Built motion from commit (unavailable).|2.5.13
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xe26b=['redirect','/dashboards/general','apiKeyNonce','isNil','apiKeyIat','generateApiKey','validatePasswordPattern','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','ValidationError','updatePasswordsHistory','decryptString','split','length','splice','encryptString','join','sign','secret','session','options','promisify','verify','randomBytes','hex','floor','now','toString','HS512','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','moment','secrets','role','internal','email','userpic','permissions','md5secret','mailPause','faxPause','smsPause','openchannelPause','pauseType','showWebBar','lastPauseAt','crudPermissions','allowmessenger','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','settingsEnabled','isChatInteractionAuthorized','use','user','ChatInteraction','params','disposition','then','closed','status','unmanaged','json','Unmanaged.','Forbidden.','catch','isAuthenticated','headers','authorization','startsWith','User','find','name','pass','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','sub','findOne','blockDuration','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blocked','blockedAt','User\x20object\x20not\x20found.','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token'];(function(_0x9a6649,_0x403b8f){var _0x323421=function(_0x46f079){while(--_0x46f079){_0x9a6649['push'](_0x9a6649['shift']());}};_0x323421(++_0x403b8f);}(_0xe26b,0x188));var _0xbe26=function(_0x4dc35e,_0x2e6bca){_0x4dc35e=_0x4dc35e-0x0;var _0x124f78=_0xe26b[_0x4dc35e];return _0x124f78;};'use strict';var db=require('../../mysqldb')['db'];var config=require('../../config/environment');var hardwareConf=require(_0xbe26('0x0'));var licenseUtil=require(_0xbe26('0x1'));var encryptor=require(_0xbe26('0x2'));var _=require(_0xbe26('0x3'));var jwt=require(_0xbe26('0x4'));var expressJwt=require(_0xbe26('0x5'));var compose=require(_0xbe26('0x6'));var basicAuth=require(_0xbe26('0x7'));var crypto=require(_0xbe26('0x8'));var BPromise=require(_0xbe26('0x9'));var util=require('util');var moment=require(_0xbe26('0xa'));var validateJwt=expressJwt({'secret':config[_0xbe26('0xb')]['session']});var userAttributes=['id',_0xbe26('0xc'),'fullname','name',_0xbe26('0xd'),_0xbe26('0xe'),_0xbe26('0xf'),_0xbe26('0x10'),_0xbe26('0x11'),'voicePause','chatPause',_0xbe26('0x12'),_0xbe26('0x13'),_0xbe26('0x14'),_0xbe26('0x15'),_0xbe26('0x16'),_0xbe26('0x17'),'lastLoginAt',_0xbe26('0x18'),_0xbe26('0x19'),_0xbe26('0x1a'),'passwordResetAt','alias',_0xbe26('0x1b'),_0xbe26('0x1c'),_0xbe26('0x1d'),_0xbe26('0x1e'),_0xbe26('0x1f'),'phoneBarEnableSettings',_0xbe26('0x20'),_0xbe26('0x21'),_0xbe26('0x22'),_0xbe26('0x23'),'hotdesk','interface','userProfileId',_0xbe26('0x24')];exports[_0xbe26('0x25')]=function(){return this['isAuthenticated'](!![])[_0xbe26('0x26')](function(_0x26b689,_0x6925de,_0x2f5b44){if(_0x26b689[_0xbe26('0x27')]){_0x2f5b44();}else{return db[_0xbe26('0x28')]['findOne']({'where':{'id':_0x26b689[_0xbe26('0x29')]['id']},'attributes':['id','closed',_0xbe26('0x2a')],'raw':!![]})[_0xbe26('0x2b')](function(_0x240337){if(_0x240337&&_0x240337[_0xbe26('0x2c')]){return _0x6925de[_0xbe26('0x2d')](_0x240337['disposition']===_0xbe26('0x2e')?0x195:0x193)[_0xbe26('0x2f')]({'message':_0x240337['disposition']===_0xbe26('0x2e')?_0xbe26('0x30'):_0xbe26('0x31')});}else{_0x2f5b44();}})[_0xbe26('0x32')](function(_0x21cf5e){_0x2f5b44(_0x21cf5e);});}});};exports[_0xbe26('0x33')]=function isAuthenticated(_0x2c1a7a){return compose()[_0xbe26('0x26')](function(_0x61f966,_0x463979,_0x5731cb){var _0x391dac;if(_0x61f966[_0xbe26('0x34')][_0xbe26('0x35')]){if(_[_0xbe26('0x36')](_0x61f966[_0xbe26('0x34')]['authorization'],'Basic')){var _0x45bda6=basicAuth(_0x61f966);db[_0xbe26('0x37')][_0xbe26('0x38')]({'where':{'name':_0x45bda6[_0xbe26('0x39')]}})[_0xbe26('0x2b')](function(_0xaf4ad){if(!