22b3cf5e5c19fe1349ba4f74c22ab109e74ea10c
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x80ed=['unshift','join','promisify','sign','secret','payload','options','verify','secrets','randomBytes','floor','now','toString','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','jsonwebtoken','express-jwt','composable-middleware','basic-auth','bluebird','util','moment','session','role','fullname','name','internal','email','userpic','permissions','md5secret','voicePause','mailPause','faxPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','ignorePauseForPreviewCalls','chatAutoanswer','chatAutoanswerDelay','emailAutoanswer','smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer','openchannelAutoanswerDelay','faxAutoanswer','whatsappAutoanswerDelay','messengerSoundNotification','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','closed','disposition','then','json','Unmanaged.','Forbidden.','catch','headers','authorization','Basic','User','find','authenticate','pass','status','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blocked','blockedAt','User\x20object\x20not\x20found.','canUpdate','Forbidden','getLicense','isMiddleware','signToken','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','split','toLowerCase','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','Sequelize','length','splice'];(function(_0x343c76,_0x1cac3a){var _0x1bb83=function(_0x23874a){while(--_0x23874a){_0x343c76['push'](_0x343c76['shift']());}};_0x1bb83(++_0x1cac3a);}(_0x80ed,0x11c));var _0xd80e=function(_0x995a5d,_0x44b1c1){_0x995a5d=_0x995a5d-0x0;var _0x3b6320=_0x80ed[_0x995a5d];return _0x3b6320;};'use strict';var db=require(_0xd80e('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0xd80e('0x1'));var licenseUtil=require(_0xd80e('0x2'));var encryptor=require(_0xd80e('0x3'));var _=require('lodash');var jwt=require(_0xd80e('0x4'));var expressJwt=require(_0xd80e('0x5'));var compose=require(_0xd80e('0x6'));var basicAuth=require(_0xd80e('0x7'));var crypto=require('crypto');var BPromise=require(_0xd80e('0x8'));var util=require(_0xd80e('0x9'));var moment=require(_0xd80e('0xa'));var validateJwt=expressJwt({'secret':config['secrets'][_0xd80e('0xb')]});var userAttributes=['id',_0xd80e('0xc'),_0xd80e('0xd'),_0xd80e('0xe'),_0xd80e('0xf'),_0xd80e('0x10'),_0xd80e('0x11'),_0xd80e('0x12'),_0xd80e('0x13'),_0xd80e('0x14'),'chatPause',_0xd80e('0x15'),_0xd80e('0x16'),_0xd80e('0x17'),_0xd80e('0x18'),_0xd80e('0x19'),_0xd80e('0x1a'),_0xd80e('0x1b'),_0xd80e('0x1c'),_0xd80e('0x1d'),'allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer',_0xd80e('0x1e'),_0xd80e('0x1f'),_0xd80e('0x20'),_0xd80e('0x21'),_0xd80e('0x22'),'phoneBarExpires',_0xd80e('0x23'),_0xd80e('0x24'),_0xd80e('0x25'),_0xd80e('0x26'),_0xd80e('0x27'),_0xd80e('0x28'),_0xd80e('0x29'),_0xd80e('0x2a'),'wssPort',_0xd80e('0x2b'),_0xd80e('0x2c'),_0xd80e('0x2d'),_0xd80e('0x2e'),'selectRecallMeCampaign',_0xd80e('0x2f'),_0xd80e('0x30'),_0xd80e('0x31'),'emailAutoanswerDelay',_0xd80e('0x32'),_0xd80e('0x33'),_0xd80e('0x34'),_0xd80e('0x35'),_0xd80e('0x36'),'faxAutoanswerDelay','whatsappAutoanswer',_0xd80e('0x37'),_0xd80e('0x38')];exports[_0xd80e('0x39')]=function(){return