2e6a7c003b1b43bdd099863de5d0e7b99c529e71
[motion2.git] / server / api / cloudProvider / cloudProvider.oauth.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x0e93=['client_id','response_type','redirect_uri','data4','response_mode','scope','state','nonce','prompt','login','key','value','oauth2/','data1','decode','aud','audience','unix','resolve','findOne','then','data6','decryptString','data3','POST','data5','access_token','CloudProvider','catch','error','Failed\x20to\x20refresh\x20access\x20token\x20for\x20cloud\x20provider\x20#%s,\x20-\x20err:%s','authorization_code','data2','findAll','all','inspect','[CLOUD_PROVIDER]\x20Error\x20while\x20refreshing\x20the\x20tokens\x20after\x20service\x20restart\x20error:%s','crypto','jsonwebtoken','moment','ioredis','request-promise','util','../../components/encryptor','../../config/environment','api','../../mysqldb','defaults','redis','localhost','https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0','openid','profile','email','offline_access','https://outlook.office365.com/IMAP.AccessAsUser.All','https://outlook.office.com/SMTP.Send','/authorize','/token','map','type','Dynamics365','push','data7','/.default','join','Outlook365','replace','{TENANT_ID}','code','from','stringify','toString','base64','randomBytes'];(function(_0x24f31b,_0x44b8f3){var _0x488401=function(_0x204caf){while(--_0x204caf){_0x24f31b['push'](_0x24f31b['shift']());}};_0x488401(++_0x44b8f3);}(_0x0e93,0x1e7));var _0x30e9=function(_0x38f953,_0x3f66bd){_0x38f953=_0x38f953-0x0;var _0x4a7531=_0x0e93[_0x38f953];return _0x4a7531;};'use strict';var _=require('lodash');var crypto=require(_0x30e9('0x0'));var jwt=require(_0x30e9('0x1'));var moment=require(_0x30e9('0x2'));var Redis=require(_0x30e9('0x3'));var rp=require(_0x30e9('0x4'));var util=require(_0x30e9('0x5'));var encryptor=require(_0x30e9('0x6'));var config=require(_0x30e9('0x7'));var logger=require('../../config/logger')(_0x30e9('0x8'));var schedule=require('../../config/schedule/cloud-provider');var db=require(_0x30e9('0x9'))['db'];config['redis']=_[_0x30e9('0xa')](config[_0x30e9('0xb')],{'host':_0x30e9('0xc'),'port':0x18eb});var redis=new Redis(config['redis']);var MICROSOFT_AUTH_URL=_0x30e9('0xd');var AZURE_AUTH_SCOPES={'Outlook365':[_0x30e9('0xe'),_0x30e9('0xf'),_0x30e9('0x10'),_0x30e9('0x11'),_0x30e9('0x12'),'https://outlook.office.com/POP.AccessAsUser.All',_0x30e9('0x13')],'Dynamics365':[_0x30e9('0xe'),_0x30e9('0x11')]};var MICROSOFT_AUTH_ENDPOINT=_0x30e9('0x14');var MICROSOFT_TOKEN_ENDPOINT=_0x30e9('0x15');var OAUTH_REFRESH_INTERVAL=0xfa;function getAuthorizationScopes(_0x580044){var _0x24eace=_[_0x30e9('0x16')](AZURE_AUTH_SCOPES[_0x580044[_0x30e9('0x17')]]);if(_0x580044[_0x30e9('0x17')]===_0x30e9('0x18'))_0x24eace[_0x30e9('0x19')](_0x580044[_0x30e9('0x1a')]+_0x30e9('0x1b'));return _0x24eace[_0x30e9('0x1c')]('\x20');}function getAccessTokenScope(_0x3128f5){if(_0x3128f5[_0x30e9('0x17')]===_0x30e9('0x1d'))return'https://outlook.office365.com/IMAP.AccessAsUser.All';if(_0x3128f5[_0x30e9('0x17')]===_0x30e9('0x18'))return _0x3128f5[_0x30e9('0x1a')]+'/.default';}function generateMicrosoftAuthorizationUrl(_0xcabd73,_0x99cfc2){var _0x2496e3=MICROSOFT_AUTH_URL[_0x30e9('0x1e')](_0x30e9('0x1f'),_0xcabd73['data2']);var _0x264a84=[_0x30e9('0x20'),'id_token'];var _0x34d9f2=Buffer[_0x30e9('0x21')](JSON[_0x30e9('0x22')]({'id':_0x99cfc2}))[_0x30e9('0x23')](_0x30e9('0x24'));var _0x1111d7=crypto[_0x30e9('0x25')](0x10)[_0x30e9('0x23')]('hex');var _0x6e7e51=getAuthorizationScopes(_0xcabd73);var _0x2f7a83=[{'key':_0x30e9('0x26'),'value':_0xcabd73['data1']},{'key':_0x30e9('0x27'),'value':encodeURIComponent(_0x264a84[_0x30e9('0x1c')]('\x20'))},{'key':_0x30e9('0x28'),'value':_0xcabd73[_0x30e9('0x29')]},{'key':_0x30e9('0x2a'),'value':'form_post'},{'key':_0x30e9('0x2b'),'value':encodeURIComponent(_0x6e7e51)},{'key':_0x30e9('0x2c'),'value':_0x34d9f2},{'key':_0x30e9('0x2d'),'value':_0x1111d7},{'key':_0x30e9('0x2e'),'value':_0x30e9('0x2f')}];var _0x2ed3e7=_0x2496e3+MICROSOFT_AUTH_ENDPOINT+'?'