2f99c296760a05695a24a380dfe7a354e79f07cf
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x4f09=['The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','Sequelize','unshift','encryptString','join','promisify','secret','payload','options','verify','toString','hex','floor','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','lodash','jsonwebtoken','basic-auth','crypto','bluebird','moment','session','role','fullname','name','internal','email','userpic','permissions','md5secret','chatPause','mailPause','faxPause','smsPause','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','interface','userProfileId','privacyEnabled','wssPort','downloadOmnichannelInteractions','downloadAttachments','selectRecallMeCampaign','isChatInteractionAuthorized','isAuthenticated','use','ChatInteraction','findOne','params','closed','disposition','then','unmanaged','json','Unmanaged.','Forbidden.','catch','authorization','startsWith','headers','Basic','User','find','authenticate','pass','status','user','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blocked','blockedAt','add','minutes','User\x20not\x20found.','User\x20object\x20not\x20found.','update','Forbidden','isWebrtcLicence','isMiddleware','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','/dashboards/general','send','retrieveApiKey','isNil','generateApiKey','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','ValidationError','validatePasswordHistory','decryptString','split','toLowerCase','format'];(function(_0x3fb91a,_0x303ceb){var _0x4b071a=function(_0x14c7be){while(--_0x14c7be){_0x3fb91a['push'](_0x3fb91a['shift']());}};_0x4b071a(++_0x303ceb);}(_0x4f09,0x18b));var _0x94f0=function(_0x3021c5,_0x1980cc){_0x3021c5=_0x3021c5-0x0;var _0x170536=_0x4f09[_0x3021c5];return _0x170536;};'use strict';var db=require(_0x94f0('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x94f0('0x1'));var licenseUtil=require(_0x94f0('0x2'));var encryptor=require('../encryptor');var _=require(_0x94f0('0x3'));var jwt=require(_0x94f0('0x4'));var expressJwt=require('express-jwt');var compose=require('composable-middleware');var basicAuth=require(_0x94f0('0x5'));var crypto=require(_0x94f0('0x6'));var BPromise=require(_0x94f0('0x7'));var util=require('util');var moment=require(_0x94f0('0x8'));var validateJwt=expressJwt({'secret':config['secrets'][_0x94f0('0x9')]});var userAttributes=['id',_0x94f0('0xa'),_0x94f0('0xb'),_0x94f0('0xc'),_0x94f0('0xd'),_0x94f0('0xe'),_0x94f0('0xf'),_0x94f0('0x10'),_0x94f0('0x11'),'voicePause',_0x94f0('0x12'),_0x94f0('0x13'),_0x94f0('0x14'),_0x94f0('0x15'),'openchannelPause','pauseType',_0x94f0('0x16'),_0x94f0('0x17'),_0x94f0('0x18'),_0x94f0('0x19'),_0x94f0('0x1a'),_0x94f0('0x1b'),'alias',_0x94f0('0x1c'),_0x94f0('0x1d'),_0x94f0('0x1e'),_0x94f0('0x1f'),_0x94f0('0x20'),_0x94f0('0x21'),_0x94f0('0x22'),_0x94f0('0x23'),_0x94f0('0x24'),'phoneBarRemoteControlPort','hotdesk',_0x94f0('0x25'),_0x94f0('0x26'),_0x94f0('0x27'),'settingsEnabled',_0x94f0('0x28'),'downloadVoiceRecordings',_0x94f0('0x29'),_0x94f0('0x2a'),'ignorePauseForPreviewCalls',_0x94f0('0x2b')];exports[_0x94f0('0x2c')]=function(){return