55f635979171615d885d4fc75bc1543a9d519a35
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x4fd8=['/dashboards/general','send','isNil','apiKeyNonce','generateApiKey','regenerateApiKey','apiKeyIat','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','splice','unshift','encryptString','join','promisify','sign','secret','secrets','options','verify','randomBytes','hex','now','HS512','toString','../../mysqldb','../encryptor','lodash','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util','moment','session','role','fullname','name','email','md5secret','chatPause','mailPause','faxPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','closed','disposition','then','status','unmanaged','catch','headers','authorization','startsWith','User','find','authenticate','pass','json','Wrong\x20credentials.','Bearer','query','getUuid','apikey','Setting','allowedLoginAttempts','blockDuration','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','Unknown\x20authorization\x20format','User\x20object\x20not\x20found.','canUpdate','getLicense','Forbidden','isMiddleware','signToken','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect'];(function(_0x24901c,_0x25de46){var _0x12f652=function(_0x47be1f){while(--_0x47be1f){_0x24901c['push'](_0x24901c['shift']());}};_0x12f652(++_0x25de46);}(_0x4fd8,0x114));var _0x84fd=function(_0x3dd15e,_0x1f0015){_0x3dd15e=_0x3dd15e-0x0;var _0x231fd0=_0x4fd8[_0x3dd15e];return _0x231fd0;};'use strict';var db=require(_0x84fd('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require('../../config/license/hardware');var licenseUtil=require('../../config/license/util');var encryptor=require(_0x84fd('0x1'));var _=require(_0x84fd('0x2'));var jwt=require('jsonwebtoken');var expressJwt=require(_0x84fd('0x3'));var compose=require(_0x84fd('0x4'));var basicAuth=require(_0x84fd('0x5'));var crypto=require(_0x84fd('0x6'));var BPromise=require(_0x84fd('0x7'));var util=require(_0x84fd('0x8'));var moment=require(_0x84fd('0x9'));var validateJwt=expressJwt({'secret':config['secrets'][_0x84fd('0xa')]});var userAttributes=['id',_0x84fd('0xb'),_0x84fd('0xc'),_0x84fd('0xd'),'internal',_0x84fd('0xe'),'userpic','permissions',_0x84fd('0xf'),'voicePause',_0x84fd('0x10'),_0x84fd('0x11'),_0x84fd('0x12'),_0x84fd('0x13'),_0x84fd('0x14'),_0x84fd('0x15'),_0x84fd('0x16'),_0x84fd('0x17'),_0x84fd('0x18'),'crudPermissions',_0x84fd('0x19'),_0x84fd('0x1a'),_0x84fd('0x1b'),_0x84fd('0x1c'),'phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording',_0x84fd('0x1d'),_0x84fd('0x1e'),_0x84fd('0x1f'),_0x84fd('0x20'),'phoneBarRemoteControl','phoneBarRemoteControlPort',_0x84fd('0x21'),_0x84fd('0x22'),_0x84fd('0x23'),_0x84fd('0x24'),_0x84fd('0x25'),_0x84fd('0x26'),_0x84fd('0x27'),_0x84fd('0x28'),_0x84fd('0x29')];exports[_0x84fd('0x2a')]=function(){return