Built motion from commit d1eab355.|2.6.28
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x23ab=['randomBytes','toString','hex','floor','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','basic-auth','crypto','util','secrets','role','fullname','name','internal','email','userpic','permissions','md5secret','faxPause','smsPause','openchannelPause','pauseType','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','privacyEnabled','wssPort','downloadOmnichannelInteractions','ignorePauseForPreviewCalls','selectRecallMeCampaign','chatAutoanswer','chatAutoanswerDelay','emailAutoanswer','smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer','openchannelAutoanswerDelay','faxAutoanswer','faxAutoanswerDelay','whatsappAutoanswer','messengerSoundNotification','isAuthenticated','user','ChatInteraction','params','closed','disposition','then','forceDownload','status','json','unmanaged','Forbidden.','catch','headers','startsWith','authorization','Basic','User','find','authenticate','pass','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','findOne','allowedLoginAttempts','blockDuration','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blocked','add','minutes','use','User\x20object\x20not\x20found.','getLicense','update','Forbidden','isWebrtcLicence','webrtc','isMiddleware','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','split','toLowerCase','updatePasswordsHistory','decryptString','length','splice','unshift','encryptString','join','promisify','sign','options','verify','session'];(function(_0x8153ce,_0xcb6429){var _0x3294bc=function(_0x52382f){while(--_0x52382f){_0x8153ce['push'](_0x8153ce['shift']());}};_0x3294bc(++_0xcb6429);}(_0x23ab,0x116));var _0xb23a=function(_0x3ab51d,_0x2fa01d){_0x3ab51d=_0x3ab51d-0x0;var _0x29a04e=_0x23ab[_0x3ab51d];return _0x29a04e;};'use strict';var db=require('../../mysqldb')['db'];var config=require(_0xb23a('0x0'));var hardwareConf=require(_0xb23a('0x1'));var licenseUtil=require(_0xb23a('0x2'));var encryptor=require(_0xb23a('0x3'));var _=require(_0xb23a('0x4'));var jwt=require(_0xb23a('0x5'));var expressJwt=require('express-jwt');var compose=require('composable-middleware');var basicAuth=require(_0xb23a('0x6'));var crypto=require(_0xb23a('0x7'));var BPromise=require('bluebird');var util=require(_0xb23a('0x8'));var moment=require('moment');var validateJwt=expressJwt({'secret':config[_0xb23a('0x9')]['session']});var userAttributes=['id',_0xb23a('0xa'),_0xb23a('0xb'),_0xb23a('0xc'),_0xb23a('0xd'),_0xb23a('0xe'),_0xb23a('0xf'),_0xb23a('0x10'),_0xb23a('0x11'),'voicePause','chatPause','mailPause',_0xb23a('0x12'),_0xb23a('0x13'),_0xb23a('0x14'),_0xb23a('0x15'),'showWebBar',_0xb23a('0x16'),_0xb23a('0x17'),_0xb23a('0x18'),_0xb23a('0x19'),'passwordResetAt',_0xb23a('0x1a'),_0xb23a('0x1b'),_0xb23a('0x1c'),_0xb23a('0x1d'),_0xb23a('0x1e'),_0xb23a('0x1f'),_0xb23a('0x20'),_0xb23a('0x21'),_0xb23a('0x22'),_0xb23a('0x23'),_0xb23a('0x24'),_0xb23a('0x25'),_0xb23a('0x26'),_0xb23a('0x27'),_0xb23a('0x28'),'settingsEnabled',_0xb23a('0x29'),'downloadVoiceRecordings',_0xb23a('0x2a'),'downloadAttachments',_0xb23a('0x2b'),_0xb23a('0x2c'),_0xb23a('0x2d'),_0xb23a('0x2e'),_0xb23a('0x2f'),'emailAutoanswerDelay',_0xb23a('0x30'),_0xb23a('0x31'),_0xb23a('0x32'),_0xb23a('0x33'),_0xb23a('0x34'),_0xb23a('0x35'),_0xb23a('0x36'),'whatsappAutoanswerDelay',_0xb23a('0x37')];exports['isChatInteractionAuthorized']=function(){return