_0xaf4ad||!_0xaf4ad['authenticate'](_0x45bda6[_0xbe26('0x3a')])){return _0x463979[_0xbe26('0x2d')](0x191)['json']({'message':_0xbe26('0x3b')});}_0x61f966[_0xbe26('0x27')]={'id':_0xaf4ad['id']};_0x5731cb();})['catch'](function(_0xb85ed7){_0x5731cb(_0xb85ed7);});}else if(_[_0xbe26('0x36')](_0x61f966[_0xbe26('0x34')]['authorization'],_0xbe26('0x3c'))){validateJwt(_0x61f966,_0x463979,_0x5731cb);}else{if(_0x2c1a7a){_0x5731cb();}else{return _0x463979['status'](0x193)[_0xbe26('0x2f')]({'message':_0xbe26('0x3d')});}}}else if(_0x61f966[_0xbe26('0x3e')]['apikey']){try{var _0x4915c6={'audience':hardwareConf[_0xbe26('0x3f')](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x61f966[_0xbe26('0x3e')][_0xbe26('0x40')],_0x4915c6)['then'](function(_0x17162d){return db[_0xbe26('0x37')][_0xbe26('0x38')]({'where':{'id':_0x17162d[_0xbe26('0x41')]}})[_0xbe26('0x2b')](function(_0xa33894){_0x391dac=_0xa33894;return db['Setting'][_0xbe26('0x42')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts',_0xbe26('0x43')],'raw':!![]});})[_0xbe26('0x2b')](function(_0x29d599){if(!_0x391dac||!_['isEqual'](_0x391dac['apiKeyNonce'],_0x17162d[_0xbe26('0x44')])){return _0x463979['status'](0x191)[_0xbe26('0x2f')]({'message':_0xbe26('0x45')});}if(_0x391dac[_0xbe26('0x46')]){return _0x463979[_0xbe26('0x2d')](0x191)[_0xbe26('0x2f')]({'message':_0xbe26('0x47')});}if(_0x391dac[_0xbe26('0x48')]){if(_0x29d599[_0xbe26('0x43')]>0x0){if(moment(_0x391dac[_0xbe26('0x49')])['add'](_0x29d599[_0xbe26('0x43')],'minutes')>moment()){return _0x463979['status'](0x191)[_0xbe26('0x2f')]({'message':_0xbe26('0x47')});}}else{return _0x463979[_0xbe26('0x2d')](0x191)[_0xbe26('0x2f')]({'message':_0xbe26('0x47')});}}_0x61f966[_0xbe26('0x27')]={'id':_0x391dac['id']};_0x5731cb();});})[_0xbe26('0x32')](function(){return _0x463979['status'](0x191)[_0xbe26('0x2f')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x309f78){_0x5731cb(_0x309f78);}}else if(_0x2c1a7a){_0x5731cb();}else{return _0x463979[_0xbe26('0x2d')](0x193)['json']({'message':'Unknown\x20authorization\x20format'});}})[_0xbe26('0x26')](function(_0x6a490a,_0x3e2163,_0x243501){if(_0x6a490a[_0xbe26('0x27')]){db[_0xbe26('0x37')][_0xbe26('0x38')]({'where':{'id':_0x6a490a['user']['id']},'attributes':userAttributes})[_0xbe26('0x2b')](function(_0x806051){if(!_0x806051){return _0x3e2163[_0xbe26('0x2d')](0x194)[_0xbe26('0x2f')]({'message':'User\x20not\x20found.'});}_0x6a490a[_0xbe26('0x27')]=_0x806051;_0x243501();})['catch'](function(_0x238b13){_0x243501(_0x238b13);});}else if(_0x2c1a7a){_0x243501();}else{return _0x3e2163[_0xbe26('0x2d')](0x194)[_0xbe26('0x2f')]({'message':_0xbe26('0x4a')});}});};exports['canUpdate']=function canUpdate(){return compose()[_0xbe26('0x26')](function(_0x4e5fa1,_0x5db67e,_0x16e745){return licenseUtil[_0xbe26('0x4b')]()[_0xbe26('0x2b')](function(_0x13c3a3){if(_0x13c3a3[_0xbe26('0x4c')]){_0x16e745();}else{return _0x5db67e[_0xbe26('0x2d')](0x193)['json']({'message':_0xbe26('0x4d')});}})[_0xbe26('0x32')](function(_0x2ff071){_0x16e745(_0x2ff071);});});};exports[_0xbe26('0x4e')]=function(_0x586590,_0x5c1566,_0x3f9fcc){_0x586590[_0xbe26('0x4e')]=!![];return _0x3f9fcc();};exports[_0xbe26('0x4f')]=function signToken(_0x206c3b){return signJwt(_0x206c3b);};exports[_0xbe26('0x50')]=function(_0x273c38,_0x152e79){if(!