Built motion from commit (unavailable).|2.5.31
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x69d3=['hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','isChatInteractionAuthorized','isAuthenticated','user','ChatInteraction','findOne','closed','status','disposition','json','unmanaged','use','headers','authorization','startsWith','Basic','User','then','authenticate','Wrong\x20credentials.','catch','Bearer','query','apikey','getUuid','sub','Setting','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','blocked','blockedAt','blockDuration','minutes','User\x20not\x20found.','canUpdate','Forbidden','isMiddleware','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','retrieveApiKey','isNil','apiKeyIat','generateApiKey','validatePasswordPattern','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','splice','unshift','encryptString','join','promisify','sign','secret','payload','verify','toString','hex','floor','now','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','express-jwt','basic-auth','crypto','bluebird','util','moment','secrets','session','name','internal','email','permissions','md5secret','voicePause','mailPause','faxPause','smsPause','showWebBar','crudPermissions','allowmessenger','phoneBarAutoAnswer','phoneBarDnd','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl'];(function(_0x4edc7f,_0x1c4c90){var _0x3bc4c6=function(_0x2da577){while(--_0x2da577){_0x4edc7f['push'](_0x4edc7f['shift']());}};_0x3bc4c6(++_0x1c4c90);}(_0x69d3,0x12b));var _0x369d=function(_0x30ce8b,_0x228d98){_0x30ce8b=_0x30ce8b-0x0;var _0x593958=_0x69d3[_0x30ce8b];return _0x593958;};'use strict';var db=require(_0x369d('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x369d('0x1'));var licenseUtil=require(_0x369d('0x2'));var encryptor=require(_0x369d('0x3'));var _=require('lodash');var jwt=require('jsonwebtoken');var expressJwt=require(_0x369d('0x4'));var compose=require('composable-middleware');var basicAuth=require(_0x369d('0x5'));var crypto=require(_0x369d('0x6'));var BPromise=require(_0x369d('0x7'));var util=require(_0x369d('0x8'));var moment=require(_0x369d('0x9'));var validateJwt=expressJwt({'secret':config[_0x369d('0xa')][_0x369d('0xb')]});var userAttributes=['id','role','fullname',_0x369d('0xc'),_0x369d('0xd'),_0x369d('0xe'),'userpic',_0x369d('0xf'),_0x369d('0x10'),_0x369d('0x11'),'chatPause',_0x369d('0x12'),_0x369d('0x13'),_0x369d('0x14'),'openchannelPause','pauseType',_0x369d('0x15'),'lastLoginAt','lastPauseAt',_0x369d('0x16'),_0x369d('0x17'),'passwordResetAt','alias',_0x369d('0x18'),'phoneBarAutoAnswerDelay',_0x369d('0x19'),'phoneBarEnableRecording',_0x369d('0x1a'),_0x369d('0x1b'),_0x369d('0x1c'),_0x369d('0x1d'),_0x369d('0x1e'),'phoneBarRemoteControlPort',_0x369d('0x1f'),_0x369d('0x20'),_0x369d('0x21'),_0x369d('0x22'),_0x369d('0x23'),_0x369d('0x24'),_0x369d('0x25'),_0x369d('0x26'),_0x369d('0x27')];exports[_0x369d('0x28')]=function(){return this[_0x369d('0x29')](!![])['use'](function(_0x389ae3,_0x4508ca,_0x5a6e41){if(_0x389ae3[_0x369d('0x2a')]){_0x5a6e41();}else{return db[_0x369d('0x2b')][_0x369d('0x2c')]({'where':{'id':_0x389ae3['params']['id']},'attributes':['id','closed','disposition'],'raw':!![]})['then'](function(_0x404165){if(_0x404165&&_0x404165[_0x369d('0x2d')]){return _0x4508ca[_0x369d('0x2e')](_0x404165[_0x369d('0x2f')]==='unmanaged'?0x195:0x193)[_0x369d('0x30')]({'message':_0x404165[_0x369d('0x2f')]===_0x369d('0x31')?'Unmanaged.':'Forbidden.'