Built motion from commit 00bf23f6.|2.6.16
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x70e0=['express-jwt','composable-middleware','crypto','util','role','fullname','name','internal','email','userpic','permissions','chatPause','mailPause','faxPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','phoneBarAutoAnswer','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','settingsEnabled','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','selectRecallMeCampaign','chatAutoanswer','chatAutoanswerDelay','emailAutoanswer','emailAutoanswerDelay','openchannelAutoanswerDelay','faxAutoanswer','faxAutoanswerDelay','whatsappAutoanswerDelay','isAuthenticated','use','user','ChatInteraction','findOne','closed','disposition','then','unmanaged','json','Unmanaged.','catch','headers','authorization','startsWith','Basic','User','authenticate','Bearer','status','query','apikey','getUuid','find','sub','Setting','allowedLoginAttempts','blockDuration','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','blockedAt','add','minutes','Unknown\x20authorization\x20format','User\x20not\x20found.','canUpdate','getLicense','update','Forbidden','webrtc','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','motion.token','redirect','send','retrieveApiKey','isNil','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','split','splice','encryptString','promisify','sign','secret','secrets','session','options','verify','randomBytes','hex','floor','now','toString','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','lodash','jsonwebtoken'];(function(_0x1531ea,_0x4a3022){var _0x93314b=function(_0x1c4ea2){while(--_0x1c4ea2){_0x1531ea['push'](_0x1531ea['shift']());}};_0x93314b(++_0x4a3022);}(_0x70e0,0x17b));var _0x070e=function(_0x5b1022,_0x3d12d3){_0x5b1022=_0x5b1022-0x0;var _0x10f404=_0x70e0[_0x5b1022];return _0x10f404;};'use strict';var db=require(_0x070e('0x0'))['db'];var config=require(_0x070e('0x1'));var hardwareConf=require(_0x070e('0x2'));var licenseUtil=require('../../config/license/util');var encryptor=require('../encryptor');var _=require(_0x070e('0x3'));var jwt=require(_0x070e('0x4'));var expressJwt=require(_0x070e('0x5'));var compose=require(_0x070e('0x6'));var basicAuth=require('basic-auth');var crypto=require(_0x070e('0x7'));var BPromise=require('bluebird');var util=require(_0x070e('0x8'));var moment=require('moment');var validateJwt=expressJwt({'secret':config['secrets']['session']});var userAttributes=['id',_0x070e('0x9'),_0x070e('0xa'),_0x070e('0xb'),_0x070e('0xc'),_0x070e('0xd'),_0x070e('0xe'),_0x070e('0xf'),'md5secret','voicePause',_0x070e('0x10'),_0x070e('0x11'),_0x070e('0x12'),_0x070e('0x13'),_0x070e('0x14'),_0x070e('0x15'),_0x070e('0x16'),_0x070e('0x17'),_0x070e('0x18'),_0x070e('0x19'),_0x070e('0x1a'),'passwordResetAt','alias',_0x070e('0x1b'),'phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording',_0x070e('0x1c'),_0x070e('0x1d'),'phoneBarExpires','phoneBarPrefixRequired',_0x070e('0x1e'),_0x070e('0x1f'),_0x070