Built motion from commit (unavailable).|2.5.22
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x46d5=['now','HS512','toString','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','moment','session','role','fullname','name','internal','email','userpic','permissions','md5secret','voicePause','faxPause','smsPause','openchannelPause','pauseType','lastLoginAt','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarRemoteControlPort','hotdesk','userProfileId','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','ChatInteraction','findOne','params','closed','disposition','then','status','unmanaged','Unmanaged.','catch','headers','authorization','startsWith','Basic','User','find','pass','json','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','Invalid\x20API\x20access\x20key','blocked','blockedAt','add','user','User\x20not\x20found.','canUpdate','getLicense','update','isMiddleware','signToken','cookie','motion.token','redirect','/dashboards/general','retrieveApiKey','isNil','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','Sequelize','updatePasswordsHistory','length','splice','encryptString','join','promisify','secrets','payload','verify','randomBytes','hex','floor'];(function(_0x564db2,_0xeab590){var _0x506c6b=function(_0x4c60dc){while(--_0x4c60dc){_0x564db2['push'](_0x564db2['shift']());}};_0x506c6b(++_0xeab590);}(_0x46d5,0x168));var _0x546d=function(_0x4b369d,_0x265eb8){_0x4b369d=_0x4b369d-0x0;var _0x571a98=_0x46d5[_0x4b369d];return _0x571a98;};'use strict';var db=require('../../mysqldb')['db'];var config=require(_0x546d('0x0'));var hardwareConf=require(_0x546d('0x1'));var licenseUtil=require(_0x546d('0x2'));var encryptor=require(_0x546d('0x3'));var _=require('lodash');var jwt=require(_0x546d('0x4'));var expressJwt=require(_0x546d('0x5'));var compose=require(_0x546d('0x6'));var basicAuth=require(_0x546d('0x7'));var crypto=require(_0x546d('0x8'));var BPromise=require(_0x546d('0x9'));var util=require('util');var moment=require(_0x546d('0xa'));var validateJwt=expressJwt({'secret':config['secrets'][_0x546d('0xb')]});var userAttributes=['id',_0x546d('0xc'),_0x546d('0xd'),_0x546d('0xe'),_0x546d('0xf'),_0x546d('0x10'),_0x546d('0x11'),_0x546d('0x12'),_0x546d('0x13'),_0x546d('0x14'),'chatPause','mailPause',_0x546d('0x15'),_0x546d('0x16'),_0x546d('0x17'),_0x546d('0x18'),'showWebBar',_0x546d('0x19'),'lastPauseAt','crudPermissions',_0x546d('0x1a'),_0x546d('0x1b'),_0x546d('0x1c'),_0x546d('0x1d'),_0x546d('0x1e'),'phoneBarDnd',_0x546d('0x1f'),_0x546d('0x20'),_0x546d('0x21'),_0x546d('0x22'),'phoneBarPrefixRequired','phoneBarRemoteControl',_0x546d('0x23'),_0x546d('0x24'),'interface',_0x546d('0x25'),_0x546d('0x26')];exports[_0x546d('0x27')]=function(){return this[_0x546d('0x28')](!![])[_0x546d('0x29')](function(_0x2c36f8,_0x41d0d7,_0x50527b){if(_0x2c36f8['user']){_0x50527b();}else{return db[_0x546d('0x2a')][_0x546d('0x2b')]({'where':{'id':_0x2c36f8[_0x546d('0x2c')]['id']},'attributes':['id',_0x546d('0x2d'),_0x546d('0x2e')],'raw':!![]})[_0x546d('0x2f')](function(_0x1718eb){if(_0x1718eb&&_0x1718eb[_0x546d('0x2d')]){return _0x41d0d7[_0x546d('0x30')](_0x1718eb[_0x546d('0x2e')]==='unmanaged'?0x195:0x193)['json']({'message':_0x1718eb[_0x546d('0x2e')]===_0x546d('0x31')?_0x546d('0x32'):'Forbidden.'});}else{_0x50527b();}})[_0x546d('0x33')](function(_0x41c1c6){_0x50527b(_0x41c1c6);});}});};exports['isAuthenticated']=function isAuthenticated(_0x272ab2){return compose()['use'](function(_0x42bb95,_0x3d3fb0,_0x46b99c){var _0x1fccdc;if(_0x42bb95[_0x546d('0x34')][_0x546d('0x35')]){if(_[_0x546d('0x36')](_0x42bb95[_0x546d('0x34')]['authorization'],_0x546d('0x37'))){var _0x118be6=basicAuth(_0x42bb95);db[_0x546d('0x38')][_0x546d('0x39')]({'where':{'name':_0x118be6[_0x546d('0xe')]}})['then'](function(_0x19a0e7){if(!