this[_0xb23a('0x38')](!![])['use'](function(_0x303774,_0x35bab6,_0x2e3d48){if(_0x303774[_0xb23a('0x39')]){_0x2e3d48();}else{return db[_0xb23a('0x3a')]['findOne']({'where':{'id':_0x303774[_0xb23a('0x3b')]['id']},'attributes':['id',_0xb23a('0x3c'),_0xb23a('0x3d')],'raw':!![]})[_0xb23a('0x3e')](function(_0x59dfd0){if(_0x59dfd0&&_0x59dfd0['closed']&&!_0x303774['query'][_0xb23a('0x3f')]){return _0x35bab6[_0xb23a('0x40')](_0x59dfd0[_0xb23a('0x3d')]==='unmanaged'?0x195:0x193)[_0xb23a('0x41')]({'message':_0x59dfd0[_0xb23a('0x3d')]===_0xb23a('0x42')?'Unmanaged.':_0xb23a('0x43')});}else{_0x2e3d48();}})[_0xb23a('0x44')](function(_0x4b13e8){_0x2e3d48(_0x4b13e8);});}});};exports['isAuthenticated']=function isAuthenticated(_0x13500a){return compose()['use'](function(_0x1748c0,_0x53577a,_0x3d7a22){var _0x1de1fc;if(_0x1748c0[_0xb23a('0x45')]['authorization']){if(_[_0xb23a('0x46')](_0x1748c0[_0xb23a('0x45')][_0xb23a('0x47')],_0xb23a('0x48'))){var _0x554b21=basicAuth(_0x1748c0);db[_0xb23a('0x49')][_0xb23a('0x4a')]({'where':{'name':_0x554b21[_0xb23a('0xc')]}})[_0xb23a('0x3e')](function(_0x4ee4a8){if(!_0x4ee4a8||!_0x4ee4a8[_0xb23a('0x4b')](_0x554b21[_0xb23a('0x4c')])){return _0x53577a[_0xb23a('0x40')](0x191)[_0xb23a('0x41')]({'message':_0xb23a('0x4d')});}_0x1748c0[_0xb23a('0x39')]={'id':_0x4ee4a8['id']};_0x3d7a22();})[_0xb23a('0x44')](function(_0x56b0c6){_0x3d7a22(_0x56b0c6);});}else if(_[_0xb23a('0x46')](_0x1748c0[_0xb23a('0x45')][_0xb23a('0x47')],_0xb23a('0x4e'))){validateJwt(_0x1748c0,_0x53577a,_0x3d7a22);}else{if(_0x13500a){_0x3d7a22();}else{return _0x53577a[_0xb23a('0x40')](0x193)[_0xb23a('0x41')]({'message':_0xb23a('0x4f')});}}}else if(_0x1748c0[_0xb23a('0x50')][_0xb23a('0x51')]){try{var _0x1cab47={'audience':hardwareConf[_0xb23a('0x52')](),'issuer':hardwareConf[_0xb23a('0x52')]()};verifyJwt(_0x1748c0[_0xb23a('0x50')][_0xb23a('0x51')],_0x1cab47)[_0xb23a('0x3e')](function(_0x160a75){return db['User'][_0xb23a('0x4a')]({'where':{'id':_0x160a75[_0xb23a('0x53')]}})[_0xb23a('0x3e')](function(_0x599682){_0x1de1fc=_0x599682;return db['Setting'][_0xb23a('0x54')]({'where':{'id':0x1},'attributes':[_0xb23a('0x55'),_0xb23a('0x56')],'raw':!![]});})[_0xb23a('0x3e')](function(_0x5092b5){if(!_0x1de1fc||!