e('0x20'),_0x070e('0x21'),'userProfileId','privacyEnabled',_0x070e('0x22'),_0x070e('0x23'),_0x070e('0x24'),_0x070e('0x25'),_0x070e('0x26'),'ignorePauseForPreviewCalls',_0x070e('0x27'),_0x070e('0x28'),_0x070e('0x29'),_0x070e('0x2a'),_0x070e('0x2b'),'smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer',_0x070e('0x2c'),_0x070e('0x2d'),_0x070e('0x2e'),'whatsappAutoanswer',_0x070e('0x2f')];exports['isChatInteractionAuthorized']=function(){return this[_0x070e('0x30')](!![])[_0x070e('0x31')](function(_0x27a01e,_0x33e8c6,_0x28a1c3){if(_0x27a01e[_0x070e('0x32')]){_0x28a1c3();}else{return db[_0x070e('0x33')][_0x070e('0x34')]({'where':{'id':_0x27a01e['params']['id']},'attributes':['id',_0x070e('0x35'),_0x070e('0x36')],'raw':!![]})[_0x070e('0x37')](function(_0x503f4d){if(_0x503f4d&&_0x503f4d[_0x070e('0x35')]){return _0x33e8c6['status'](_0x503f4d['disposition']===_0x070e('0x38')?0x195:0x193)[_0x070e('0x39')]({'message':_0x503f4d[_0x070e('0x36')]===_0x070e('0x38')?_0x070e('0x3a'):'Forbidden.'});}else{_0x28a1c3();}})[_0x070e('0x3b')](function(_0x219e48){_0x28a1c3(_0x219e48);});}});};exports[_0x070e('0x30')]=function isAuthenticated(_0x1d2a34){return compose()[_0x070e('0x31')](function(_0x28d7f2,_0x1a1892,_0x26373b){var _0x5e8326;if(_0x28d7f2[_0x070e('0x3c')][_0x070e('0x3d')]){if(_[_0x070e('0x3e')](_0x28d7f2['headers']['authorization'],_0x070e('0x3f'))){var _0x46065c=basicAuth(_0x28d7f2);db[_0x070e('0x40')]['find']({'where':{'name':_0x46065c[_0x070e('0xb')]}})[_0x070e('0x37')](function(_0x3a9425){if(!_0x3a9425||!_0x3a9425[_0x070e('0x41')](_0x46065c['pass'])){return _0x1a1892['status'](0x191)['json']({'message':'Wrong\x20credentials.'});}_0x28d7f2[_0x070e('0x32')]={'id':_0x3a9425['id']};_0x26373b();})['catch'](function(_0x1dff97){_0x26373b(_0x1dff97);});}else if(_[_0x070e('0x3e')](_0x28d7f2['headers']['authorization'],_0x070e('0x42'))){validateJwt(_0x28d7f2,_0x1a1892,_0x26373b);}else{if(_0x1d2a34){_0x26373b();}else{return _0x1a1892[_0x070e('0x43')](0x193)['json']({'message':'Unknown\x20authorization\x20format'});}}}else if(_0x28d7f2[_0x070e('0x44')][_0x070e('0x45')]){try{var _0x444d02={'audience':hardwareConf[_0x070e('0x46')](),'issuer':hardwareConf[_0x070e('0x46')]()};verifyJwt(_0x28d7f2['query']['apikey'],_0x444d02)[_0x070e('0x37')](function(_0x3011c4){return db[_0x070e('0x40')][_0x070e('0x47')]({'where':{'id':_0x3011c4[_0x070e('0x48')]}})['then'](function(_0x22f3a9){_0x5e8326=_0x22f3a9;return db[_0x070e('0x49')]['findOne']({'where':{'id':0x1},'attributes':[_0x070e('0x4a'),_0x070e('0x4b')],'raw':!![]});})['then'](function(_0x4d4ee8){if(!_0x5e8326||!