_0x19a0e7||!_0x19a0e7['authenticate'](_0x118be6[_0x546d('0x3a')])){return _0x3d3fb0[_0x546d('0x30')](0x191)[_0x546d('0x3b')]({'message':'Wrong\x20credentials.'});}_0x42bb95['user']={'id':_0x19a0e7['id']};_0x46b99c();})[_0x546d('0x33')](function(_0xb0f666){_0x46b99c(_0xb0f666);});}else if(_['startsWith'](_0x42bb95[_0x546d('0x34')][_0x546d('0x35')],_0x546d('0x3c'))){validateJwt(_0x42bb95,_0x3d3fb0,_0x46b99c);}else{if(_0x272ab2){_0x46b99c();}else{return _0x3d3fb0[_0x546d('0x30')](0x193)[_0x546d('0x3b')]({'message':_0x546d('0x3d')});}}}else if(_0x42bb95[_0x546d('0x3e')]['apikey']){try{var _0xcbe0b1={'audience':hardwareConf[_0x546d('0x3f')](),'issuer':hardwareConf[_0x546d('0x3f')]()};verifyJwt(_0x42bb95[_0x546d('0x3e')][_0x546d('0x40')],_0xcbe0b1)[_0x546d('0x2f')](function(_0xa5597b){return db['User'][_0x546d('0x39')]({'where':{'id':_0xa5597b[_0x546d('0x41')]}})[_0x546d('0x2f')](function(_0xdbbdf3){_0x1fccdc=_0xdbbdf3;return db[_0x546d('0x42')][_0x546d('0x2b')]({'where':{'id':0x1},'attributes':[_0x546d('0x43'),_0x546d('0x44')],'raw':!![]});})[_0x546d('0x2f')](function(_0x1c6e5e){if(!_0x1fccdc||!_[_0x546d('0x45')](_0x1fccdc[_0x546d('0x46')],_0xa5597b[_0x546d('0x47')])){return _0x3d3fb0[_0x546d('0x30')](0x191)[_0x546d('0x3b')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x1fccdc['disabled']){return _0x3d3fb0['status'](0x191)[_0x546d('0x3b')]({'message':_0x546d('0x48')});}if(_0x1fccdc[_0x546d('0x49')]){if(_0x1c6e5e['blockDuration']>0x0){if(moment(_0x1fccdc[_0x546d('0x4a')])[_0x546d('0x4b')](_0x1c6e5e[_0x546d('0x44')],'minutes')>moment()){return _0x3d3fb0[_0x546d('0x30')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}}else{return _0x3d3fb0['status'](0x191)[_0x546d('0x3b')]({'message':_0x546d('0x48')});}}_0x42bb95[_0x546d('0x4c')]={'id':_0x1fccdc['id']};_0x46b99c();});})['catch'](function(){return _0x3d3fb0[_0x546d('0x30')](0x191)[_0x546d('0x3b')]({'message':_0x546d('0x48')});});}catch(_0xfe956b){_0x46b99c(_0xfe956b);}}else if(_0x272ab2){_0x46b99c();}else{return _0x3d3fb0[_0x546d('0x30')](0x193)[_0x546d('0x3b')]({'message':_0x546d('0x3d')});}})[_0x546d('0x29')](function(_0x526bb7,_0x248004,_0x70ed7a){if(_0x526bb7[_0x546d('0x4c')]){db[_0x546d('0x38')]['find']({'where':{'id':_0x526bb7[_0x546d('0x4c')]['id']},'attributes':userAttributes})[_0x546d('0x2f')](function(_0x309adf){if(!_0x309adf){return _0x248004['status'](0x194)[_0x546d('0x3b')]({'message':_0x546d('0x4d')});}_0x526bb7[_0x546d('0x4c')]=_0x309adf;_0x70ed7a();})[_0x546d('0x33')](function(_0xd6adb3){_0x70ed7a(_0xd6adb3);});}else if(_0x272ab2){_0x70ed7a();}else{return _0x248004[_0x546d('0x30')](0x194)[_0x546d('0x3b')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x546d('0x4e')]=function canUpdate(){return compose()[_0x546d('0x29')](function(_0x56f473,_0x58e0ae,_0x5e5e5a){return licenseUtil[_0x546d('0x4f')]()[_0x546d('0x2f')](function(_0x2cd329){if(_0x2cd329[_0x546d('0x50')]){_0x5e5e5a();}else{return _0x58e0ae[_0x546d('0x30')](0x193)[_0x546d('0x3b')]({'message':'Forbidden'});}})[_0x546d('0x33')](function(_0x491a20){_0x5e5e5a(_0x491a20);});});};exports[_0x546d('0x51')]=function(_0x3caebc,_0x1edf8a,_0x59ef89){_0x3caebc[_0x546d('0x51')]=!![];return _0x59ef89();};exports[_0x546d('0x52')]=function signToken(_0xffe99d){return signJwt(_0xffe99d);};exports['setTokenCookie']=function(_0x1f8913,_0x2cbd20){if(!