6a1b0102d122ad99f031b2c562f9bf98c3892daa
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x38ee=['catch','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','Setting','findOne','allowedLoginAttempts','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blocked','blockDuration','blockedAt','add','minutes','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','update','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','role','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','apiKeyIat','regenerateApiKey','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','decryptString','length','splice','unshift','join','promisify','sign','payload','verify','randomBytes','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','lodash','jsonwebtoken','express-jwt','crypto','bluebird','moment','secrets','session','fullname','name','internal','email','permissions','md5secret','voicePause','mailPause','smsPause','openchannelPause','pauseType','showWebBar','lastPauseAt','allowmessenger','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableDtmfTone','phoneBarPrefixRequired','phoneBarRemoteControlPort','hotdesk','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','closed','disposition','then','status','unmanaged','Forbidden.','headers','authorization','startsWith','Basic','User','find','json','Wrong\x20credentials.'];(function(_0x2bb6dd,_0x252667){var _0x2a07dc=function(_0x1b6693){while(--_0x1b6693){_0x2bb6dd['push'](_0x2bb6dd['shift']());}};_0x2a07dc(++_0x252667);}(_0x38ee,0xba));var _0xe38e=function(_0x4f5108,_0x46a54b){_0x4f5108=_0x4f5108-0x0;var _0x2d56ca=_0x38ee[_0x4f5108];return _0x2d56ca;};'use strict';var db=require(_0xe38e('0x0'))['db'];var config=require(_0xe38e('0x1'));var hardwareConf=require(_0xe38e('0x2'));var licenseUtil=require(_0xe38e('0x3'));var encryptor=require('../encryptor');var _=require(_0xe38e('0x4'));var jwt=require(_0xe38e('0x5'));var expressJwt=require(_0xe38e('0x6'));var compose=require('composable-middleware');var basicAuth=require('basic-auth');var crypto=require(_0xe38e('0x7'));var BPromise=require(_0xe38e('0x8'));var util=require('util');var moment=require(_0xe38e('0x9'));var validateJwt=expressJwt({'secret':config[_0xe38e('0xa')][_0xe38e('0xb')]});var userAttributes=['id','role',_0xe38e('0xc'),_0xe38e('0xd'),_0xe38e('0xe'),_0xe38e('0xf'),'userpic',_0xe38e('0x10'),_0xe38e('0x11'),_0xe38e('0x12'),'chatPause',_0xe38e('0x13'),'faxPause',_0xe38e('0x14'),_0xe38e('0x15'),_0xe38e('0x16'),_0xe38e('0x17'),'lastLoginAt',_0xe38e('0x18'),'crudPermissions',_0xe38e('0x19'),'passwordResetAt',_0xe38e('0x1a'),_0xe38e('0x1b'),_0xe38e('0x1c'),_0xe38e('0x1d'),'phoneBarEnableRecording',_0xe38e('0x1e'),'phoneBarEnableSettings','phoneBarExpires',_0xe38e('0x1f'),'phoneBarRemoteControl',_0xe38e('0x20'),_0xe38e('0x21'),'interface','userProfileId',_0xe38e('0x22')];exports[_0xe38e('0x23')]=function(){return this[_0xe38e('0x24')](!![])[_0xe38e('0x25')](function(_0x477de6,_0x25e519,_0x1ba74a){if(_0x477de6[_0xe38e('0x26')]){_0x1ba74a();}else{return db[_0xe38e('0x27')]['findOne']({'where':{'id':_0x477de6['params']['id']},'attributes':['id',_0xe38e('0x28'),_0xe38e('0x29')],'raw':!![]})[_0xe38e('0x2a')](function(_0x156d93){if(_0x156d93&&_0x156d93['closed']){return _0x25e519[_0xe38e('0x2b')](_0x156d93[_0xe38e('0x29')]===_0xe38e('0x2c')?0x195:0x193)['json']({'message':_0x156d93['disposition']===_0xe38e('0x2c')?'Unmanaged.':_0xe38e('0x2d')});}else{_0x1ba74a();}})['catch'](function(_0xbc3f8d){_0x1ba74a(_0xbc3f8d);});}});};exports[_0xe38e('0x24')]=function isAuthenticated(_0xbbd3c3){return compose()[_0xe38e('0x25')](function(_0x56d3cb,_0x5cc6d3,_0x301772){var _0x1cf02f;if(_0x56d3cb[_0xe38e('0x2e')][_0xe38e('0x2f')]){if(_[_0xe38e('0x30')](_0x56d3cb[_0xe38e('0x2e')][_0xe38e('0x2f')],_0xe38e('0x31'))){var _0x42057b=basicAuth(_0x56d3cb);db[_0xe38e('0x32')][_0xe38e('0x33')]({'where':{'name':_0x42057b[_0xe38e('0xd')]}})[_0xe38e('0x2a')](function(_0x1e3571){if(!