});}else{_0x5a6e41();}})['catch'](function(_0x18c4cc){_0x5a6e41(_0x18c4cc);});}});};exports[_0x369d('0x29')]=function isAuthenticated(_0x2fb739){return compose()[_0x369d('0x32')](function(_0x403850,_0xd06ed0,_0x4ec486){var _0x36f313;if(_0x403850[_0x369d('0x33')][_0x369d('0x34')]){if(_[_0x369d('0x35')](_0x403850[_0x369d('0x33')][_0x369d('0x34')],_0x369d('0x36'))){var _0x2b50aa=basicAuth(_0x403850);db[_0x369d('0x37')]['find']({'where':{'name':_0x2b50aa['name']}})[_0x369d('0x38')](function(_0x3ecf13){if(!_0x3ecf13||!_0x3ecf13[_0x369d('0x39')](_0x2b50aa['pass'])){return _0xd06ed0[_0x369d('0x2e')](0x191)[_0x369d('0x30')]({'message':_0x369d('0x3a')});}_0x403850['user']={'id':_0x3ecf13['id']};_0x4ec486();})[_0x369d('0x3b')](function(_0x5ac456){_0x4ec486(_0x5ac456);});}else if(_[_0x369d('0x35')](_0x403850[_0x369d('0x33')][_0x369d('0x34')],_0x369d('0x3c'))){validateJwt(_0x403850,_0xd06ed0,_0x4ec486);}else{if(_0x2fb739){_0x4ec486();}else{return _0xd06ed0['status'](0x193)['json']({'message':'Unknown\x20authorization\x20format'});}}}else if(_0x403850[_0x369d('0x3d')][_0x369d('0x3e')]){try{var _0x21f940={'audience':hardwareConf[_0x369d('0x3f')](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x403850[_0x369d('0x3d')][_0x369d('0x3e')],_0x21f940)[_0x369d('0x38')](function(_0x29d397){return db[_0x369d('0x37')]['find']({'where':{'id':_0x29d397[_0x369d('0x40')]}})['then'](function(_0x3d256c){_0x36f313=_0x3d256c;return db[_0x369d('0x41')][_0x369d('0x2c')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts','blockDuration'],'raw':!![]});})[_0x369d('0x38')](function(_0xfabbd9){if(!_0x36f313||!_['isEqual'](_0x36f313[_0x369d('0x42')],_0x29d397[_0x369d('0x43')])){return _0xd06ed0[_0x369d('0x2e')](0x191)['json']({'message':_0x369d('0x44')});}if(_0x36f313['disabled']){return _0xd06ed0[_0x369d('0x2e')](0x191)[_0x369d('0x30')]({'message':_0x369d('0x45')});}if(_0x36f313[_0x369d('0x46')]){if(_0xfabbd9['blockDuration']>0x0){if(moment(_0x36f313[_0x369d('0x47')])['add'](_0xfabbd9[_0x369d('0x48')],_0x369d('0x49'))>moment()){return _0xd06ed0[_0x369d('0x2e')](0x191)[_0x369d('0x30')]({'message':_0x369d('0x45')});}}else{return _0xd06ed0[_0x369d('0x2e')](0x191)[_0x369d('0x30')]({'message':_0x369d('0x45')});}}_0x403850[_0x369d('0x2a')]={'id':_0x36f313['id']};_0x4ec486();});})[_0x369d('0x3b')](function(){return _0xd06ed0['status'](0x191)[_0x369d('0x30')]({'message':_0x369d('0x45')});});}catch(_0x1832d3){_0x4ec486(_0x1832d3);}}else if(_0x2fb739){_0x4ec486();}else{return _0xd06ed0['status'](0x193)['json']({'message':'Unknown\x20authorization\x20format'});}})[_0x369d('0x32')](function(_0x327271,_0x25c8c8,_0x401606){if(_0x327271[_0x369d('0x2a')]){db[_0x369d('0x37')]['find']({'where':{'id':_0x327271['user']['id']},'attributes':userAttributes})[_0x369d('0x38')](function(_0x54ca20){if(!_0x54ca20){return _0x25c8c8[_0x369d('0x2e')](0x194)['json']({'message':_0x369d('0x4a')});}_0x327271[_0x369d('0x2a')]=_0x54ca20;_0x401606();})['catch'](function(_0x2d9d97){_0x401606(_0x2d9d97);});}else if(_0x2fb739){_0x401606();}else{return _0x25c8c8['status'](0x194)['json']({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x369d('0x4b')]=function canUpdate(){return compose()[_0x369d('0x32')](function(_0x49ba66,_0x133157,_0x4f9d0c){return licenseUtil['getLicense']()['then'](function(_0x5cc2a9){if(_0x5cc2a9['update']){_0x4f9d0c();}else{return _0x133157[_0x369d('0x2e')](0x193)['json']({'message':_0x369d('0x4c')});}})[_0x369d('0x3b')](function(_0x4d6436){_0x4f9d0c(_0x4d6436);});});};exports[_0x369d('0x4d')]=function(_0x4500b6,_0x580e4e,_0x3c3103){_0x4500b6[_0x369d('0x4d')]=!![];return _0x3c3103();};exports['signToken']=function signToken(_0x17696a){return signJwt(_0x17696a);};exports[_0x369d('0x4e')]=function(_0x22bc40,_0x3df8d1){if(!