_0x1f8913[_0x546d('0x4c')]){return _0x2cbd20['status'](0x194)['json']({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x4ae6a2={'payload':{'id':_0x1f8913['user']['id'],'role':_0x1f8913['user'][_0x546d('0xc')]},'options':{'expiresIn':0x15180}};return signJwt(_0x4ae6a2)['then'](function(_0x351a00){_0x2cbd20[_0x546d('0x53')](_0x546d('0x54'),_0x351a00);_0x2cbd20[_0x546d('0x55')](_0x546d('0x56'));})[_0x546d('0x33')](function(_0x382458){return _0x2cbd20[_0x546d('0x30')](0x1f4)['send'](_0x382458);});};exports[_0x546d('0x57')]=function(_0x4825e0){if(_[_0x546d('0x58')](_0x4825e0[_0x546d('0x46')])||_[_0x546d('0x58')](_0x4825e0[_0x546d('0x59')])){return null;}else{return createJwt(_0x4825e0);}};exports[_0x546d('0x5a')]=function(_0x1e56e1){_0x1e56e1[_0x546d('0x46')]=generateNonce();_0x1e56e1[_0x546d('0x59')]=generateIssuedAt();return createJwt(_0x1e56e1);};exports[_0x546d('0x5b')]=function(_0x347981,_0x231541){var _0x2bddd2=_0x347981[_0x546d('0x3e')][_0x546d('0x40')];if(_0x2bddd2){var _0x388d48={'nonce':_0x231541[_0x546d('0x46')],'iat':_0x231541[_0x546d('0x59')],'audience':hardwareConf[_0x546d('0x3f')](),'issuer':hardwareConf[_0x546d('0x3f')]()};return verifyJwt(_0x2bddd2,_0x388d48)[_0x546d('0x2f')](function(){return generateApiKey(_0x231541);});}else{throw{'message':_0x546d('0x5c')};}};exports[_0x546d('0x5d')]=function(_0x34827e){var _0x5005ae=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x5005ae[_0x546d('0x5e')](_0x34827e))throw new db['Sequelize'][(_0x546d('0x5f'))](_0x546d('0x60'));return;};exports[_0x546d('0x61')]=function(_0xd150fc,_0x55a5be,_0x78df1a){var _0x354efa=encryptor[_0x546d('0x62')](_0x55a5be)[_0x546d('0x63')](',');for(var _0x3555e0=0x0;_0x3555e0<_0x78df1a;_0x3555e0++){if(!_0x354efa[_0x3555e0])break;if(_0xd150fc[_0x546d('0x64')]()===_0x354efa[_0x3555e0]['toLowerCase']()){var _0x486612=util[_0x546d('0x65')](_0x546d('0x66'),_0x78df1a);if(_0x78df1a===0x1){_0x486612='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x546d('0x67'))]['ValidationError'](_0x486612);}}return;};exports[_0x546d('0x68')]=function(_0xc0e4c7,_0x5b0d9d){var _0x9b1fcf=_0x5b0d9d?encryptor['decryptString'](_0x5b0d9d)['split'](','):[];if(_0x9b1fcf[_0x546d('0x69')]===0x5){_0x9b1fcf[_0x546d('0x6a')](-0x1,0x1);}_0x9b1fcf['unshift'](_0xc0e4c7);return encryptor[_0x546d('0x6b')](_0x9b1fcf[_0x546d('0x6c')](','));};function signJwt(_0x5811bd){var _0xaed96c=BPromise[_0x546d('0x6d')](jwt['sign'],{'context':jwt});var _0x2232c7=_0x5811bd['secret']||config[_0x546d('0x6e')]['session'];return new BPromise(function(_0x593635,_0x48e506){_0xaed96c(_0x5811bd[_0x546d('0x6f')],_0x2232c7,_0x5811bd['options'])['then'](function(_0x39c325){_0x593635(_0x39c325);})[_0x546d('0x33')](function(_0x30475b){_0x48e506(_0x30475b);});});}function verifyJwt(_0x26717b,_0x4068f4,_0x199622){var _0x56fd5d=BPromise['promisify'](jwt[_0x546d('0x70')],{'context':jwt});var _0x4bcf0d=_0x199622||config[_0x546d('0x6e')][_0x546d('0xb')];return new BPromise(function(_0x54b081,_0x9f333e){_0x56fd5d(_0x26717b,_0x4bcf0d,_0x4068f4)[_0x546d('0x2f')](function(_0x3d4e80){_0x54b081(_0x3d4e80);})[_0x546d('0x33')](function(_0x2d8498){_0x9f333e(_0x2d8498);});});}function generateNonce(){return crypto[_0x546d('0x71')](0x10)['toString'](_0x546d('0x72'));}function generateIssuedAt(){return Math[_0x546d('0x73')](Date[_0x546d('0x74')]()/0x3e8)['toString']();}function createJwt(_0x4301e6){var _0x2c8757={'payload':{'iat':_0x4301e6[_0x546d('0x59')],'nonce':_0x4301e6[_0x546d('0x46')]},'options':{'algorithm':_0x546d('0x75'),'subject':_0x4301e6['id'][_0x546d('0x76')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x2c8757)[_0x546d('0x2f')](function(_0x1134cc){return{'iat':_0x4301e6[_0x546d('0x59')],'nonce':_0x4301e6[_0x546d('0x46')],'token':_0x1134cc};});}