Built motion from commit (unavailable).|2.5.6
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xbee7=['hotdesk','interface','userProfileId','settingsEnabled','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','then','status','unmanaged','json','Forbidden.','catch','headers','authorization','startsWith','Basic','User','find','authenticate','pass','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','query','sub','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','User\x20object\x20not\x20found.','canUpdate','getLicense','update','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','redirect','/dashboards/general','send','retrieveApiKey','generateApiKey','regenerateApiKey','apiKeyIat','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','split','toLowerCase','format','updatePasswordsHistory','decryptString','splice','unshift','encryptString','join','secret','payload','options','verify','randomBytes','hex','floor','now','toString','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util','secrets','session','role','fullname','name','internal','email','permissions','md5secret','voicePause','chatPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort'];(function(_0x1660a6,_0x49140e){var _0x5d56ad=function(_0x51d581){while(--_0x51d581){_0x1660a6['push'](_0x1660a6['shift']());}};_0x5d56ad(++_0x49140e);}(_0xbee7,0xc3));var _0x7bee=function(_0x59a2fc,_0x474f45){_0x59a2fc=_0x59a2fc-0x0;var _0x1e0888=_0xbee7[_0x59a2fc];return _0x1e0888;};'use strict';var db=require(_0x7bee('0x0'))['db'];var config=require(_0x7bee('0x1'));var hardwareConf=require(_0x7bee('0x2'));var licenseUtil=require(_0x7bee('0x3'));var encryptor=require(_0x7bee('0x4'));var _=require(_0x7bee('0x5'));var jwt=require(_0x7bee('0x6'));var expressJwt=require(_0x7bee('0x7'));var compose=require(_0x7bee('0x8'));var basicAuth=require(_0x7bee('0x9'));var crypto=require(_0x7bee('0xa'));var BPromise=require(_0x7bee('0xb'));var util=require(_0x7bee('0xc'));var validateJwt=expressJwt({'secret':config[_0x7bee('0xd')][_0x7bee('0xe')]});var userAttributes=['id',_0x7bee('0xf'),_0x7bee('0x10'),_0x7bee('0x11'),_0x7bee('0x12'),_0x7bee('0x13'),'userpic',_0x7bee('0x14'),_0x7bee('0x15'),_0x7bee('0x16'),_0x7bee('0x17'),'mailPause','faxPause',_0x7bee('0x18'),_0x7bee('0x19'),_0x7bee('0x1a'),_0x7bee('0x1b'),_0x7bee('0x1c'),_0x7bee('0x1d'),'crudPermissions',_0x7bee('0x1e'),_0x7bee('0x1f'),_0x7bee('0x20'),'phoneBarAutoAnswer',_0x7bee('0x21'),_0x7bee('0x22'),_0x7bee('0x23'),_0x7bee('0x24'),'phoneBarEnableSettings',_0x7bee('0x25'),_0x7bee('0x26'),_0x7bee('0x27'),_0x7bee('0x28'),_0x7bee('0x29'),_0x7bee('0x2a'),_0x7bee('0x2b'),_0x7bee('0x2c')];exports['isChatInteractionAuthorized']=function(){return this[_0x7bee('0x2d')](!![])[_0x7bee('0x2e')](function(_0x2c7b4f,_0x3454c5,_0x4ef957){if(_0x2c7b4f[_0x7bee('0x2f')]){_0x4ef957();}else{return db[_0x7bee('0x30')][_0x7bee('0x31')]({'where':{'id':_0x2c7b4f[_0x7bee('0x32')]['id']},'attributes':['id',_0x7bee('0x33'),_0x7bee('0x34')],'raw':!![]})[_0x7bee('0x35')](function(_0x13f5b9){if(_0x13f5b9&&_0x13f5b9[_0x7bee('0x33')]){return _0x3454c5[_0x7bee('0x36')](_0x13f5b9[_0x7bee('0x34')]===_0x7bee('0x37')?0x195:0x193)[_0x7bee('0x38')]({'message':_0x13f5b9['disposition']===_0x7bee('0x37')?'Unmanaged.':_0x7bee('0x39')});}else{_0x4ef957();}})[_0x7bee('0x3a')](function(_0x4336bd){_0x4ef957(_0x4336bd);});}});};exports['isAuthenticated']=function isAuthenticated(_0x1c036e){return compose()['use'](function(_0x5f4c0a,_0x3fffd4,_0x1ae511){if(_0x5f4c0a[_0x7bee('0x3b')][_0x7bee('0x3c')]){if(_[_0x7bee('0x3d')](_0x5f4c0a[_0x7bee('0x3b')][_0x7bee('0x3c')],_0x7bee('0x3e'))){var _0x5d2be1=basicAuth(_0x5f4c0a);db[_0x7bee('0x3f')][_0x7bee('0x40')]({'where':{'name':_0x5d2be1[_0x7bee('0x11')]}})[_0x7bee('0x35')](function(_0x4c8bc0){if(!