_['isEqual'](_0x1de1fc[_0xb23a('0x57')],_0x160a75[_0xb23a('0x58')])){return _0x53577a[_0xb23a('0x40')](0x191)[_0xb23a('0x41')]({'message':_0xb23a('0x59')});}if(_0x1de1fc[_0xb23a('0x5a')]){return _0x53577a[_0xb23a('0x40')](0x191)[_0xb23a('0x41')]({'message':_0xb23a('0x5b')});}if(_0x1de1fc[_0xb23a('0x5c')]){if(_0x5092b5[_0xb23a('0x56')]>0x0){if(moment(_0x1de1fc['blockedAt'])[_0xb23a('0x5d')](_0x5092b5[_0xb23a('0x56')],_0xb23a('0x5e'))>moment()){return _0x53577a[_0xb23a('0x40')](0x191)['json']({'message':_0xb23a('0x5b')});}}else{return _0x53577a[_0xb23a('0x40')](0x191)[_0xb23a('0x41')]({'message':_0xb23a('0x5b')});}}_0x1748c0['user']={'id':_0x1de1fc['id']};_0x3d7a22();});})[_0xb23a('0x44')](function(){return _0x53577a[_0xb23a('0x40')](0x191)[_0xb23a('0x41')]({'message':_0xb23a('0x5b')});});}catch(_0x206d2d){_0x3d7a22(_0x206d2d);}}else if(_0x13500a){_0x3d7a22();}else{return _0x53577a[_0xb23a('0x40')](0x193)[_0xb23a('0x41')]({'message':'Unknown\x20authorization\x20format'});}})[_0xb23a('0x5f')](function(_0x44ba0b,_0x47fcce,_0x4abb00){if(_0x44ba0b[_0xb23a('0x39')]){db[_0xb23a('0x49')]['find']({'where':{'id':_0x44ba0b['user']['id']},'attributes':userAttributes})['then'](function(_0x2c83ae){if(!_0x2c83ae){return _0x47fcce['status'](0x194)['json']({'message':'User\x20not\x20found.'});}_0x44ba0b['user']=_0x2c83ae;_0x4abb00();})[_0xb23a('0x44')](function(_0x185537){_0x4abb00(_0x185537);});}else if(_0x13500a){_0x4abb00();}else{return _0x47fcce[_0xb23a('0x40')](0x194)[_0xb23a('0x41')]({'message':_0xb23a('0x60')});}});};exports['canUpdate']=function canUpdate(){return compose()['use'](function(_0x21a9fb,_0x3e09ab,_0x9cf928){return licenseUtil[_0xb23a('0x61')]()[_0xb23a('0x3e')](function(_0x19ac1d){if(_0x19ac1d[_0xb23a('0x62')]){_0x9cf928();}else{return _0x3e09ab[_0xb23a('0x40')](0x193)[_0xb23a('0x41')]({'message':_0xb23a('0x63')});}})[_0xb23a('0x44')](function(_0x3dc780){_0x9cf928(_0x3dc780);});});};exports[_0xb23a('0x64')]=function isWebrtcLicence(){return compose()[_0xb23a('0x5f')](function(_0x19d39f,_0x3ae333,_0x20fbd8){return licenseUtil['getLicense']()['then'](function(_0x2cb89d){if(_0x2cb89d[_0xb23a('0x65')]){_0x20fbd8();}else{return _0x3ae333[_0xb23a('0x40')](0x193)[_0xb23a('0x41')]({'message':_0xb23a('0x63')});}})[_0xb23a('0x44')](function(_0x2d366c){_0x20fbd8(_0x2d366c);});});};exports[_0xb23a('0x66')]=function(_0xd14279,_0x17b2b0,_0x54d880){_0xd14279[_0xb23a('0x66')]=!![];return _0x54d880();};exports['signToken']=function signToken(_0x7d5266){return signJwt(_0x7d5266);};exports[_0xb23a('0x67')]=function(_0x7ce50d,_0x42cd4f){if(!_0x7ce50d[_0xb23a('0x39')]){return _0x42cd4f[_0xb23a('0x40')](0x194)[_0xb23a('0x41')]({'message':_0xb23a('0x68')});}var _0x5cc110={'payload':{'id':_0x7ce50d[_0xb23a('0x39')]['id'],'role':_0x7ce50d[_0xb23a('0x39')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x5cc110)[_0xb23a('0x3e')](function(_0x277914){_0x42cd4f[_0xb23a('0x69')](_0xb23a('0x6a'),_0x277914);_0x42cd4f[_0xb23a('0x6b')](_0xb23a('0x6c'));})[_0xb23a('0x44')](function(_0xbfeac){return _0x42cd4f[_0xb23a('0x40')](0x1f4)[_0xb23a('0x6d')](_0xbfeac);});};exports[_0xb23a('0x6e')]=function(_0x97247){if(_['isNil'](_0x97247[_0xb23a('0x57')])||_[_0xb23a('0x6f')](_0x97247[_0xb23a('0x70')])){return null;}else{return createJwt(_0x97247);}};exports[_0xb23a('0x71')]=function(_0x430994){_0x430994[_0xb23a('0x57')]=generateNonce();_0x430994[_0xb23a('0x70')]=generateIssuedAt();return