+_[_0x30e9('0x16')](_0x2f7a83,function(_0x328818){return _0x328818[_0x30e9('0x30')]+'='+_0x328818[_0x30e9('0x31')];})[_0x30e9('0x1c')]('&');_0xcabd73['oauth2Claims']={'issuer':_0x2496e3[_0x30e9('0x1e')](_0x30e9('0x32'),''),'audience':_0xcabd73[_0x30e9('0x33')],'state':_0x34d9f2,'nonce':_0x1111d7};redis['set'](_0x34d9f2,JSON['stringify'](_0xcabd73));return _0x2ed3e7;}function isValidIdToken(_0x3f27cb,_0x59ce56){try{var _0x58fa30=jwt[_0x30e9('0x34')](_0x3f27cb,{'complete':!![]});var _0x2cfde3=_0x58fa30['payload'];if(_0x2cfde3['iss']!==_0x59ce56['issuer'])return![];if(_0x2cfde3[_0x30e9('0x35')]!==_0x59ce56[_0x30e9('0x36')])return![];if(_0x2cfde3[_0x30e9('0x2d')]!==_0x59ce56[_0x30e9('0x2d')])return![];if(moment()['isAfter'](moment[_0x30e9('0x37')](_0x2cfde3['exp'])))return![];return!![];}catch(_0x403716){throw _0x403716;}}function refreshOauth2MicrosoftAccessToken(_0x2232c0){return Promise[_0x30e9('0x38')]()['then'](function(){if(_0x2232c0['data3'])return _0x2232c0;return db['CloudProvider'][_0x30e9('0x39')]({'where':{'id':_0x2232c0['id']},'raw':!![]});})[_0x30e9('0x3a')](function(_0x526103){var _0x2e74f6={'grant_type':'refresh_token','refresh_token':_0x526103[_0x30e9('0x3b')],'scope':getAccessTokenScope(_0x526103),'redirect_uri':_0x526103[_0x30e9('0x29')],'client_id':_0x526103[_0x30e9('0x33')],'client_secret':encryptor[_0x30e9('0x3c')](_0x526103[_0x30e9('0x3d')])};var _0xfac8bc={'method':_0x30e9('0x3e'),'uri':MICROSOFT_AUTH_URL[_0x30e9('0x1e')](_0x30e9('0x1f'),_0x526103['data2'])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x2e74f6,'json':!![]};return rp(_0xfac8bc);})[_0x30e9('0x3a')](function(_0x325409){_0x2232c0[_0x30e9('0x3f')]=_0x325409[_0x30e9('0x40')];_0x2232c0[_0x30e9('0x3b')]=_0x325409['refresh_token'];return db[_0x30e9('0x41')]['update']({'data5':_0x2232c0[_0x30e9('0x3f')],'data6':_0x2232c0[_0x30e9('0x3b')]},{'where':{'id':_0x2232c0['id']}});})[_0x30e9('0x3a')](function(){return _0x2232c0;})[_0x30e9('0x42')](function(_0x350c99){logger[_0x30e9('0x43')](_0x30e9('0x44'),_0x2232c0['id'],_0x350c99);});}function getOauth2MicrosoftAccessToken(_0x203ca0,_0x3fa448){var _0x44997f={'grant_type':_0x30e9('0x45'),'code':_0x203ca0,'scope':getAccessTokenScope(_0x3fa448),'redirect_uri':_0x3fa448[_0x30e9('0x29')],'client_id':_0x3fa448[_0x30e9('0x33')],'client_secret':encryptor['decryptString'](_0x3fa448[_0x30e9('0x3d')])};var _0x3d7335={'method':'POST','uri':MICROSOFT_AUTH_URL[_0x30e9('0x1e')](_0x30e9('0x1f'),_0x3fa448[_0x30e9('0x46')])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x44997f,'json':!![]};return rp(_0x3d7335);}function startRefreshInterval(_0x149a50){var _0x280a92=schedule['intervals'];if(_0x280a92[_0x149a50['id']])clearInterval(_0x280a92[_0x149a50['id']]);_0x280a92[_0x149a50['id']]=setInterval(refreshOauth2MicrosoftAccessToken['bind'](this,{'id':_0x149a50['id']}),OAUTH_REFRESH_INTERVAL*0x3e8);schedule['intervals']=_0x280a92;}function startAllRefreshIntervals(){return db[_0x30e9('0x41')][_0x30e9('0x47')]({'where':{'data6':{'$ne':null}},'raw':!![]})[_0x30e9('0x3a')](function(_0x340ed7){var _0x62ed43=_0x340ed7[_0x30e9('0x16')](function(_0x4d0df1){return refreshOauth2MicrosoftAccessToken(_0x4d0df1)['then'](function(_0x2813a1){startRefreshInterval(_0x2813a1);});});return Promise[_0x30e9('0x48')](_0x62ed43);})[_0x30e9('0x42')](function(_0xe776b4){var _0xb5f0de=_0xe776b4?util[_0x30e9('0x49')](_0xe776b4,{'showHidden':![],'depth':null}):'';logger[_0x30e9('0x43')](_0x30e9('0x4a'),_0xb5f0de);});}module['exports']={'generateMicrosoftAuthorizationUrl':generateMicrosoftAuthorizationUrl,'getOauth2MicrosoftAccessToken':getOauth2MicrosoftAccessToken,'isValidIdToken':isValidIdToken,'startAllRefreshIntervals':startAllRefreshIntervals,'refreshOauth2MicrosoftAccessToken':refreshOauth2MicrosoftAccessToken,'startRefreshInterval':startRefreshInterval};