_['isEqual'](_0x5e8326[_0x070e('0x4c')],_0x3011c4[_0x070e('0x4d')])){return _0x1a1892[_0x070e('0x43')](0x191)[_0x070e('0x39')]({'message':_0x070e('0x4e')});}if(_0x5e8326['disabled']){return _0x1a1892[_0x070e('0x43')](0x191)[_0x070e('0x39')]({'message':_0x070e('0x4f')});}if(_0x5e8326['blocked']){if(_0x4d4ee8[_0x070e('0x4b')]>0x0){if(moment(_0x5e8326[_0x070e('0x50')])[_0x070e('0x51')](_0x4d4ee8['blockDuration'],_0x070e('0x52'))>moment()){return _0x1a1892[_0x070e('0x43')](0x191)['json']({'message':_0x070e('0x4f')});}}else{return _0x1a1892['status'](0x191)[_0x070e('0x39')]({'message':_0x070e('0x4f')});}}_0x28d7f2[_0x070e('0x32')]={'id':_0x5e8326['id']};_0x26373b();});})[_0x070e('0x3b')](function(){return _0x1a1892[_0x070e('0x43')](0x191)['json']({'message':_0x070e('0x4f')});});}catch(_0x5db2ce){_0x26373b(_0x5db2ce);}}else if(_0x1d2a34){_0x26373b();}else{return _0x1a1892['status'](0x193)[_0x070e('0x39')]({'message':_0x070e('0x53')});}})[_0x070e('0x31')](function(_0x4d52ff,_0x2ad56c,_0x1223be){if(_0x4d52ff[_0x070e('0x32')]){db[_0x070e('0x40')]['find']({'where':{'id':_0x4d52ff[_0x070e('0x32')]['id']},'attributes':userAttributes})['then'](function(_0x544b53){if(!_0x544b53){return _0x2ad56c['status'](0x194)[_0x070e('0x39')]({'message':_0x070e('0x54')});}_0x4d52ff[_0x070e('0x32')]=_0x544b53;_0x1223be();})[_0x070e('0x3b')](function(_0x34f23e){_0x1223be(_0x34f23e);});}else if(_0x1d2a34){_0x1223be();}else{return _0x2ad56c['status'](0x194)[_0x070e('0x39')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x070e('0x55')]=function canUpdate(){return compose()[_0x070e('0x31')](function(_0xff760c,_0x52fcea,_0x54285a){return licenseUtil[_0x070e('0x56')]()['then'](function(_0x35349f){if(_0x35349f[_0x070e('0x57')]){_0x54285a();}else{return _0x52fcea[_0x070e('0x43')](0x193)['json']({'message':_0x070e('0x58')});}})[_0x070e('0x3b')](function(_0x48d836){_0x54285a(_0x48d836);});});};exports['isWebrtcLicence']=function isWebrtcLicence(){return compose()[_0x070e('0x31')](function(_0x945901,_0x2d43ce,_0x1fc7c4){return licenseUtil[_0x070e('0x56')]()['then'](function(_0x20b80e){if(_0x20b80e[_0x070e('0x59')]){_0x1fc7c4();}else{return _0x2d43ce[_0x070e('0x43')](0x193)[_0x070e('0x39')]({'message':_0x070e('0x58')});}})[_0x070e('0x3b')](function(_0x1f54d5){_0x1fc7c4(_0x1f54d5);});});};exports[_0x070e('0x5a')]=function(_0xd67987,_0x66a3f3,_0x210c4d){_0xd67987[_0x070e('0x5a')]=!![];return _0x210c4d();};exports[_0x070e('0x5b')]=function signToken(_0x216d27){return signJwt(_0x216d27);};exports[_0x070e('0x5c')]=function(_0x5e051a,_0x171621){if(!_0x5e051a[_0x070e('0x32')]){return _0x171621[_0x070e('0x43')](0x194)[_0x070e('0x39')]({'message':_0x070e('0x5d')});}var _0x3bd738={'payload':{'id':_0x5e051a[_0x070e('0x32')]['id'],'role':_0x5e051a[_0x070e('0x32')][_0x070e('0x9')]},'options':{'expiresIn':0x15180}};return signJwt(_0x3bd738)['then'](function(_0x251696){_0x171621['cookie'](_0x070e('0x5e'),_0x251696);_0x171621[_0x070e('0x5f')]('/dashboards/general');})[_0x070e('0x3b')](function(_0x130a50){return _0x171621[_0x070e('0x43')](0x1f4)[_0x070e('0x60')](_0x130a50);});};exports[_0x070e('0x61')]=function(_0x1e8a4f){if(_[_0x070e('0x62')](_0x1e8a4f['apiKeyNonce'])||_[_0x070e('0x62')](_0x1e8a4f['apiKeyIat'])){return null;}else{return createJwt(_0x1e8a4f);}};exports['generateApiKey']=function(_0x3a06c6){_0x3a06c6[_0x070e('0x4c')]=generateNonce();_0x3a06c6[_0x070e('0x63')]=generateIssuedAt();return