this[_0x84fd('0x2b')](!![])[_0x84fd('0x2c')](function(_0x3dc56d,_0x58d006,_0x46ad25){if(_0x3dc56d[_0x84fd('0x2d')]){_0x46ad25();}else{return db[_0x84fd('0x2e')][_0x84fd('0x2f')]({'where':{'id':_0x3dc56d['params']['id']},'attributes':['id',_0x84fd('0x30'),_0x84fd('0x31')],'raw':!![]})[_0x84fd('0x32')](function(_0xfc391a){if(_0xfc391a&&_0xfc391a[_0x84fd('0x30')]){return _0x58d006[_0x84fd('0x33')](_0xfc391a[_0x84fd('0x31')]===_0x84fd('0x34')?0x195:0x193)['json']({'message':_0xfc391a['disposition']===_0x84fd('0x34')?'Unmanaged.':'Forbidden.'});}else{_0x46ad25();}})[_0x84fd('0x35')](function(_0x770389){_0x46ad25(_0x770389);});}});};exports[_0x84fd('0x2b')]=function isAuthenticated(_0xd65969){return compose()[_0x84fd('0x2c')](function(_0x75b647,_0x65627b,_0x204142){var _0x49676f;if(_0x75b647[_0x84fd('0x36')][_0x84fd('0x37')]){if(_[_0x84fd('0x38')](_0x75b647[_0x84fd('0x36')][_0x84fd('0x37')],'Basic')){var _0x5ede5e=basicAuth(_0x75b647);db[_0x84fd('0x39')][_0x84fd('0x3a')]({'where':{'name':_0x5ede5e[_0x84fd('0xd')]}})[_0x84fd('0x32')](function(_0x595138){if(!_0x595138||!_0x595138[_0x84fd('0x3b')](_0x5ede5e[_0x84fd('0x3c')])){return _0x65627b[_0x84fd('0x33')](0x191)[_0x84fd('0x3d')]({'message':_0x84fd('0x3e')});}_0x75b647['user']={'id':_0x595138['id']};_0x204142();})['catch'](function(_0xf4a7d6){_0x204142(_0xf4a7d6);});}else if(_[_0x84fd('0x38')](_0x75b647[_0x84fd('0x36')]['authorization'],_0x84fd('0x3f'))){validateJwt(_0x75b647,_0x65627b,_0x204142);}else{if(_0xd65969){_0x204142();}else{return _0x65627b[_0x84fd('0x33')](0x193)[_0x84fd('0x3d')]({'message':'Unknown\x20authorization\x20format'});}}}else if(_0x75b647[_0x84fd('0x40')]['apikey']){try{var _0x52027a={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x84fd('0x41')]()};verifyJwt(_0x75b647[_0x84fd('0x40')][_0x84fd('0x42')],_0x52027a)[_0x84fd('0x32')](function(_0x71e757){return db[_0x84fd('0x39')][_0x84fd('0x3a')]({'where':{'id':_0x71e757['sub']}})[_0x84fd('0x32')](function(_0x55fbe6){_0x49676f=_0x55fbe6;return db[_0x84fd('0x43')][_0x84fd('0x2f')]({'where':{'id':0x1},'attributes':[_0x84fd('0x44'),_0x84fd('0x45')],'raw':!![]});})[_0x84fd('0x32')](function(_0x378d30){if(!_0x49676f||!_['isEqual'](_0x49676f['apiKeyNonce'],_0x71e757[_0x84fd('0x46')])){return _0x65627b[_0x84fd('0x33')](0x191)[_0x84fd('0x3d')]({'message':_0x84fd('0x47')});}if(_0x49676f['disabled']){return _0x65627b[_0x84fd('0x33')](0x191)[_0x84fd('0x3d')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x49676f['blocked']){if(_0x378d30[_0x84fd('0x45')]>0x0){if(moment(_0x49676f[_0x84fd('0x48')])[_0x84fd('0x49')](_0x378d30[_0x84fd('0x45')],_0x84fd('0x4a'))>moment()){return _0x65627b[_0x84fd('0x33')](0x191)[_0x84fd('0x3d')]({'message':_0x84fd('0x4b')});}}else{return _0x65627b[_0x84fd('0x33')](0x191)[_0x84fd('0x3d')]({'message':_0x84fd('0x4b')});}}_0x75b647[_0x84fd('0x2d')]={'id':_0x49676f['id']};_0x204142();});})[_0x84fd('0x35')](function(){return _0x65627b['status'](0x191)[_0x84fd('0x3d')]({'message':_0x84fd('0x4b')});});}catch(_0x1c4887){_0x204142(_0x1c4887);}}else if(_0xd65969){_0x204142();}else{return _0x65627b[_0x84fd('0x33')](0x193)[_0x84fd('0x3d')]({'message':_0x84fd('0x4c')});}})[_0x84fd('0x2c')](function(_0xa3a971,_0x3a0275,_0x1c41a1){if(_0xa3a971[_0x84fd('0x2d')]){db['User']['find']({'where':{'id':_0xa3a971[_0x84fd('0x2d')]['id']},'attributes':userAttributes})[_0x84fd('0x32')](function(_0x4ab4eb){if(!_0x4ab4eb){return _0x3a0275[_0x84fd('0x33')](0x194)[_0x84fd('0x3d')]({'message':'User\x20not\x20found.'});}_0xa3a971[_0x84fd('0x2d')]=_0x4ab4eb;_0x1c41a1();})[_0x84fd('0x35')](function(_0x5f3b58){_0x1c41a1(_0x5f3b58);});}else if(_0xd65969){_0x1c41a1();}else{return _0x3a0275['status'](0x194)['json']({'message':_0x84fd('0x4d')});}});};exports[_0x84fd('0x4e')]=function canUpdate(){return compose()['use'](function(_0x26e96d,_0x3b3a38,_0x1b8783){return licenseUtil[_0x84fd('0x4f')]()[_0x84fd('0x32')](function(_0x18d539){if(_0x18d539['update']){_0x1b8783();}else{return _0x3b3a38['status'](0x193)[_0x84fd('0x3d')]({'message':_0x84fd('0x50')});}})[_0x84fd('0x35')](function(_0x223002){_0x1b8783(_0x223002);});});};exports['isMiddleware']=function(_0x85deb9,_0x505ed2,_0x44332f){_0x85deb9[_0x84fd('0x51')]=!![];return _0x44332f();};exports[_0x84fd('0x52')]=function signToken(_0x5801d1){return signJwt(_0x5801d1);};exports['setTokenCookie']=function(_0x462e82,_0x217ac4){if(!_0x462e82['user']){return _0x217ac4[_0x84fd('0x33')](0x194)['json']({'message':_0x84fd('0x53')});}var _0x8aaa50={'payload':{'id':_0x462e82['user']['id'],'role':_0x462e82['user'][_0x84fd('0xb')]},'options':{'expiresIn':0x15180}};return signJwt(_0x8aaa50)[_0x84fd('0x32')](function(_0x56a890){_0x217ac4[_0x84fd('0x54')](_0x84fd('0x55'),_0x56a890);_0x217ac4[_0x84fd('0x56')](_0x84fd('0x57'));})[_0x84fd('0x35')](function(_0x41f684){return _0x217ac4[_0x84fd('0x33')](0x1f4)[_0x84fd('0x58')](_0x41f684);});};exports['retrieveApiKey']=function(_0x2da364){if(_[_0x84fd('0x59')](_0x2da364[_0x84fd('0x5a')])||_['isNil'](_0x2da364['apiKeyIat'])){return null;}else{return createJwt(_0x2da364);}};exports[_0x84fd('0x5b')]=function(_0xcb6e1d){_0xcb6e1d['apiKeyNonce']=generateNonce();_0xcb6e1d['apiKeyIat']=generateIssuedAt();return createJwt(_0xcb6e1d);};exports[_0x84fd('0x5c')]=function(_0x2028c7,_0xd16cad){var _0x3b3aa7=_0x2028c7[_0x84fd('0x40')]['apikey'];if(_0x3b3aa7){var _0x518463={'nonce':_0xd16cad['apiKeyNonce'],'iat':_0xd16cad[_0x84fd('0x5d')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x84fd('0x41')]()};return