Built motion from commit (unavailable).|2.5.4
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x628b=['phoneBarDnd','phoneBarEnableRecording','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','interface','userProfileId','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','params','then','closed','disposition','unmanaged','json','Unmanaged.','Forbidden.','catch','headers','authorization','Basic','User','find','authenticate','pass','status','Wrong\x20credentials.','startsWith','Bearer','Unknown\x20authorization\x20format','query','getUuid','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','User\x20object\x20not\x20found.','canUpdate','../../config/license/util','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','role','redirect','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','promisify','sign','secret','options','verify','randomBytes','toString','hex','floor','../../mysqldb','../../config/environment','../../config/license/hardware','jsonwebtoken','express-jwt','composable-middleware','basic-auth','bluebird','secrets','session','fullname','name','email','userpic','md5secret','voicePause','chatPause','mailPause','faxPause','smsPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer'];(function(_0x420513,_0x30eae3){var _0x1b44ec=function(_0x644f88){while(--_0x644f88){_0x420513['push'](_0x420513['shift']());}};_0x1b44ec(++_0x30eae3);}(_0x628b,0xa9));var _0xb628=function(_0x5089b4,_0x5b8dc3){_0x5089b4=_0x5089b4-0x0;var _0x3071c7=_0x628b[_0x5089b4];return _0x3071c7;};'use strict';var db=require(_0xb628('0x0'))['db'];var config=require(_0xb628('0x1'));var hardwareConf=require(_0xb628('0x2'));var _=require('lodash');var jwt=require(_0xb628('0x3'));var expressJwt=require(_0xb628('0x4'));var compose=require(_0xb628('0x5'));var basicAuth=require(_0xb628('0x6'));var crypto=require('crypto');var BPromise=require(_0xb628('0x7'));var validateJwt=expressJwt({'secret':config[_0xb628('0x8')][_0xb628('0x9')]});var userAttributes=['id','role',_0xb628('0xa'),_0xb628('0xb'),'internal',_0xb628('0xc'),_0xb628('0xd'),'permissions',_0xb628('0xe'),_0xb628('0xf'),_0xb628('0x10'),_0xb628('0x11'),_0xb628('0x12'),_0xb628('0x13'),'openchannelPause',_0xb628('0x14'),_0xb628('0x15'),_0xb628('0x16'),_0xb628('0x17'),_0xb628('0x18'),_0xb628('0x19'),_0xb628('0x1a'),_0xb628('0x1b'),_0xb628('0x1c'),'phoneBarAutoAnswerDelay',_0xb628('0x1d'),_0xb628('0x1e'),'phoneBarEnableDtmfTone',_0xb628('0x1f'),_0xb628('0x20'),_0xb628('0x21'),_0xb628('0x22'),_0xb628('0x23'),'hotdesk',_0xb628('0x24'),_0xb628('0x25')];exports[_0xb628('0x26')]=function(){return this[_0xb628('0x27')](!![])[_0xb628('0x28')](function(_0xe111e,_0x4a4fac,_0x3416a0){if(_0xe111e[_0xb628('0x29')]){_0x3416a0();}else{return db[_0xb628('0x2a')]['findOne']({'where':{'id':_0xe111e[_0xb628('0x2b')]['id']},'attributes':['id','closed','disposition'],'raw':!![]})[_0xb628('0x2c')](function(_0x404ad1){if(_0x404ad1&&_0x404ad1[_0xb628('0x2d')]){return _0x4a4fac['status'](_0x404ad1[_0xb628('0x2e')]===_0xb628('0x2f')?0x195:0x193)[_0xb628('0x30')]({'message':_0x404ad1[_0xb628('0x2e')]==='unmanaged'?