createJwt(_0x430994);};exports['regenerateApiKey']=function(_0x45bdc6,_0xbf564e){var _0x22e089=_0x45bdc6[_0xb23a('0x50')][_0xb23a('0x51')];if(_0x22e089){var _0x4ffdcc={'nonce':_0xbf564e['apiKeyNonce'],'iat':_0xbf564e['apiKeyIat'],'audience':hardwareConf[_0xb23a('0x52')](),'issuer':hardwareConf[_0xb23a('0x52')]()};return verifyJwt(_0x22e089,_0x4ffdcc)[_0xb23a('0x3e')](function(){return generateApiKey(_0xbf564e);});}else{throw{'message':_0xb23a('0x72')};}};exports[_0xb23a('0x73')]=function(_0x2fe289){var _0x290b47=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x290b47['test'](_0x2fe289))throw new db[(_0xb23a('0x74'))][(_0xb23a('0x75'))](_0xb23a('0x76'));return;};exports['validatePasswordHistory']=function(_0x5e9e7c,_0x4ce0eb,_0x5b0622){var _0x1c4bca=encryptor['decryptString'](_0x4ce0eb)[_0xb23a('0x77')](',');for(var _0x2e8b2a=0x0;_0x2e8b2a<_0x5b0622;_0x2e8b2a++){if(!_0x1c4bca[_0x2e8b2a])break;if(_0x5e9e7c[_0xb23a('0x78')]()===_0x1c4bca[_0x2e8b2a]['toLowerCase']()){var _0x1879c0=util['format']('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x5b0622);if(_0x5b0622===0x1){_0x1879c0='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0xb23a('0x74'))][(_0xb23a('0x75'))](_0x1879c0);}}return;};exports[_0xb23a('0x79')]=function(_0x5ad45d,_0x501d2f){var _0x47be82=_0x501d2f?encryptor[_0xb23a('0x7a')](_0x501d2f)[_0xb23a('0x77')](','):[];if(_0x47be82[_0xb23a('0x7b')]===0x5){_0x47be82[_0xb23a('0x7c')](-0x1,0x1);}_0x47be82[_0xb23a('0x7d')](_0x5ad45d);return encryptor[_0xb23a('0x7e')](_0x47be82[_0xb23a('0x7f')](','));};function signJwt(_0x579953){var _0x4cd59d=BPromise[_0xb23a('0x80')](jwt[_0xb23a('0x81')],{'context':jwt});var _0x5b160f=_0x579953['secret']||config[_0xb23a('0x9')]['session'];return new BPromise(function(_0x3b96e7,_0x9f1669){_0x4cd59d(_0x579953['payload'],_0x5b160f,_0x579953[_0xb23a('0x82')])[_0xb23a('0x3e')](function(_0xa0cff8){_0x3b96e7(_0xa0cff8);})[_0xb23a('0x44')](function(_0x19399c){_0x9f1669(_0x19399c);});});}function verifyJwt(_0x14eb93,_0x5f255a,_0x46c36f){var _0x399cd7=BPromise[_0xb23a('0x80')](jwt[_0xb23a('0x83')],{'context':jwt});var _0xe9bc7c=_0x46c36f||config[_0xb23a('0x9')][_0xb23a('0x84')];return new BPromise(function(_0x5c6ade,_0x130817){_0x399cd7(_0x14eb93,_0xe9bc7c,_0x5f255a)[_0xb23a('0x3e')](function(_0x1fa7cb){_0x5c6ade(_0x1fa7cb);})['catch'](function(_0x2b86fc){_0x130817(_0x2b86fc);});});}function generateNonce(){return crypto[_0xb23a('0x85')](0x10)[_0xb23a('0x86')](_0xb23a('0x87'));}function generateIssuedAt(){return Math[_0xb23a('0x88')](Date['now']()/0x3e8)[_0xb23a('0x86')]();}function createJwt(_0x529685){var _0x109e6b={'payload':{'iat':_0x529685[_0xb23a('0x70')],'nonce':_0x529685[_0xb23a('0x57')]},'options':{'algorithm':'HS512','subject':_0x529685['id'][_0xb23a('0x86')](),'issuer':hardwareConf[_0xb23a('0x52')](),'audience':hardwareConf[_0xb23a('0x52')]()}};return signJwt(_0x109e6b)[_0xb23a('0x3e')](function(_0x3d2144){return{'iat':_0x529685[_0xb23a('0x70')],'nonce':_0x529685[_0xb23a('0x57')],'token':_0x3d2144};});}