5dc11e31ed8bea6800f2972fe15962872cb92ebb
[motion2.git] / server / api / cloudProvider / cloudProvider.oauth.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xd869=['findAll','all','error','[CLOUD_PROVIDER]\x20Error\x20while\x20refreshing\x20the\x20tokens\x20after\x20service\x20restart\x20error:%s','exports','lodash','jsonwebtoken','moment','ioredis','util','../../components/encryptor','../../config/environment','../../config/logger','api','../../config/schedule/cloud-provider','../../mysqldb','defaults','redis','localhost','https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0','profile','https://outlook.office365.com/IMAP.AccessAsUser.All','https://outlook.office.com/POP.AccessAsUser.All','https://outlook.office.com/SMTP.Send','openid','offline_access','/authorize','map','Dynamics365','push','data7','join','type','Outlook365','/.default','{TENANT_ID}','code','id_token','stringify','toString','base64','randomBytes','client_id','data1','redirect_uri','data4','response_mode','form_post','scope','state','nonce','login','key','value','replace','oauth2/','decode','payload','iss','issuer','aud','unix','exp','resolve','then','data3','refresh_token','data6','decryptString','data5','access_token','catch','authorization_code','POST','data2','bind','intervals','CloudProvider'];(function(_0xfd495c,_0x4a3c1a){var _0x561dd8=function(_0x83e915){while(--_0x83e915){_0xfd495c['push'](_0xfd495c['shift']());}};_0x561dd8(++_0x4a3c1a);}(_0xd869,0x1d9));var _0x9d86=function(_0x5f58bb,_0x3f0bad){_0x5f58bb=_0x5f58bb-0x0;var _0xcc672d=_0xd869[_0x5f58bb];return _0xcc672d;};'use strict';var _=require(_0x9d86('0x0'));var crypto=require('crypto');var jwt=require(_0x9d86('0x1'));var moment=require(_0x9d86('0x2'));var Redis=require(_0x9d86('0x3'));var rp=require('request-promise');var util=require(_0x9d86('0x4'));var encryptor=require(_0x9d86('0x5'));var config=require(_0x9d86('0x6'));var logger=require(_0x9d86('0x7'))(_0x9d86('0x8'));var schedule=require(_0x9d86('0x9'));var db=require(_0x9d86('0xa'))['db'];config['redis']=_[_0x9d86('0xb')](config[_0x9d86('0xc')],{'host':_0x9d86('0xd'),'port':0x18eb});var redis=new Redis(config[_0x9d86('0xc')]);var MICROSOFT_AUTH_URL=_0x9d86('0xe');var AZURE_AUTH_SCOPES={'Outlook365':['openid',_0x9d86('0xf'),'email','offline_access',_0x9d86('0x10'),_0x9d86('0x11'),_0x9d86('0x12')],'Dynamics365':[_0x9d86('0x13'),_0x9d86('0x14')]};var MICROSOFT_AUTH_ENDPOINT=_0x9d86('0x15');var MICROSOFT_TOKEN_ENDPOINT='/token';var OAUTH_REFRESH_INTERVAL=0xfa;function getAuthorizationScopes(_0x61a30a){var _0x14bf93=_[_0x9d86('0x16')](AZURE_AUTH_SCOPES[_0x61a30a['type']]);if(_0x61a30a['type']===_0x9d86('0x17'))_0x14bf93[_0x9d86('0x18')](_0x61a30a[_0x9d86('0x19')]+'/.default');return _0x14bf93[_0x9d86('0x1a')]('\x20');}function getAccessTokenScope(_0x492dde){if(_0x492dde[_0x9d86('0x1b')]===_0x9d86('0x1c'))return _0x9d86('0x10');if(_0x492dde[_0x9d86('0x1b')]===_0x9d86('0x17'))return _0x492dde[_0x9d86('0x19')]+_0x9d86('0x1d');}function generateMicrosoftAuthorizationUrl(_0x49c257,_0x169cbf){var _0x46d26e=MICROSOFT_AUTH_URL['replace'](_0x9d86('0x1e'),_0x49c257['data2']);var _0x53c131=[_0x9d86('0x1f'),_0x9d86('0x20')];var _0x2721f6=Buffer['from'](JSON[_0x9d86('0x21')]({'id':_0x169cbf}))[_0x9d86('0x22')](_0x9d86('0x23'));var _0x164de8=crypto[_0x9d86('0x24')](0x10)[_0x9d86('0x22')]('hex');var _0x2eacec=getAuthorizationScopes(_0x49c257);var _0xdb2197=[{'key':_0x9d86('0x25'),'value':_0x49c257[_0x9d86('0x26')]},{'key':'response_type','value':encodeURIComponent(_0x53c131['join']('\x20'))},{'key':_0x9d86('0x27'),'value':_0x49c257[_0x9d86('0x28')]},{'key':_0x9d86('0x29'),'value':_0x9d86('0x2a')},{'key':_0x9d86('0x2b'),'value':encodeURIComponent(_0x2eacec)},{'key':_0x9d86('0x2c'),'value':_0x2721f6},{'key':_0x9d86('0x2d'),'value':_0x164de8},{'key':'prompt','value':_0x9d86('0x2e')}];var _0x230d19=_0x46d26e+MICROSOFT_AUTH_ENDPOINT+'?'