_0xb628('0x31'):_0xb628('0x32')});}else{_0x3416a0();}})[_0xb628('0x33')](function(_0x2ddab4){_0x3416a0(_0x2ddab4);});}});};exports['isAuthenticated']=function isAuthenticated(_0x137580){return compose()[_0xb628('0x28')](function(_0x1588ee,_0x5ae8af,_0xb94727){if(_0x1588ee[_0xb628('0x34')][_0xb628('0x35')]){if(_['startsWith'](_0x1588ee['headers'][_0xb628('0x35')],_0xb628('0x36'))){var _0x1c9415=basicAuth(_0x1588ee);db[_0xb628('0x37')][_0xb628('0x38')]({'where':{'name':_0x1c9415[_0xb628('0xb')]}})[_0xb628('0x2c')](function(_0x3dcc2d){if(!_0x3dcc2d||!_0x3dcc2d[_0xb628('0x39')](_0x1c9415[_0xb628('0x3a')])){return _0x5ae8af[_0xb628('0x3b')](0x191)[_0xb628('0x30')]({'message':_0xb628('0x3c')});}_0x1588ee['user']={'id':_0x3dcc2d['id']};_0xb94727();})[_0xb628('0x33')](function(_0x519675){_0xb94727(_0x519675);});}else if(_[_0xb628('0x3d')](_0x1588ee['headers'][_0xb628('0x35')],_0xb628('0x3e'))){validateJwt(_0x1588ee,_0x5ae8af,_0xb94727);}else{if(_0x137580){_0xb94727();}else{return _0x5ae8af['status'](0x193)[_0xb628('0x30')]({'message':_0xb628('0x3f')});}}}else if(_0x1588ee[_0xb628('0x40')]['apikey']){try{var _0x4037cc={'audience':hardwareConf[_0xb628('0x41')](),'issuer':hardwareConf[_0xb628('0x41')]()};verifyJwt(_0x1588ee['query']['apikey'],_0x4037cc)[_0xb628('0x2c')](function(_0x49c994){return db[_0xb628('0x37')][_0xb628('0x38')]({'where':{'id':_0x49c994['sub']}})[_0xb628('0x2c')](function(_0x49f624){if(!_0x49f624||!_[_0xb628('0x42')](_0x49f624[_0xb628('0x43')],_0x49c994[_0xb628('0x44')])){return _0x5ae8af[_0xb628('0x3b')](0x191)[_0xb628('0x30')]({'message':_0xb628('0x45')});}_0x1588ee['user']={'id':_0x49f624['id']};_0xb94727();});})[_0xb628('0x33')](function(){return _0x5ae8af[_0xb628('0x3b')](0x191)['json']({'message':_0xb628('0x46')});});}catch(_0x59e172){_0xb94727(_0x59e172);}}else if(_0x137580){_0xb94727();}else{return _0x5ae8af[_0xb628('0x3b')](0x193)[_0xb628('0x30')]({'message':'Unknown\x20authorization\x20format'});}})[_0xb628('0x28')](function(_0x51e0b7,_0x54acf5,_0x52ad1c){if(_0x51e0b7[_0xb628('0x29')]){db['User'][_0xb628('0x38')]({'where':{'id':_0x51e0b7['user']['id']},'attributes':userAttributes})[_0xb628('0x2c')](function(_0x64fd9b){if(!_0x64fd9b){return _0x54acf5[_0xb628('0x3b')](0x194)[_0xb628('0x30')]({'message':'User\x20not\x20found.'});}_0x51e0b7[_0xb628('0x29')]=_0x64fd9b;_0x52ad1c();})['catch'](function(_0x4166bb){_0x52ad1c(_0x4166bb);});}else if(_0x137580){_0x52ad1c();}else{return _0x54acf5[_0xb628('0x3b')](0x194)[_0xb628('0x30')]({'message':_0xb628('0x47')});}});};exports[_0xb628('0x48')]=function canUpdate(){return compose()[_0xb628('0x28')](function(_0x2fd1db,_0x13d157,_0x1d4038){return require(_0xb628('0x49'))[_0xb628('0x4a')]()[_0xb628('0x2c')](function(_0x651e19){if(_0x651e19[_0xb628('0x4b')]){_0x1d4038();}else{return _0x13d157[_0xb628('0x3b')](0x193)[_0xb628('0x30')]({'message':_0xb628('0x4c')});}})[_0xb628('0x33')](function(_0x4c474a){_0x1d4038(_0x4c474a);});});};exports['isMiddleware']=function(_0x5e7da0,_0x4af286,_0x220518){_0x5e7da0[_0xb628('0x4d')]=!![];return _0x220518();};exports[_0xb628('0x4e')]=function signToken(_0x2083c8){return signJwt(_0x2083c8);};exports[_0xb628('0x4f')]=function(_0x3e3dd7,_0x390f72){if(!