this[_0xd80e('0x3a')](!![])[_0xd80e('0x3b')](function(_0x326d66,_0x43152c,_0x5430b6){if(_0x326d66[_0xd80e('0x3c')]){_0x5430b6();}else{return db[_0xd80e('0x3d')][_0xd80e('0x3e')]({'where':{'id':_0x326d66['params']['id']},'attributes':['id',_0xd80e('0x3f'),_0xd80e('0x40')],'raw':!![]})[_0xd80e('0x41')](function(_0x482779){if(_0x482779&&_0x482779['closed']){return _0x43152c['status'](_0x482779[_0xd80e('0x40')]==='unmanaged'?0x195:0x193)[_0xd80e('0x42')]({'message':_0x482779[_0xd80e('0x40')]==='unmanaged'?_0xd80e('0x43'):_0xd80e('0x44')});}else{_0x5430b6();}})[_0xd80e('0x45')](function(_0x46c05d){_0x5430b6(_0x46c05d);});}});};exports['isAuthenticated']=function isAuthenticated(_0x15f317){return compose()[_0xd80e('0x3b')](function(_0x845451,_0x39088b,_0x2b1aaf){var _0x361946;if(_0x845451[_0xd80e('0x46')][_0xd80e('0x47')]){if(_['startsWith'](_0x845451['headers'][_0xd80e('0x47')],_0xd80e('0x48'))){var _0x400220=basicAuth(_0x845451);db[_0xd80e('0x49')][_0xd80e('0x4a')]({'where':{'name':_0x400220[_0xd80e('0xe')]}})['then'](function(_0x568d82){if(!_0x568d82||!_0x568d82[_0xd80e('0x4b')](_0x400220[_0xd80e('0x4c')])){return _0x39088b[_0xd80e('0x4d')](0x191)[_0xd80e('0x42')]({'message':_0xd80e('0x4e')});}_0x845451[_0xd80e('0x3c')]={'id':_0x568d82['id']};_0x2b1aaf();})[_0xd80e('0x45')](function(_0x1a0dfe){_0x2b1aaf(_0x1a0dfe);});}else if(_['startsWith'](_0x845451['headers'][_0xd80e('0x47')],_0xd80e('0x4f'))){validateJwt(_0x845451,_0x39088b,_0x2b1aaf);}else{if(_0x15f317){_0x2b1aaf();}else{return _0x39088b[_0xd80e('0x4d')](0x193)[_0xd80e('0x42')]({'message':_0xd80e('0x50')});}}}else if(_0x845451[_0xd80e('0x51')][_0xd80e('0x52')]){try{var _0x3cb956={'audience':hardwareConf[_0xd80e('0x53')](),'issuer':hardwareConf[_0xd80e('0x53')]()};verifyJwt(_0x845451['query'][_0xd80e('0x52')],_0x3cb956)['then'](function(_0x22d371){return db[_0xd80e('0x49')][_0xd80e('0x4a')]({'where':{'id':_0x22d371[_0xd80e('0x54')]}})['then'](function(_0x3e44d7){_0x361946=_0x3e44d7;return db['Setting'][_0xd80e('0x3e')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts',_0xd80e('0x55')],'raw':!![]});})[_0xd80e('0x41')](function(_0x4b7f32){if(!_0x361946||!_[_0xd80e('0x56')](_0x361946[_0xd80e('0x57')],_0x22d371[_0xd80e('0x58')])){return _0x39088b['status'](0x191)[_0xd80e('0x42')]({'message':_0xd80e('0x59')});}if(_0x361946[_0xd80e('0x5a')]){return _0x39088b[_0xd80e('0x4d')](0x191)[_0xd80e('0x42')]({'message':_0xd80e('0x5b')});}if(_0x361946[_0xd80e('0x5c')]){if(_0x4b7f32[_0xd80e('0x55')]>0x0){if(moment(_0x361946[_0xd80e('0x5d')])['add'](_0x4b7f32['blockDuration'],'minutes')>moment()){return _0x39088b[_0xd80e('0x4d')](0x191)[_0xd80e('0x42')]({'message':'Invalid\x20API\x20access\x20key'});}}else{return _0x39088b[_0xd80e('0x4d')](0x191)['json']({'message':_0xd80e('0x5b')});}}_0x845451['user']={'id':_0x361946['id']};_0x2b1aaf();});})[_0xd80e('0x45')](function(){return _0x39088b[_0xd80e('0x4d')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x44a736){_0x2b1aaf(_0x44a736);}}else if(_0x15f317){_0x2b1aaf();}else{return _0x39088b[_0xd80e('0x4d')](0x193)[_0xd80e('0x42')]({'message':_0xd80e('0x50')});}})[_0xd80e('0x3b')](function(_0x19de99,_0x20cbff,_0x439ba7){if(_0x19de99[_0xd80e('0x3c')]){db[_0xd80e('0x49')][_0xd80e('0x4a')]({'where':{'id':_0x19de99[_0xd80e('0x3c')]['id']},'attributes':userAttributes})[_0xd80e('0x41')](function(_0x11463c){if(!_0x11463c){return _0x20cbff[_0xd80e('0x4d')](0x194)[_0xd80e('0x42')]({'message':'User\x20not\x20found.'});}_0x19de99['user']=_0x11463c;_0x439ba7();})['catch'](function(_0x10dc30){_0x439ba7(_0x10dc30);});}else if(_0x15f317){_0x439ba7();}else{return _0x20cbff['status'](0x194)[_0xd80e('0x42')]({'message':_0xd80e('0x5e')});}});};exports[_0xd80e('0x5f')]=function canUpdate(){return compose()[_0xd80e('0x3b')](function(_0x2612e7,_0x7c394f,_0x506fd0){return licenseUtil['getLicense']()['then'](function(_0x2ea201){if(_0x2ea201['update']){_0x506fd0();}else{return _0x7c394f[_0xd80e('0x4d')](0x193)[_0xd80e('0x42')]({'message':_0xd80e('0x60')});}})[_0xd80e('0x45')](function(_0x28fda8){_0x506fd0(_0x28fda8);});});};exports['isWebrtcLicence']=function isWebrtcLicence(){return compose()[_0xd80e('0x3b')](function(_0x4353f2,_0x3217c7,_0x5ba71d){return licenseUtil[_0xd80e('0x61')]()[_0xd80e('0x41')](function(_0x1b9ee5){if(_0x1b9ee5['webrtc']){_0x5ba71d();}else{return _0x3217c7[_0xd80e('0x4d')](0x193)[_0xd80e('0x42')]({'message':_0xd80e('0x60')});}})[_0xd80e('0x45')](function(_0x4144f5){_0x5ba71d(_0x4144f5);});});};exports[_0xd80e('0x62')]=function(_0x56ba81,_0x5aad1b,_0x275985){_0x56ba81[_0xd80e('0x62')]=!![];return _0x275985();};exports[_0xd80e('0x63')]=function signToken(_0x5dec55){return signJwt(_0x5dec55);};exports['setTokenCookie']=function(_0x1762a8,_0xff0980){if(!_0x1762a8[_0xd80e('0x3c')]){return _0xff0980[_0xd80e('0x4d')](0x194)[_0xd80e('0x42')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x4237fe={'payload':{'id':_0x1762a8['user']['id'],'role':_0x1762a8[_0xd80e('0x3c')][_0xd80e('0xc')]},'options':{'expiresIn':0x15180}};return signJwt(_0x4237fe)['then'](function(_0x29af86){_0xff0980[_0xd80e('0x64')](_0xd80e('0x65'),_0x29af86);_0xff0980[_0xd80e('0x66')](_0xd80e('0x67'));})[_0xd80e('0x45')](function(_0x18dbb0){return _0xff0980['status'](0x1f4)[_0xd80e('0x68')](_0x18dbb0);});};exports[_0xd80e('0x69')]=function(_0x419df7){if(_['isNil'](_0x419df7['apiKeyNonce'])||_[_0xd80e('0x6a')](_0x419df7[_0xd80e('0x6b')])){return null;}else{return createJwt(_0x419df7);}};exports[_0xd80e('0x6c')]=function(_0x23a40c){_0x23a40c[_0xd80e('0x57')]=generateNonce();_0x23a40c[_0xd80e('0x6b')]=generateIssuedAt();return