c['user']=_0x59e378;_0x2d0f4b();})[_0x7af9('0x3d')](function(_0x4537b6){_0x2d0f4b(_0x4537b6);});}else if(_0xb5e376){_0x2d0f4b();}else{return _0xd8e33f[_0x7af9('0x32')](0x194)[_0x7af9('0x3b')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x7af9('0x51')]=function canUpdate(){return compose()['use'](function(_0x1e485b,_0x26e821,_0x12f4f5){return licenseUtil[_0x7af9('0x52')]()[_0x7af9('0x31')](function(_0x33653b){if(_0x33653b[_0x7af9('0x53')]){_0x12f4f5();}else{return _0x26e821[_0x7af9('0x32')](0x193)['json']({'message':'Forbidden'});}})['catch'](function(_0x49f421){_0x12f4f5(_0x49f421);});});};exports[_0x7af9('0x54')]=function(_0x42556c,_0x551bcb,_0x3e722b){_0x42556c['isMiddleware']=!![];return _0x3e722b();};exports[_0x7af9('0x55')]=function signToken(_0x1fd103){return signJwt(_0x1fd103);};exports['setTokenCookie']=function(_0x5c3f0a,_0x209b50){if(!_0x5c3f0a['user']){return _0x209b50[_0x7af9('0x32')](0x194)[_0x7af9('0x3b')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x388ad2={'payload':{'id':_0x5c3f0a[_0x7af9('0x2d')]['id'],'role':_0x5c3f0a[_0x7af9('0x2d')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x388ad2)[_0x7af9('0x31')](function(_0x5b362d){_0x209b50[_0x7af9('0x56')]('motion.token',_0x5b362d);_0x209b50[_0x7af9('0x57')](_0x7af9('0x58'));})[_0x7af9('0x3d')](function(_0x2cf39d){return _0x209b50['status'](0x1f4)[_0x7af9('0x59')](_0x2cf39d);});};exports[_0x7af9('0x5a')]=function(_0x4c8758){if(_[_0x7af9('0x5b')](_0x4c8758[_0x7af9('0x49')])||_[_0x7af9('0x5b')](_0x4c8758[_0x7af9('0x5c')])){return null;}else{return createJwt(_0x4c8758);}};exports[_0x7af9('0x5d')]=function(_0xbb14c7){_0xbb14c7[_0x7af9('0x49')]=generateNonce();_0xbb14c7[_0x7af9('0x5c')]=generateIssuedAt();return createJwt(_0xbb14c7);};exports[_0x7af9('0x5e')]=function(_0x1e7eac,_0x278327){var _0x703fa5=_0x1e7eac[_0x7af9('0x40')][_0x7af9('0x41')];if(_0x703fa5){var _0x4f57d6={'nonce':_0x278327[_0x7af9('0x49')],'iat':_0x278327['apiKeyIat'],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x7af9('0x42')]()};return verifyJwt(_0x703fa5,_0x4f57d6)[_0x7af9('0x31')](function(){return generateApiKey(_0x278327);});}else{throw{'message':_0x7af9('0x5f')};}};exports['validatePasswordPattern']=function(_0x5e288e){var _0xe05327=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0xe05327[_0x7af9('0x60')](_0x5e288e))throw new db[(_0x7af9('0x61'))][(_0x7af9('0x62'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x7af9('0x63')]=function(_0x112590,_0x51dd8a,_0x274f4e){var _0x1a9b46=encryptor[_0x7af9('0x64')](_0x51dd8a)[_0x7af9('0x65')](',');for(var _0x472cd4=0x0;_0x472cd4<_0x274f4e;_0x472cd4++){if(!_0x1a9b46[_0x472cd4])break;if(_0x112590['toLowerCase']()===_0x1a9b46[_0x472cd4][_0x7af9('0x66')]()){var _0x34847b=util[_0x7af9('0x67')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x274f4e);if(_0x274f4e===0x1){_0x34847b=_0x7af9('0x68');}throw new db['Sequelize'][(_0x7af9('0x62'))](_0x34847b);}}return;};exports[_0x7af9('0x69')]=function(_0x526b67,_0x26fdd1){var _0x29e362=_0x26fdd1?encryptor[_0x7af9('0x64')](_0x26fdd1)[_0x7af9('0x65')](','):[];if(_0x29e362['length']===0x5){_0x29e362['splice'](-0x1,0x1);}_0x29e362['unshift'](_0x526b67);return encryptor[_0x7af9('0x6a')](_0x29e362[_0x7af9('0x6b')](','));};function signJwt(_0x342d54){var _0x3662db=BPromise[_0x7af9('0x6c')](jwt[_0x7af9('0x6d')],{'context':jwt});var _0x1801d8=_0x342d54[_0x7af9('0x6e')]||config[_0x7af9('0xc')][_0x7af9('0x6f')];return new BPromise(function(_0x4c3afb,_0x503095){_0x3662db(_0x342d54[_0x7af9('0x70')],_0x1801d8,_0x342d54[_0x7af9('0x71')])[_0x7af9('0x31')](function(_0x38b541){_0x4c3afb(_0x38b541);})[_0x7af9('0x3d')](function(_0x23e4a1){_0x503095(_0x23e4a1);});});}function verifyJwt(_0x20ee50,_0x4759e5,_0x53a273){var _0x488674=BPromise[_0x7af9('0x6c')](jwt['verify'],{'context':jwt});var _0xffd755=_0x53a273||config['secrets'][_0x7af9('0x6f')];return new BPromise(function(_0x963a99,_0x3c06dd){_0x488674(_0x20ee50,_0xffd755,_0x4759e5)[_0x7af9('0x31')](function(_0x3a06ab){_0x963a99(_0x3a06ab);})[_0x7af9('0x3d')](function(_0x259812){_0x3c06dd(_0x259812);});});}function generateNonce(){return crypto[_0x7af9('0x72')](0x10)[_0x7af9('0x73')](_0x7af9('0x74'));}function generateIssuedAt(){return Math[_0x7af9('0x75')](Date[_0x7af9('0x76')]()/0x3e8)[_0x7af9('0x73')]();}function createJwt(_0x1262e8){var _0x14a0af={'payload':{'iat':_0x1262e8[_0x7af9('0x5c')],'nonce':_0x1262e8[_0x7af9('0x49')]},'options':{'algorithm':_0x7af9('0x77'),'subject':_0x1262e8['id'][_0x7af9('0x73')](),'issuer':hardwareConf[_0x7af9('0x42')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x14a0af)[_0x7af9('0x31')](function(_0x56deb6){return{'iat':_0x1262e8[_0x7af9('0x5c')],'nonce':_0x1262e8['apiKeyNonce'],'token':_0x56deb6};});}