_0x1e3571||!_0x1e3571['authenticate'](_0x42057b['pass'])){return _0x5cc6d3[_0xe38e('0x2b')](0x191)[_0xe38e('0x34')]({'message':_0xe38e('0x35')});}_0x56d3cb[_0xe38e('0x26')]={'id':_0x1e3571['id']};_0x301772();})[_0xe38e('0x36')](function(_0x48c3d2){_0x301772(_0x48c3d2);});}else if(_['startsWith'](_0x56d3cb[_0xe38e('0x2e')][_0xe38e('0x2f')],_0xe38e('0x37'))){validateJwt(_0x56d3cb,_0x5cc6d3,_0x301772);}else{if(_0xbbd3c3){_0x301772();}else{return _0x5cc6d3[_0xe38e('0x2b')](0x193)['json']({'message':_0xe38e('0x38')});}}}else if(_0x56d3cb[_0xe38e('0x39')][_0xe38e('0x3a')]){try{var _0x5ba259={'audience':hardwareConf[_0xe38e('0x3b')](),'issuer':hardwareConf[_0xe38e('0x3b')]()};verifyJwt(_0x56d3cb[_0xe38e('0x39')][_0xe38e('0x3a')],_0x5ba259)[_0xe38e('0x2a')](function(_0x2910c1){return db[_0xe38e('0x32')][_0xe38e('0x33')]({'where':{'id':_0x2910c1[_0xe38e('0x3c')]}})['then'](function(_0x2374ec){_0x1cf02f=_0x2374ec;return db[_0xe38e('0x3d')][_0xe38e('0x3e')]({'where':{'id':0x1},'attributes':[_0xe38e('0x3f'),'blockDuration'],'raw':!![]});})['then'](function(_0x2a53c7){if(!_0x1cf02f||!_[_0xe38e('0x40')](_0x1cf02f[_0xe38e('0x41')],_0x2910c1[_0xe38e('0x42')])){return _0x5cc6d3[_0xe38e('0x2b')](0x191)[_0xe38e('0x34')]({'message':_0xe38e('0x43')});}if(_0x1cf02f[_0xe38e('0x44')]){return _0x5cc6d3[_0xe38e('0x2b')](0x191)[_0xe38e('0x34')]({'message':_0xe38e('0x45')});}if(_0x1cf02f[_0xe38e('0x46')]){if(_0x2a53c7[_0xe38e('0x47')]>0x0){if(moment(_0x1cf02f[_0xe38e('0x48')])[_0xe38e('0x49')](_0x2a53c7[_0xe38e('0x47')],_0xe38e('0x4a'))>moment()){return _0x5cc6d3[_0xe38e('0x2b')](0x191)[_0xe38e('0x34')]({'message':_0xe38e('0x45')});}}else{return _0x5cc6d3[_0xe38e('0x2b')](0x191)['json']({'message':_0xe38e('0x45')});}}_0x56d3cb[_0xe38e('0x26')]={'id':_0x1cf02f['id']};_0x301772();});})['catch'](function(){return _0x5cc6d3['status'](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x3b422d){_0x301772(_0x3b422d);}}else if(_0xbbd3c3){_0x301772();}else{return _0x5cc6d3[_0xe38e('0x2b')](0x193)[_0xe38e('0x34')]({'message':_0xe38e('0x38')});}})[_0xe38e('0x25')](function(_0x432777,_0x1c221c,_0x3dcc13){if(_0x432777[_0xe38e('0x26')]){db['User'][_0xe38e('0x33')]({'where':{'id':_0x432777[_0xe38e('0x26')]['id']},'attributes':userAttributes})[_0xe38e('0x2a')](function(_0x29911f){if(!_0x29911f){return _0x1c221c[_0xe38e('0x2b')](0x194)[_0xe38e('0x34')]({'message':_0xe38e('0x4b')});}_0x432777[_0xe38e('0x26')]=_0x29911f;_0x3dcc13();})[_0xe38e('0x36')](function(_0x50a8fa){_0x3dcc13(_0x50a8fa);});}else if(_0xbbd3c3){_0x3dcc13();}else{return _0x1c221c['status'](0x194)['json']({'message':_0xe38e('0x4c')});}});};exports[_0xe38e('0x4d')]=function canUpdate(){return compose()[_0xe38e('0x25')](function(_0x466e3c,_0x5d228d,_0x2c9879){return licenseUtil['getLicense']()['then'](function(_0xd284a7){if(_0xd284a7[_0xe38e('0x4e')]){_0x2c9879();}else{return _0x5d228d[_0xe38e('0x2b')](0x193)[_0xe38e('0x34')]({'message':_0xe38e('0x4f')});}})['catch'](function(_0x5219a1){_0x2c9879(_0x5219a1);});});};exports[_0xe38e('0x50')]=function(_0x52c605,_0x4e395d,_0x4eca25){_0x52c605['isMiddleware']=!![];return _0x4eca25();};exports[_0xe38e('0x51')]=function signToken(_0x111a25){return signJwt(_0x111a25);};exports[_0xe38e('0x52')]=function(_0x27af6e,_0x4f6f87){if(!