createJwt(_0x23a40c);};exports[_0xd80e('0x6d')]=function(_0x3984fe,_0x5205c4){var _0x340311=_0x3984fe['query'][_0xd80e('0x52')];if(_0x340311){var _0x3c184c={'nonce':_0x5205c4[_0xd80e('0x57')],'iat':_0x5205c4[_0xd80e('0x6b')],'audience':hardwareConf[_0xd80e('0x53')](),'issuer':hardwareConf[_0xd80e('0x53')]()};return verifyJwt(_0x340311,_0x3c184c)['then'](function(){return generateApiKey(_0x5205c4);});}else{throw{'message':_0xd80e('0x6e')};}};exports['validatePasswordPattern']=function(_0x389413){var _0x6e506=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x6e506['test'](_0x389413))throw new db['Sequelize'][(_0xd80e('0x6f'))](_0xd80e('0x70'));return;};exports[_0xd80e('0x71')]=function(_0x570a02,_0x568770,_0x1ba0ed){var _0x387561=encryptor['decryptString'](_0x568770)[_0xd80e('0x72')](',');for(var _0x19e264=0x0;_0x19e264<_0x1ba0ed;_0x19e264++){if(!_0x387561[_0x19e264])break;if(_0x570a02[_0xd80e('0x73')]()===_0x387561[_0x19e264]['toLowerCase']()){var _0x41dda0=util['format'](_0xd80e('0x74'),_0x1ba0ed);if(_0x1ba0ed===0x1){_0x41dda0=_0xd80e('0x75');}throw new db[(_0xd80e('0x76'))][(_0xd80e('0x6f'))](_0x41dda0);}}return;};exports['updatePasswordsHistory']=function(_0x2df79e,_0x564475){var _0x53b784=_0x564475?encryptor['decryptString'](_0x564475)[_0xd80e('0x72')](','):[];if(_0x53b784[_0xd80e('0x77')]===0x5){_0x53b784[_0xd80e('0x78')](-0x1,0x1);}_0x53b784[_0xd80e('0x79')](_0x2df79e);return encryptor['encryptString'](_0x53b784[_0xd80e('0x7a')](','));};function signJwt(_0x280798){var _0x5d775f=BPromise[_0xd80e('0x7b')](jwt[_0xd80e('0x7c')],{'context':jwt});var _0x2c92b9=_0x280798[_0xd80e('0x7d')]||config['secrets'][_0xd80e('0xb')];return new BPromise(function(_0x1c2ba2,_0x57e904){_0x5d775f(_0x280798[_0xd80e('0x7e')],_0x2c92b9,_0x280798[_0xd80e('0x7f')])[_0xd80e('0x41')](function(_0x4abc70){_0x1c2ba2(_0x4abc70);})['catch'](function(_0x4c9383){_0x57e904(_0x4c9383);});});}function verifyJwt(_0x5f241c,_0x6edb7,_0x4f283c){var _0x3c8ad1=BPromise[_0xd80e('0x7b')](jwt[_0xd80e('0x80')],{'context':jwt});var _0x4e1b08=_0x4f283c||config[_0xd80e('0x81')][_0xd80e('0xb')];return new BPromise(function(_0x2b3ad6,_0x1a351b){_0x3c8ad1(_0x5f241c,_0x4e1b08,_0x6edb7)[_0xd80e('0x41')](function(_0x2a34cd){_0x2b3ad6(_0x2a34cd);})[_0xd80e('0x45')](function(_0x18cb0e){_0x1a351b(_0x18cb0e);});});}function generateNonce(){return crypto[_0xd80e('0x82')](0x10)['toString']('hex');}function generateIssuedAt(){return Math[_0xd80e('0x83')](Date[_0xd80e('0x84')]()/0x3e8)[_0xd80e('0x85')]();}function createJwt(_0x34b493){var _0x50df62={'payload':{'iat':_0x34b493[_0xd80e('0x6b')],'nonce':_0x34b493[_0xd80e('0x57')]},'options':{'algorithm':_0xd80e('0x86'),'subject':_0x34b493['id'][_0xd80e('0x85')](),'issuer':hardwareConf[_0xd80e('0x53')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x50df62)[_0xd80e('0x41')](function(_0x1e44f7){return{'iat':_0x34b493[_0xd80e('0x6b')],'nonce':_0x34b493[_0xd80e('0x57')],'token':_0x1e44f7};});}