this[_0x94f0('0x2d')](!![])[_0x94f0('0x2e')](function(_0x5390db,_0x1ed598,_0x20a16c){if(_0x5390db['user']){_0x20a16c();}else{return db[_0x94f0('0x2f')][_0x94f0('0x30')]({'where':{'id':_0x5390db[_0x94f0('0x31')]['id']},'attributes':['id',_0x94f0('0x32'),_0x94f0('0x33')],'raw':!![]})[_0x94f0('0x34')](function(_0x20e671){if(_0x20e671&&_0x20e671[_0x94f0('0x32')]){return _0x1ed598['status'](_0x20e671['disposition']===_0x94f0('0x35')?0x195:0x193)[_0x94f0('0x36')]({'message':_0x20e671[_0x94f0('0x33')]==='unmanaged'?_0x94f0('0x37'):_0x94f0('0x38')});}else{_0x20a16c();}})[_0x94f0('0x39')](function(_0x3f8812){_0x20a16c(_0x3f8812);});}});};exports[_0x94f0('0x2d')]=function isAuthenticated(_0x5a314d){return compose()['use'](function(_0x4ff057,_0x1597c7,_0x25b2e7){var _0x2cd681;if(_0x4ff057['headers'][_0x94f0('0x3a')]){if(_[_0x94f0('0x3b')](_0x4ff057[_0x94f0('0x3c')][_0x94f0('0x3a')],_0x94f0('0x3d'))){var _0x5ed002=basicAuth(_0x4ff057);db[_0x94f0('0x3e')][_0x94f0('0x3f')]({'where':{'name':_0x5ed002['name']}})[_0x94f0('0x34')](function(_0x458a8d){if(!_0x458a8d||!_0x458a8d[_0x94f0('0x40')](_0x5ed002[_0x94f0('0x41')])){return _0x1597c7[_0x94f0('0x42')](0x191)[_0x94f0('0x36')]({'message':'Wrong\x20credentials.'});}_0x4ff057[_0x94f0('0x43')]={'id':_0x458a8d['id']};_0x25b2e7();})[_0x94f0('0x39')](function(_0x175690){_0x25b2e7(_0x175690);});}else if(_[_0x94f0('0x3b')](_0x4ff057[_0x94f0('0x3c')][_0x94f0('0x3a')],_0x94f0('0x44'))){validateJwt(_0x4ff057,_0x1597c7,_0x25b2e7);}else{if(_0x5a314d){_0x25b2e7();}else{return _0x1597c7[_0x94f0('0x42')](0x193)[_0x94f0('0x36')]({'message':_0x94f0('0x45')});}}}else if(_0x4ff057[_0x94f0('0x46')][_0x94f0('0x47')]){try{var _0x43a207={'audience':hardwareConf[_0x94f0('0x48')](),'issuer':hardwareConf[_0x94f0('0x48')]()};verifyJwt(_0x4ff057[_0x94f0('0x46')][_0x94f0('0x47')],_0x43a207)[_0x94f0('0x34')](function(_0x5d5c6f){return db[_0x94f0('0x3e')]['find']({'where':{'id':_0x5d5c6f[_0x94f0('0x49')]}})[_0x94f0('0x34')](function(_0x29a3dd){_0x2cd681=_0x29a3dd;return db[_0x94f0('0x4a')][_0x94f0('0x30')]({'where':{'id':0x1},'attributes':[_0x94f0('0x4b'),_0x94f0('0x4c')],'raw':!![]});})[_0x94f0('0x34')](function(_0x3be86d){if(!_0x2cd681||!_[_0x94f0('0x4d')](_0x2cd681[_0x94f0('0x4e')],_0x5d5c6f[_0x94f0('0x4f')])){return _0x1597c7[_0x94f0('0x42')](0x191)[_0x94f0('0x36')]({'message':_0x94f0('0x50')});}if(_0x2cd681[_0x94f0('0x51')]){return _0x1597c7['status'](0x191)[_0x94f0('0x36')]({'message':_0x94f0('0x52')});}if(_0x2cd681[_0x94f0('0x53')]){if(_0x3be86d[_0x94f0('0x4c')]>0x0){if(moment(_0x2cd681[_0x94f0('0x54')])[_0x94f0('0x55')](_0x3be86d[_0x94f0('0x4c')],_0x94f0('0x56'))>moment()){return _0x1597c7[_0x94f0('0x42')](0x191)['json']({'message':_0x94f0('0x52')});}}else{return _0x1597c7[_0x94f0('0x42')](0x191)[_0x94f0('0x36')]({'message':_0x94f0('0x52')});}}_0x4ff057[_0x94f0('0x43')]={'id':_0x2cd681['id']};_0x25b2e7();});})[_0x94f0('0x39')](function(){return _0x1597c7[_0x94f0('0x42')](0x191)[_0x94f0('0x36')]({'message':_0x94f0('0x52')});});}catch(_0x3d967e){_0x25b2e7(_0x3d967e);}}else if(_0x5a314d){_0x25b2e7();}else{return _0x1597c7[_0x94f0('0x42')](0x193)[_0x94f0('0x36')]({'message':_0x94f0('0x45')});}})['use'](function(_0x51df68,_0x372931,_0x21961c){if(_0x51df68['user']){db[_0x94f0('0x3e')][_0x94f0('0x3f')]({'where':{'id':_0x51df68[_0x94f0('0x43')]['id']},'attributes':userAttributes})[_0x94f0('0x34')](function(_0x4c58e5){if(!_0x4c58e5){return _0x372931[_0x94f0('0x42')](0x194)['json']({'message':_0x94f0('0x57')});}_0x51df68[_0x94f0('0x43')]=_0x4c58e5;_0x21961c();})[_0x94f0('0x39')](function(_0x19a853){_0x21961c(_0x19a853);});}else if(_0x5a314d){_0x21961c();}else{return _0x372931[_0x94f0('0x42')](0x194)[_0x94f0('0x36')]({'message':_0x94f0('0x58')});}});};exports['canUpdate']=function canUpdate(){return compose()['use'](function(_0x9fc137,_0x8fc876,_0x531da2){return licenseUtil['getLicense']()[_0x94f0('0x34')](function(_0x3adb2a){if(_0x3adb2a[_0x94f0('0x59')]){_0x531da2();}else{return _0x8fc876['status'](0x193)[_0x94f0('0x36')]({'message':_0x94f0('0x5a')});}})[_0x94f0('0x39')](function(_0x35aa6f){_0x531da2(_0x35aa6f);});});};exports[_0x94f0('0x5b')]=function isWebrtcLicence(){return compose()[_0x94f0('0x2e')](function(_0x5d3b96,_0x8c1875,_0x42d105){return licenseUtil['getLicense']()[_0x94f0('0x34')](function(_0x527cb1){if(_0x527cb1['webrtc']){_0x42d105();}else{return _0x8c1875[_0x94f0('0x42')](0x193)['json']({'message':_0x94f0('0x5a')});}})[_0x94f0('0x39')](function(_0x54af86){_0x42d105(_0x54af86);});});};exports[_0x94f0('0x5c')]=function(_0x36a295,_0x518332,_0x5bacec){_0x36a295['isMiddleware']=!![];return _0x5bacec();};exports['signToken']=function signToken(_0xe82afd){return signJwt(_0xe82afd);};exports[_0x94f0('0x5d')]=function(_0x13ece1,_0x3f8a9f){if(!_0x13ece1['user']){return _0x3f8a9f[_0x94f0('0x42')](0x194)['json']({'message':_0x94f0('0x5e')});}var _0x1106e5={'payload':{'id':_0x13ece1[_0x94f0('0x43')]['id'],'role':_0x13ece1[_0x94f0('0x43')][_0x94f0('0xa')]},'options':{'expiresIn':0x15180}};return signJwt(_0x1106e5)[_0x94f0('0x34')](function(_0x51c91c){_0x3f8a9f[_0x94f0('0x5f')](_0x94f0('0x60'),_0x51c91c);_0x3f8a9f['redirect'](_0x94f0('0x61'));})[_0x94f0('0x39')](function(_0x3ab655){return _0x3f8a9f[_0x94f0('0x42')](0x1f4)[_0x94f0('0x62')](_0x3ab655);});};exports[_0x94f0('0x63')]=function(_0x382d66){if(_[_0x94f0('0x64')](_0x382d66[_0x94f0('0x4e')])||_[_0x94f0('0x64')](_0x382d66['apiKeyIat'])){return null;}else{return createJwt(_0x382d66);}};exports[_0x94f0('0x65')]=function(_0x31c01c){_0x31c01c['apiKeyNonce']=generateNonce();_0x31c01c[_0x94f0('0x66')]=generateIssuedAt();return createJwt(_0x31c01c);};exports[_0x94f0('0x67')]=function(_0x5a5cc6,_0x43d11c){var _0x429773=_0x5a5cc6[_0x94f0('0x46')][_0x94f0('0x47')];if(_0x429773){var _0xbb3b83={'nonce':_0x43d11c['apiKeyNonce'],'iat':_0x43d11c[_0x94f0('0x66')],'audience':hardwareConf[_0x94f0('0x48')](),'issuer':hardwareConf[_0x94f0('0x48')]()};return verifyJwt(_0x429773,_0xbb3b83)[_0x94f0('0x34')](function(){return generateApiKey(_0x43d11c);});}else{throw{'message':_0x94f0('0x68')};}};exports[_0x94f0('0x69')]=function(_0x4fcf80){var _0xbc00e1=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0xbc00e1[_0x94f0('0x6a')](_0x4fcf80))throw new db['Sequelize'][(_0x94f0('0x6b'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports[_0x94f0('0x6c')]=function(_0x22392b,_0x6737f,_0xdbcc50){var _0x24f56c=encryptor[_0x94f0('0x6d')](_0x6737f)[_0x94f0('0x6e')](',');for(var _0x4b6a00=0x0;_0x4b6a00<_0xdbcc50;_0x4b6a00++){if(!_0x24f56c[_0x4b6a00])break;if(_0x22392b['toLowerCase']()===_0x24f56c[_0x4b6a00][_0x94f0('0x6f')]()){var _0x1cfdcb=util[_0x94f0('0x70')](_0x94f0('0x71'),_0xdbcc50);if(_0xdbcc50===0x1){_0x1cfdcb='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x94f0('0x72'))]['ValidationError'](_0x1cfdcb);}}return;};exports['updatePasswordsHistory']=function(_0x7ced7f,_0x38804d){var _0x4b78e7=_0x38804d?encryptor[_0x94f0('0x6d')](_0x38804d)[_0x94f0('0x6e')](','):[];if(_0x4b78e7['length']===0x5){_0x4b78e7['splice'](-0x1,0x1);}_0x4b78e7[_0x94f0('0x73')](_0x7ced7f);return encryptor[_0x94f0('0x74')](_0x4b78e7[_0x94f0('0x75')](','));};function signJwt(_0x13fe44){var _0x4f2e3a=BPromise[_0x94f0('0x76')](jwt['sign'],{'context':jwt});var _0x507d84=_0x13fe44[_0x94f0('0x77')]||config['secrets'][_0x94f0('0x9')];return new BPromise(function(_0x12f423,_0x1baee1){_0x4f2e3a(_0x13fe44[_0x94f0('0x78')],_0x507d84,_0x13fe44[_0x94f0('0x79')])[_0x94f0('0x34')](function(_0x5b76b5){_0x12f423(_0x5b76b5);})[_0x94f0('0x39')](function(_0x56bba0){_0x1baee1(_0x56bba0);});});}function verifyJwt(_0x5eb973,_0x43aa3b,_0x575309){var _0x177628=BPromise[_0x94f0('0x76')](jwt[_0x94f0('0x7a')],{'context':jwt});var _0x6e8c2d=_0x575309||config['secrets'][_0x94f0('0x9')];return new BPromise(function(_0x4ed244,_0x164f83){_0x177628(_0x5eb973,_0x6e8c2d,_0x43aa3b)[_0x94f0('0x34')](function(_0x52f34a){_0x4ed244(_0x52f34a);})['catch'](function(_0x15b1a6){_0x164f83(_0x15b1a6);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0x94f0('0x7b')](_0x94f0('0x7c'));}function generateIssuedAt(){return Math[_0x94f0('0x7d')](Date['now']()/0x3e8)[_0x94f0('0x7b')]();}function createJwt(_0xd8de35){var _0x253c61={'payload':{'iat':_0xd8de35[_0x94f0('0x66')],'nonce':_0xd8de35[_0x94f0('0x4e')]},'options':{'algorithm':_0x94f0('0x7e'),'subject':_0xd8de35['id'][_0x94f0('0x7b')](),'issuer':hardwareConf[_0x94f0('0x48')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x253c61)[_0x94f0('0x34')](function(_0x57bd12){return{'iat':_0xd8de35[_0x94f0('0x66')],'nonce':_0xd8de35[_0x94f0('0x4e')],'token':_0x57bd12};});}