_0x3e3dd7[_0xb628('0x29')]){return _0x390f72['status'](0x194)['json']({'message':_0xb628('0x50')});}var _0x3b5b23={'payload':{'id':_0x3e3dd7[_0xb628('0x29')]['id'],'role':_0x3e3dd7[_0xb628('0x29')][_0xb628('0x51')]},'options':{'expiresIn':0x15180}};return signJwt(_0x3b5b23)[_0xb628('0x2c')](function(_0x1e4703){_0x390f72['cookie']('motion.token',_0x1e4703);_0x390f72[_0xb628('0x52')]('/dashboards/general');})[_0xb628('0x33')](function(_0x1dc5c2){return _0x390f72[_0xb628('0x3b')](0x1f4)[_0xb628('0x53')](_0x1dc5c2);});};exports[_0xb628('0x54')]=function(_0xbad7af){if(_['isNil'](_0xbad7af[_0xb628('0x43')])||_[_0xb628('0x55')](_0xbad7af[_0xb628('0x56')])){return null;}else{return createJwt(_0xbad7af);}};exports[_0xb628('0x57')]=function(_0x4617fb){_0x4617fb['apiKeyNonce']=generateNonce();_0x4617fb['apiKeyIat']=generateIssuedAt();return createJwt(_0x4617fb);};exports[_0xb628('0x58')]=function(_0x22c7a5,_0x334f75){var _0x1f2fa6=_0x22c7a5[_0xb628('0x40')]['apikey'];if(_0x1f2fa6){var _0xbe94ba={'nonce':_0x334f75[_0xb628('0x43')],'iat':_0x334f75[_0xb628('0x56')],'audience':hardwareConf[_0xb628('0x41')](),'issuer':hardwareConf[_0xb628('0x41')]()};return verifyJwt(_0x1f2fa6,_0xbe94ba)[_0xb628('0x2c')](function(){return generateApiKey(_0x334f75);});}else{throw{'message':_0xb628('0x59')};}};function signJwt(_0x5d14bf){var _0x3eac5e=BPromise[_0xb628('0x5a')](jwt[_0xb628('0x5b')],{'context':jwt});var _0x429913=_0x5d14bf[_0xb628('0x5c')]||config[_0xb628('0x8')]['session'];return new BPromise(function(_0x515424,_0x1a6b08){_0x3eac5e(_0x5d14bf['payload'],_0x429913,_0x5d14bf[_0xb628('0x5d')])[_0xb628('0x2c')](function(_0x3ea5c0){_0x515424(_0x3ea5c0);})[_0xb628('0x33')](function(_0x2bce69){_0x1a6b08(_0x2bce69);});});}function verifyJwt(_0x22eb29,_0x5d0b95,_0xf54d52){var _0x2605b3=BPromise['promisify'](jwt[_0xb628('0x5e')],{'context':jwt});var _0x40a408=_0xf54d52||config[_0xb628('0x8')][_0xb628('0x9')];return new BPromise(function(_0x33ec40,_0x4de5ed){_0x2605b3(_0x22eb29,_0x40a408,_0x5d0b95)[_0xb628('0x2c')](function(_0x441cc3){_0x33ec40(_0x441cc3);})[_0xb628('0x33')](function(_0x13374b){_0x4de5ed(_0x13374b);});});}function generateNonce(){return crypto[_0xb628('0x5f')](0x10)[_0xb628('0x60')](_0xb628('0x61'));}function generateIssuedAt(){return Math[_0xb628('0x62')](Date['now']()/0x3e8)[_0xb628('0x60')]();}function createJwt(_0x3e4243){var _0x31b32b={'payload':{'iat':_0x3e4243[_0xb628('0x56')],'nonce':_0x3e4243[_0xb628('0x43')]},'options':{'algorithm':'HS512','subject':_0x3e4243['id'][_0xb628('0x60')](),'issuer':hardwareConf[_0xb628('0x41')](),'audience':hardwareConf[_0xb628('0x41')]()}};return signJwt(_0x31b32b)[_0xb628('0x2c')](function(_0x423746){return{'iat':_0x3e4243[_0xb628('0x56')],'nonce':_0x3e4243['apiKeyNonce'],'token':_0x423746};});}