_0x4c8bc0||!_0x4c8bc0[_0x7bee('0x41')](_0x5d2be1[_0x7bee('0x42')])){return _0x3fffd4[_0x7bee('0x36')](0x191)[_0x7bee('0x38')]({'message':'Wrong\x20credentials.'});}_0x5f4c0a['user']={'id':_0x4c8bc0['id']};_0x1ae511();})[_0x7bee('0x3a')](function(_0x174de9){_0x1ae511(_0x174de9);});}else if(_[_0x7bee('0x3d')](_0x5f4c0a[_0x7bee('0x3b')][_0x7bee('0x3c')],_0x7bee('0x43'))){validateJwt(_0x5f4c0a,_0x3fffd4,_0x1ae511);}else{if(_0x1c036e){_0x1ae511();}else{return _0x3fffd4[_0x7bee('0x36')](0x193)[_0x7bee('0x38')]({'message':_0x7bee('0x44')});}}}else if(_0x5f4c0a['query'][_0x7bee('0x45')]){try{var _0x1589c8={'audience':hardwareConf[_0x7bee('0x46')](),'issuer':hardwareConf[_0x7bee('0x46')]()};verifyJwt(_0x5f4c0a[_0x7bee('0x47')][_0x7bee('0x45')],_0x1589c8)[_0x7bee('0x35')](function(_0x479d93){return db['User'][_0x7bee('0x40')]({'where':{'id':_0x479d93[_0x7bee('0x48')]}})[_0x7bee('0x35')](function(_0x141b22){if(!_0x141b22||!_['isEqual'](_0x141b22[_0x7bee('0x49')],_0x479d93[_0x7bee('0x4a')])){return _0x3fffd4[_0x7bee('0x36')](0x191)[_0x7bee('0x38')]({'message':_0x7bee('0x4b')});}_0x5f4c0a[_0x7bee('0x2f')]={'id':_0x141b22['id']};_0x1ae511();});})[_0x7bee('0x3a')](function(){return _0x3fffd4[_0x7bee('0x36')](0x191)['json']({'message':_0x7bee('0x4c')});});}catch(_0x4bfe01){_0x1ae511(_0x4bfe01);}}else if(_0x1c036e){_0x1ae511();}else{return _0x3fffd4[_0x7bee('0x36')](0x193)[_0x7bee('0x38')]({'message':_0x7bee('0x44')});}})['use'](function(_0x4d022c,_0x326665,_0x41f8df){if(_0x4d022c[_0x7bee('0x2f')]){db[_0x7bee('0x3f')]['find']({'where':{'id':_0x4d022c[_0x7bee('0x2f')]['id']},'attributes':userAttributes})[_0x7bee('0x35')](function(_0x50b94e){if(!_0x50b94e){return _0x326665[_0x7bee('0x36')](0x194)[_0x7bee('0x38')]({'message':'User\x20not\x20found.'});}_0x4d022c[_0x7bee('0x2f')]=_0x50b94e;_0x41f8df();})[_0x7bee('0x3a')](function(_0x55b513){_0x41f8df(_0x55b513);});}else if(_0x1c036e){_0x41f8df();}else{return _0x326665['status'](0x194)[_0x7bee('0x38')]({'message':_0x7bee('0x4d')});}});};exports[_0x7bee('0x4e')]=function canUpdate(){return compose()[_0x7bee('0x2e')](function(_0x1ec1c6,_0x311d52,_0x18d6a0){return licenseUtil[_0x7bee('0x4f')]()[_0x7bee('0x35')](function(_0x437ffe){if(_0x437ffe[_0x7bee('0x50')]){_0x18d6a0();}else{return _0x311d52[_0x7bee('0x36')](0x193)[_0x7bee('0x38')]({'message':'Forbidden'});}})[_0x7bee('0x3a')](function(_0xcf6fd2){_0x18d6a0(_0xcf6fd2);});});};exports[_0x7bee('0x51')]=function(_0x1e5fdc,_0x5bcb32,_0x3b809a){_0x1e5fdc[_0x7bee('0x51')]=!![];return _0x3b809a();};exports[_0x7bee('0x52')]=function signToken(_0x460044){return signJwt(_0x460044);};exports[_0x7bee('0x53')]=function(_0x14a4d5,_0x2ccc0a){if(!