createJwt(_0x3a06c6);};exports[_0x070e('0x64')]=function(_0x202015,_0x7948ed){var _0x440fa1=_0x202015[_0x070e('0x44')]['apikey'];if(_0x440fa1){var _0x477e69={'nonce':_0x7948ed['apiKeyNonce'],'iat':_0x7948ed['apiKeyIat'],'audience':hardwareConf[_0x070e('0x46')](),'issuer':hardwareConf[_0x070e('0x46')]()};return verifyJwt(_0x440fa1,_0x477e69)['then'](function(){return generateApiKey(_0x7948ed);});}else{throw{'message':_0x070e('0x65')};}};exports[_0x070e('0x66')]=function(_0x210f4a){var _0x2f8104=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x2f8104[_0x070e('0x67')](_0x210f4a))throw new db[(_0x070e('0x68'))][(_0x070e('0x69'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports['validatePasswordHistory']=function(_0x5943e3,_0x3087e5,_0x1948a5){var _0x29f497=encryptor[_0x070e('0x6a')](_0x3087e5)['split'](',');for(var _0x25f34c=0x0;_0x25f34c<_0x1948a5;_0x25f34c++){if(!_0x29f497[_0x25f34c])break;if(_0x5943e3['toLowerCase']()===_0x29f497[_0x25f34c][_0x070e('0x6b')]()){var _0x1cbb7e=util[_0x070e('0x6c')](_0x070e('0x6d'),_0x1948a5);if(_0x1948a5===0x1){_0x1cbb7e=_0x070e('0x6e');}throw new db[(_0x070e('0x68'))]['ValidationError'](_0x1cbb7e);}}return;};exports[_0x070e('0x6f')]=function(_0x18e8d0,_0x8aaf00){var _0x533431=_0x8aaf00?encryptor[_0x070e('0x6a')](_0x8aaf00)[_0x070e('0x70')](','):[];if(_0x533431['length']===0x5){_0x533431[_0x070e('0x71')](-0x1,0x1);}_0x533431['unshift'](_0x18e8d0);return encryptor[_0x070e('0x72')](_0x533431['join'](','));};function signJwt(_0x4cb86f){var _0x4b354d=BPromise[_0x070e('0x73')](jwt[_0x070e('0x74')],{'context':jwt});var _0x1100d8=_0x4cb86f[_0x070e('0x75')]||config[_0x070e('0x76')][_0x070e('0x77')];return new BPromise(function(_0x498bc6,_0x841c89){_0x4b354d(_0x4cb86f['payload'],_0x1100d8,_0x4cb86f[_0x070e('0x78')])['then'](function(_0x2e10f7){_0x498bc6(_0x2e10f7);})[_0x070e('0x3b')](function(_0x5b0b46){_0x841c89(_0x5b0b46);});});}function verifyJwt(_0x1bcdc3,_0x50399e,_0x1a9e25){var _0x139630=BPromise[_0x070e('0x73')](jwt[_0x070e('0x79')],{'context':jwt});var _0x764b06=_0x1a9e25||config[_0x070e('0x76')][_0x070e('0x77')];return new BPromise(function(_0x148f1d,_0x3ef9cc){_0x139630(_0x1bcdc3,_0x764b06,_0x50399e)[_0x070e('0x37')](function(_0x40c560){_0x148f1d(_0x40c560);})[_0x070e('0x3b')](function(_0x455bf2){_0x3ef9cc(_0x455bf2);});});}function generateNonce(){return crypto[_0x070e('0x7a')](0x10)['toString'](_0x070e('0x7b'));}function generateIssuedAt(){return Math[_0x070e('0x7c')](Date[_0x070e('0x7d')]()/0x3e8)[_0x070e('0x7e')]();}function createJwt(_0x5712d1){var _0x2ccd8d={'payload':{'iat':_0x5712d1[_0x070e('0x63')],'nonce':_0x5712d1[_0x070e('0x4c')]},'options':{'algorithm':_0x070e('0x7f'),'subject':_0x5712d1['id'][_0x070e('0x7e')](),'issuer':hardwareConf[_0x070e('0x46')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x2ccd8d)[_0x070e('0x37')](function(_0x7d154){return{'iat':_0x5712d1[_0x070e('0x63')],'nonce':_0x5712d1[_0x070e('0x4c')],'token':_0x7d154};});}