+_['map'](_0xdb2197,function(_0x2a0180){return _0x2a0180[_0x9d86('0x2f')]+'='+_0x2a0180[_0x9d86('0x30')];})[_0x9d86('0x1a')]('&');_0x49c257['oauth2Claims']={'issuer':_0x46d26e[_0x9d86('0x31')](_0x9d86('0x32'),''),'audience':_0x49c257['data1'],'state':_0x2721f6,'nonce':_0x164de8};redis['set'](_0x2721f6,JSON['stringify'](_0x49c257));return _0x230d19;}function isValidIdToken(_0x188403,_0x2b5a30){try{var _0x111325=jwt[_0x9d86('0x33')](_0x188403,{'complete':!![]});var _0x3b5786=_0x111325[_0x9d86('0x34')];if(_0x3b5786[_0x9d86('0x35')]!==_0x2b5a30[_0x9d86('0x36')])return![];if(_0x3b5786[_0x9d86('0x37')]!==_0x2b5a30['audience'])return![];if(_0x3b5786[_0x9d86('0x2d')]!==_0x2b5a30['nonce'])return![];if(moment()['isAfter'](moment[_0x9d86('0x38')](_0x3b5786[_0x9d86('0x39')])))return![];return!![];}catch(_0x4a453e){throw _0x4a453e;}}function refreshOauth2MicrosoftAccessToken(_0x5668a3){return Promise[_0x9d86('0x3a')]()[_0x9d86('0x3b')](function(){if(_0x5668a3[_0x9d86('0x3c')])return _0x5668a3;return db['CloudProvider']['findOne']({'where':{'id':_0x5668a3['id']},'raw':!![]});})['then'](function(_0x56adc9){var _0x33827e={'grant_type':_0x9d86('0x3d'),'refresh_token':_0x56adc9[_0x9d86('0x3e')],'scope':getAccessTokenScope(_0x56adc9),'redirect_uri':_0x56adc9[_0x9d86('0x28')],'client_id':_0x56adc9['data1'],'client_secret':encryptor[_0x9d86('0x3f')](_0x56adc9[_0x9d86('0x3c')])};var _0x433f7e={'method':'POST','uri':MICROSOFT_AUTH_URL[_0x9d86('0x31')]('{TENANT_ID}',_0x56adc9['data2'])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x33827e,'json':!![]};return rp(_0x433f7e);})[_0x9d86('0x3b')](function(_0x39cfef){_0x5668a3[_0x9d86('0x40')]=_0x39cfef[_0x9d86('0x41')];_0x5668a3[_0x9d86('0x3e')]=_0x39cfef['refresh_token'];return db['CloudProvider']['update']({'data5':_0x5668a3[_0x9d86('0x40')],'data6':_0x5668a3[_0x9d86('0x3e')]},{'where':{'id':_0x5668a3['id']}});})['then'](function(){return _0x5668a3;})[_0x9d86('0x42')](function(_0x4a99a5){logger['error']('Failed\x20to\x20refresh\x20access\x20token\x20for\x20cloud\x20provider\x20#%s,\x20-\x20err:%s',_0x5668a3['id'],_0x4a99a5);});}function getOauth2MicrosoftAccessToken(_0x2f31cf,_0x54f2c5){var _0x36a9b4={'grant_type':_0x9d86('0x43'),'code':_0x2f31cf,'scope':getAccessTokenScope(_0x54f2c5),'redirect_uri':_0x54f2c5[_0x9d86('0x28')],'client_id':_0x54f2c5['data1'],'client_secret':encryptor['decryptString'](_0x54f2c5[_0x9d86('0x3c')])};var _0x54e35c={'method':_0x9d86('0x44'),'uri':MICROSOFT_AUTH_URL[_0x9d86('0x31')](_0x9d86('0x1e'),_0x54f2c5[_0x9d86('0x45')])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x36a9b4,'json':!![]};return rp(_0x54e35c);}function startRefreshInterval(_0x120cdc){var _0x24103f=schedule['intervals'];if(_0x24103f[_0x120cdc['id']])clearInterval(_0x24103f[_0x120cdc['id']]);_0x24103f[_0x120cdc['id']]=setInterval(refreshOauth2MicrosoftAccessToken[_0x9d86('0x46')](this,{'id':_0x120cdc['id']}),OAUTH_REFRESH_INTERVAL*0x3e8);schedule[_0x9d86('0x47')]=_0x24103f;}function startAllRefreshIntervals(){return db[_0x9d86('0x48')][_0x9d86('0x49')]({'where':{'data6':{'$ne':null}},'raw':!![]})[_0x9d86('0x3b')](function(_0x7ee147){var _0x358d02=_0x7ee147[_0x9d86('0x16')](function(_0x4e7d5b){return refreshOauth2MicrosoftAccessToken(_0x4e7d5b)['then'](function(_0x41e863){startRefreshInterval(_0x41e863);});});return Promise[_0x9d86('0x4a')](_0x358d02);})[_0x9d86('0x42')](function(_0x74832a){var _0x36aef6=_0x74832a?util['inspect'](_0x74832a,{'showHidden':![],'depth':null}):'';logger[_0x9d86('0x4b')](_0x9d86('0x4c'),_0x36aef6);});}module[_0x9d86('0x4d')]={'generateMicrosoftAuthorizationUrl':generateMicrosoftAuthorizationUrl,'getOauth2MicrosoftAccessToken':getOauth2MicrosoftAccessToken,'isValidIdToken':isValidIdToken,'startAllRefreshIntervals':startAllRefreshIntervals,'refreshOauth2MicrosoftAccessToken':refreshOauth2MicrosoftAccessToken,'startRefreshInterval':startRefreshInterval};