_0x14a4d5['user']){return _0x2ccc0a[_0x7bee('0x36')](0x194)[_0x7bee('0x38')]({'message':_0x7bee('0x54')});}var _0x2e3c05={'payload':{'id':_0x14a4d5['user']['id'],'role':_0x14a4d5[_0x7bee('0x2f')][_0x7bee('0xf')]},'options':{'expiresIn':0x15180}};return signJwt(_0x2e3c05)[_0x7bee('0x35')](function(_0x1d787b){_0x2ccc0a[_0x7bee('0x55')]('motion.token',_0x1d787b);_0x2ccc0a[_0x7bee('0x56')](_0x7bee('0x57'));})[_0x7bee('0x3a')](function(_0x1ea53c){return _0x2ccc0a[_0x7bee('0x36')](0x1f4)[_0x7bee('0x58')](_0x1ea53c);});};exports[_0x7bee('0x59')]=function(_0x5629e6){if(_['isNil'](_0x5629e6[_0x7bee('0x49')])||_['isNil'](_0x5629e6['apiKeyIat'])){return null;}else{return createJwt(_0x5629e6);}};exports[_0x7bee('0x5a')]=function(_0x125b55){_0x125b55[_0x7bee('0x49')]=generateNonce();_0x125b55['apiKeyIat']=generateIssuedAt();return createJwt(_0x125b55);};exports[_0x7bee('0x5b')]=function(_0x2a103f,_0x232d3a){var _0x3618db=_0x2a103f[_0x7bee('0x47')][_0x7bee('0x45')];if(_0x3618db){var _0x1536e3={'nonce':_0x232d3a[_0x7bee('0x49')],'iat':_0x232d3a[_0x7bee('0x5c')],'audience':hardwareConf[_0x7bee('0x46')](),'issuer':hardwareConf[_0x7bee('0x46')]()};return verifyJwt(_0x3618db,_0x1536e3)['then'](function(){return generateApiKey(_0x232d3a);});}else{throw{'message':_0x7bee('0x5d')};}};exports[_0x7bee('0x5e')]=function(_0x6d7753){var _0x2bdf3d=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x2bdf3d[_0x7bee('0x5f')](_0x6d7753))throw new db[(_0x7bee('0x60'))][(_0x7bee('0x61'))](_0x7bee('0x62'));return;};exports[_0x7bee('0x63')]=function(_0x5c730b,_0x1634ba,_0x17cf1f){var _0x185085=encryptor['decryptString'](_0x1634ba)[_0x7bee('0x64')](',');for(var _0x2b4571=0x0;_0x2b4571<_0x17cf1f;_0x2b4571++){if(!_0x185085[_0x2b4571])break;if(_0x5c730b[_0x7bee('0x65')]()===_0x185085[_0x2b4571]['toLowerCase']()){var _0x518cbc=util[_0x7bee('0x66')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x17cf1f);if(_0x17cf1f===0x1){_0x518cbc='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db['Sequelize'][(_0x7bee('0x61'))](_0x518cbc);}}return;};exports[_0x7bee('0x67')]=function(_0x501633,_0x240226){var _0x5c9f38=_0x240226?encryptor[_0x7bee('0x68')](_0x240226)['split'](','):[];if(_0x5c9f38['length']===0x5){_0x5c9f38[_0x7bee('0x69')](-0x1,0x1);}_0x5c9f38[_0x7bee('0x6a')](_0x501633);return encryptor[_0x7bee('0x6b')](_0x5c9f38[_0x7bee('0x6c')](','));};function signJwt(_0xd35695){var _0x3cdab1=BPromise['promisify'](jwt['sign'],{'context':jwt});var _0x547402=_0xd35695[_0x7bee('0x6d')]||config[_0x7bee('0xd')][_0x7bee('0xe')];return new BPromise(function(_0x42d4e2,_0x3fee40){_0x3cdab1(_0xd35695[_0x7bee('0x6e')],_0x547402,_0xd35695[_0x7bee('0x6f')])['then'](function(_0xcf485){_0x42d4e2(_0xcf485);})[_0x7bee('0x3a')](function(_0x1b096c){_0x3fee40(_0x1b096c);});});}function verifyJwt(_0x16ab8c,_0x2f14f2,_0x10e8a0){var _0x16861c=BPromise['promisify'](jwt[_0x7bee('0x70')],{'context':jwt});var _0x2c16de=_0x10e8a0||config[_0x7bee('0xd')][_0x7bee('0xe')];return new BPromise(function(_0x555eb1,_0x48756f){_0x16861c(_0x16ab8c,_0x2c16de,_0x2f14f2)[_0x7bee('0x35')](function(_0x1c486a){_0x555eb1(_0x1c486a);})[_0x7bee('0x3a')](function(_0xa34d5){_0x48756f(_0xa34d5);});});}function generateNonce(){return crypto[_0x7bee('0x71')](0x10)['toString'](_0x7bee('0x72'));}function generateIssuedAt(){return Math[_0x7bee('0x73')](Date[_0x7bee('0x74')]()/0x3e8)['toString']();}function createJwt(_0x2c9e92){var _0xe59d97={'payload':{'iat':_0x2c9e92[_0x7bee('0x5c')],'nonce':_0x2c9e92[_0x7bee('0x49')]},'options':{'algorithm':'HS512','subject':_0x2c9e92['id'][_0x7bee('0x75')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x7bee('0x46')]()}};return signJwt(_0xe59d97)[_0x7bee('0x35')](function(_0x26f00d){return{'iat':_0x2c9e92[_0x7bee('0x5c')],'nonce':_0x2c9e92[_0x7bee('0x49')],'token':_0x26f00d};});}