_0x273c38[_0xbe26('0x27')]){return _0x152e79[_0xbe26('0x2d')](0x194)[_0xbe26('0x2f')]({'message':_0xbe26('0x51')});}var _0xb119ac={'payload':{'id':_0x273c38[_0xbe26('0x27')]['id'],'role':_0x273c38[_0xbe26('0x27')][_0xbe26('0xc')]},'options':{'expiresIn':0x15180}};return signJwt(_0xb119ac)[_0xbe26('0x2b')](function(_0x59afc7){_0x152e79[_0xbe26('0x52')](_0xbe26('0x53'),_0x59afc7);_0x152e79[_0xbe26('0x54')](_0xbe26('0x55'));})['catch'](function(_0x3643dd){return _0x152e79[_0xbe26('0x2d')](0x1f4)['send'](_0x3643dd);});};exports['retrieveApiKey']=function(_0x1fd5ea){if(_['isNil'](_0x1fd5ea[_0xbe26('0x56')])||_[_0xbe26('0x57')](_0x1fd5ea[_0xbe26('0x58')])){return null;}else{return createJwt(_0x1fd5ea);}};exports[_0xbe26('0x59')]=function(_0x548deb){_0x548deb['apiKeyNonce']=generateNonce();_0x548deb[_0xbe26('0x58')]=generateIssuedAt();return createJwt(_0x548deb);};exports['regenerateApiKey']=function(_0x55026a,_0x59e94e){var _0x222823=_0x55026a[_0xbe26('0x3e')][_0xbe26('0x40')];if(_0x222823){var _0x1d852c={'nonce':_0x59e94e[_0xbe26('0x56')],'iat':_0x59e94e['apiKeyIat'],'audience':hardwareConf[_0xbe26('0x3f')](),'issuer':hardwareConf[_0xbe26('0x3f')]()};return verifyJwt(_0x222823,_0x1d852c)[_0xbe26('0x2b')](function(){return generateApiKey(_0x59e94e);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0xbe26('0x5a')]=function(_0x7c2de9){var _0x219da0=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x219da0[_0xbe26('0x5b')](_0x7c2de9))throw new db[(_0xbe26('0x5c'))]['ValidationError'](_0xbe26('0x5d'));return;};exports[_0xbe26('0x5e')]=function(_0x3022ad,_0x553f65,_0x105c25){var _0x28fca5=encryptor['decryptString'](_0x553f65)['split'](',');for(var _0x566216=0x0;_0x566216<_0x105c25;_0x566216++){if(!_0x28fca5[_0x566216])break;if(_0x3022ad[_0xbe26('0x5f')]()===_0x28fca5[_0x566216][_0xbe26('0x5f')]()){var _0x1af202=util[_0xbe26('0x60')](_0xbe26('0x61'),_0x105c25);if(_0x105c25===0x1){_0x1af202=_0xbe26('0x62');}throw new db[(_0xbe26('0x5c'))][(_0xbe26('0x63'))](_0x1af202);}}return;};exports[_0xbe26('0x64')]=function(_0x1a5076,_0x2e8e68){var _0x162b6f=_0x2e8e68?encryptor[_0xbe26('0x65')](_0x2e8e68)[_0xbe26('0x66')](','):[];if(_0x162b6f[_0xbe26('0x67')]===0x5){_0x162b6f[_0xbe26('0x68')](-0x1,0x1);}_0x162b6f['unshift'](_0x1a5076);return encryptor[_0xbe26('0x69')](_0x162b6f[_0xbe26('0x6a')](','));};function signJwt(_0x1963f0){var _0x5312d7=BPromise['promisify'](jwt[_0xbe26('0x6b')],{'context':jwt});var _0x1bd5e4=_0x1963f0[_0xbe26('0x6c')]||config['secrets'][_0xbe26('0x6d')];return new BPromise(function(_0x4e0aa9,_0x107e1e){_0x5312d7(_0x1963f0['payload'],_0x1bd5e4,_0x1963f0[_0xbe26('0x6e')])['then'](function(_0x1cf954){_0x4e0aa9(_0x1cf954);})[_0xbe26('0x32')](function(_0x1af350){_0x107e1e(_0x1af350);});});}function verifyJwt(_0x1cc949,_0x3894eb,_0x1be60e){var _0x3357a2=BPromise[_0xbe26('0x6f')](jwt[_0xbe26('0x70')],{'context':jwt});var _0x220061=_0x1be60e||config[_0xbe26('0xb')][_0xbe26('0x6d')];return new BPromise(function(_0x408a4d,_0x4b41ad){_0x3357a2(_0x1cc949,_0x220061,_0x3894eb)[_0xbe26('0x2b')](function(_0x55fd66){_0x408a4d(_0x55fd66);})[_0xbe26('0x32')](function(_0x427d6a){_0x4b41ad(_0x427d6a);});});}function generateNonce(){return crypto[_0xbe26('0x71')](0x10)['toString'](_0xbe26('0x72'));}function generateIssuedAt(){return Math[_0xbe26('0x73')](Date[_0xbe26('0x74')]()/0x3e8)[_0xbe26('0x75')]();}function createJwt(_0xe3a6b0){var _0x19b863={'payload':{'iat':_0xe3a6b0['apiKeyIat'],'nonce':_0xe3a6b0[_0xbe26('0x56')]},'options':{'algorithm':_0xbe26('0x76'),'subject':_0xe3a6b0['id'][_0xbe26('0x75')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x19b863)[_0xbe26('0x2b')](function(_0x231c67){return{'iat':_0xe3a6b0[_0xbe26('0x58')],'nonce':_0xe3a6b0[_0xbe26('0x56')],'token':_0x231c67};});}