verifyJwt(_0x3b3aa7,_0x518463)[_0x84fd('0x32')](function(){return generateApiKey(_0xd16cad);});}else{throw{'message':_0x84fd('0x5e')};}};exports['validatePasswordPattern']=function(_0x1a5780){var _0x18d051=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x18d051['test'](_0x1a5780))throw new db[(_0x84fd('0x5f'))][(_0x84fd('0x60'))](_0x84fd('0x61'));return;};exports[_0x84fd('0x62')]=function(_0x8d4d84,_0xa2ba6b,_0x21bff1){var _0x122d26=encryptor[_0x84fd('0x63')](_0xa2ba6b)[_0x84fd('0x64')](',');for(var _0x49bf30=0x0;_0x49bf30<_0x21bff1;_0x49bf30++){if(!_0x122d26[_0x49bf30])break;if(_0x8d4d84[_0x84fd('0x65')]()===_0x122d26[_0x49bf30][_0x84fd('0x65')]()){var _0x382d83=util[_0x84fd('0x66')](_0x84fd('0x67'),_0x21bff1);if(_0x21bff1===0x1){_0x382d83='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x84fd('0x5f'))]['ValidationError'](_0x382d83);}}return;};exports[_0x84fd('0x68')]=function(_0x3162d1,_0x20d7e6){var _0x19d3b1=_0x20d7e6?encryptor[_0x84fd('0x63')](_0x20d7e6)[_0x84fd('0x64')](','):[];if(_0x19d3b1[_0x84fd('0x69')]===0x5){_0x19d3b1[_0x84fd('0x6a')](-0x1,0x1);}_0x19d3b1[_0x84fd('0x6b')](_0x3162d1);return encryptor[_0x84fd('0x6c')](_0x19d3b1[_0x84fd('0x6d')](','));};function signJwt(_0x5c6ce8){var _0x4087b9=BPromise[_0x84fd('0x6e')](jwt[_0x84fd('0x6f')],{'context':jwt});var _0x2bf44b=_0x5c6ce8[_0x84fd('0x70')]||config[_0x84fd('0x71')]['session'];return new BPromise(function(_0x2dd940,_0xb138a){_0x4087b9(_0x5c6ce8['payload'],_0x2bf44b,_0x5c6ce8[_0x84fd('0x72')])[_0x84fd('0x32')](function(_0x207801){_0x2dd940(_0x207801);})[_0x84fd('0x35')](function(_0x4122fd){_0xb138a(_0x4122fd);});});}function verifyJwt(_0x68ac72,_0x440e28,_0x287767){var _0x14efa7=BPromise['promisify'](jwt[_0x84fd('0x73')],{'context':jwt});var _0x1a3ae0=_0x287767||config[_0x84fd('0x71')][_0x84fd('0xa')];return new BPromise(function(_0x42a05e,_0x5420b6){_0x14efa7(_0x68ac72,_0x1a3ae0,_0x440e28)[_0x84fd('0x32')](function(_0x2833c5){_0x42a05e(_0x2833c5);})[_0x84fd('0x35')](function(_0x30483a){_0x5420b6(_0x30483a);});});}function generateNonce(){return crypto[_0x84fd('0x74')](0x10)['toString'](_0x84fd('0x75'));}function generateIssuedAt(){return Math['floor'](Date[_0x84fd('0x76')]()/0x3e8)['toString']();}function createJwt(_0x180bdb){var _0x51f213={'payload':{'iat':_0x180bdb['apiKeyIat'],'nonce':_0x180bdb[_0x84fd('0x5a')]},'options':{'algorithm':_0x84fd('0x77'),'subject':_0x180bdb['id'][_0x84fd('0x78')](),'issuer':hardwareConf[_0x84fd('0x41')](),'audience':hardwareConf[_0x84fd('0x41')]()}};return signJwt(_0x51f213)[_0x84fd('0x32')](function(_0x233de5){return{'iat':_0x180bdb[_0x84fd('0x5d')],'nonce':_0x180bdb[_0x84fd('0x5a')],'token':_0x233de5};});}