_0x22bc40[_0x369d('0x2a')]){return _0x3df8d1[_0x369d('0x2e')](0x194)[_0x369d('0x30')]({'message':_0x369d('0x4f')});}var _0x4622dc={'payload':{'id':_0x22bc40[_0x369d('0x2a')]['id'],'role':_0x22bc40['user']['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x4622dc)['then'](function(_0x454e31){_0x3df8d1[_0x369d('0x50')](_0x369d('0x51'),_0x454e31);_0x3df8d1['redirect']('/dashboards/general');})[_0x369d('0x3b')](function(_0x536dab){return _0x3df8d1['status'](0x1f4)['send'](_0x536dab);});};exports[_0x369d('0x52')]=function(_0xce3c53){if(_[_0x369d('0x53')](_0xce3c53[_0x369d('0x42')])||_['isNil'](_0xce3c53[_0x369d('0x54')])){return null;}else{return createJwt(_0xce3c53);}};exports[_0x369d('0x55')]=function(_0x1a3224){_0x1a3224['apiKeyNonce']=generateNonce();_0x1a3224[_0x369d('0x54')]=generateIssuedAt();return createJwt(_0x1a3224);};exports['regenerateApiKey']=function(_0x26cca5,_0x3f444c){var _0x2fc011=_0x26cca5[_0x369d('0x3d')]['apikey'];if(_0x2fc011){var _0x46b34e={'nonce':_0x3f444c[_0x369d('0x42')],'iat':_0x3f444c[_0x369d('0x54')],'audience':hardwareConf[_0x369d('0x3f')](),'issuer':hardwareConf[_0x369d('0x3f')]()};return verifyJwt(_0x2fc011,_0x46b34e)[_0x369d('0x38')](function(){return generateApiKey(_0x3f444c);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0x369d('0x56')]=function(_0x11751f){var _0x1ef391=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x1ef391['test'](_0x11751f))throw new db[(_0x369d('0x57'))][(_0x369d('0x58'))](_0x369d('0x59'));return;};exports['validatePasswordHistory']=function(_0x3ea94c,_0x4bfcc7,_0x22981c){var _0x320c29=encryptor[_0x369d('0x5a')](_0x4bfcc7)[_0x369d('0x5b')](',');for(var _0x420eba=0x0;_0x420eba<_0x22981c;_0x420eba++){if(!_0x320c29[_0x420eba])break;if(_0x3ea94c[_0x369d('0x5c')]()===_0x320c29[_0x420eba][_0x369d('0x5c')]()){var _0x12ebb4=util[_0x369d('0x5d')](_0x369d('0x5e'),_0x22981c);if(_0x22981c===0x1){_0x12ebb4='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x369d('0x57'))][(_0x369d('0x58'))](_0x12ebb4);}}return;};exports[_0x369d('0x5f')]=function(_0x330954,_0x8d0006){var _0x144007=_0x8d0006?encryptor[_0x369d('0x5a')](_0x8d0006)[_0x369d('0x5b')](','):[];if(_0x144007[_0x369d('0x60')]===0x5){_0x144007[_0x369d('0x61')](-0x1,0x1);}_0x144007[_0x369d('0x62')](_0x330954);return encryptor[_0x369d('0x63')](_0x144007[_0x369d('0x64')](','));};function signJwt(_0x4ce74d){var _0x21682a=BPromise[_0x369d('0x65')](jwt[_0x369d('0x66')],{'context':jwt});var _0x1675f9=_0x4ce74d[_0x369d('0x67')]||config[_0x369d('0xa')][_0x369d('0xb')];return new BPromise(function(_0x492dd0,_0x1711c6){_0x21682a(_0x4ce74d[_0x369d('0x68')],_0x1675f9,_0x4ce74d['options'])[_0x369d('0x38')](function(_0x35544e){_0x492dd0(_0x35544e);})[_0x369d('0x3b')](function(_0xda75a3){_0x1711c6(_0xda75a3);});});}function verifyJwt(_0x162519,_0x33523e,_0x294f3c){var _0x4508c0=BPromise[_0x369d('0x65')](jwt[_0x369d('0x69')],{'context':jwt});var _0x2be415=_0x294f3c||config[_0x369d('0xa')]['session'];return new BPromise(function(_0x15dfdd,_0x52db2a){_0x4508c0(_0x162519,_0x2be415,_0x33523e)[_0x369d('0x38')](function(_0x140b05){_0x15dfdd(_0x140b05);})[_0x369d('0x3b')](function(_0x3a2da1){_0x52db2a(_0x3a2da1);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0x369d('0x6a')](_0x369d('0x6b'));}function generateIssuedAt(){return Math[_0x369d('0x6c')](Date[_0x369d('0x6d')]()/0x3e8)[_0x369d('0x6a')]();}function createJwt(_0x3f9966){var _0x2cf712={'payload':{'iat':_0x3f9966[_0x369d('0x54')],'nonce':_0x3f9966[_0x369d('0x42')]},'options':{'algorithm':'HS512','subject':_0x3f9966['id'][_0x369d('0x6a')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x369d('0x3f')]()}};return signJwt(_0x2cf712)[_0x369d('0x38')](function(_0x59544d){return{'iat':_0x3f9966[_0x369d('0x54')],'nonce':_0x3f9966[_0x369d('0x42')],'token':_0x59544d};});}