_0x27af6e[_0xe38e('0x26')]){return _0x4f6f87['status'](0x194)[_0xe38e('0x34')]({'message':_0xe38e('0x53')});}var _0x4ea226={'payload':{'id':_0x27af6e[_0xe38e('0x26')]['id'],'role':_0x27af6e[_0xe38e('0x26')][_0xe38e('0x54')]},'options':{'expiresIn':0x15180}};return signJwt(_0x4ea226)[_0xe38e('0x2a')](function(_0x46c4a3){_0x4f6f87[_0xe38e('0x55')](_0xe38e('0x56'),_0x46c4a3);_0x4f6f87[_0xe38e('0x57')](_0xe38e('0x58'));})[_0xe38e('0x36')](function(_0x47e199){return _0x4f6f87[_0xe38e('0x2b')](0x1f4)[_0xe38e('0x59')](_0x47e199);});};exports[_0xe38e('0x5a')]=function(_0x374256){if(_[_0xe38e('0x5b')](_0x374256[_0xe38e('0x41')])||_[_0xe38e('0x5b')](_0x374256[_0xe38e('0x5c')])){return null;}else{return createJwt(_0x374256);}};exports['generateApiKey']=function(_0x178145){_0x178145[_0xe38e('0x41')]=generateNonce();_0x178145['apiKeyIat']=generateIssuedAt();return createJwt(_0x178145);};exports[_0xe38e('0x5d')]=function(_0x27d1ec,_0xcc4c51){var _0x6f72c0=_0x27d1ec[_0xe38e('0x39')][_0xe38e('0x3a')];if(_0x6f72c0){var _0x2173ad={'nonce':_0xcc4c51[_0xe38e('0x41')],'iat':_0xcc4c51[_0xe38e('0x5c')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0xe38e('0x3b')]()};return verifyJwt(_0x6f72c0,_0x2173ad)[_0xe38e('0x2a')](function(){return generateApiKey(_0xcc4c51);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0xe38e('0x5e')]=function(_0x368bd3){var _0x468ce5=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x468ce5[_0xe38e('0x5f')](_0x368bd3))throw new db[(_0xe38e('0x60'))][(_0xe38e('0x61'))](_0xe38e('0x62'));return;};exports[_0xe38e('0x63')]=function(_0x34b42c,_0x102b37,_0x5d451c){var _0x2c0037=encryptor['decryptString'](_0x102b37)['split'](',');for(var _0x28332d=0x0;_0x28332d<_0x5d451c;_0x28332d++){if(!_0x2c0037[_0x28332d])break;if(_0x34b42c['toLowerCase']()===_0x2c0037[_0x28332d][_0xe38e('0x64')]()){var _0x534eab=util[_0xe38e('0x65')](_0xe38e('0x66'),_0x5d451c);if(_0x5d451c===0x1){_0x534eab=_0xe38e('0x67');}throw new db[(_0xe38e('0x60'))][(_0xe38e('0x61'))](_0x534eab);}}return;};exports[_0xe38e('0x68')]=function(_0xed6a90,_0x2b3fb2){var _0x4fba06=_0x2b3fb2?encryptor[_0xe38e('0x69')](_0x2b3fb2)['split'](','):[];if(_0x4fba06[_0xe38e('0x6a')]===0x5){_0x4fba06[_0xe38e('0x6b')](-0x1,0x1);}_0x4fba06[_0xe38e('0x6c')](_0xed6a90);return encryptor['encryptString'](_0x4fba06[_0xe38e('0x6d')](','));};function signJwt(_0x5543a6){var _0x4526c1=BPromise[_0xe38e('0x6e')](jwt[_0xe38e('0x6f')],{'context':jwt});var _0x16c5fb=_0x5543a6['secret']||config[_0xe38e('0xa')][_0xe38e('0xb')];return new BPromise(function(_0x590ac3,_0x1f9e67){_0x4526c1(_0x5543a6[_0xe38e('0x70')],_0x16c5fb,_0x5543a6['options'])['then'](function(_0x388720){_0x590ac3(_0x388720);})[_0xe38e('0x36')](function(_0x3c09c9){_0x1f9e67(_0x3c09c9);});});}function verifyJwt(_0x2121e8,_0x549a67,_0x55ad61){var _0x468351=BPromise[_0xe38e('0x6e')](jwt[_0xe38e('0x71')],{'context':jwt});var _0x5b1397=_0x55ad61||config[_0xe38e('0xa')][_0xe38e('0xb')];return new BPromise(function(_0x29d38a,_0x52fcb7){_0x468351(_0x2121e8,_0x5b1397,_0x549a67)[_0xe38e('0x2a')](function(_0x269e1){_0x29d38a(_0x269e1);})[_0xe38e('0x36')](function(_0x5f5abb){_0x52fcb7(_0x5f5abb);});});}function generateNonce(){return crypto[_0xe38e('0x72')](0x10)[_0xe38e('0x73')](_0xe38e('0x74'));}function generateIssuedAt(){return Math[_0xe38e('0x75')](Date[_0xe38e('0x76')]()/0x3e8)['toString']();}function createJwt(_0x1e5572){var _0x1c5bd6={'payload':{'iat':_0x1e5572['apiKeyIat'],'nonce':_0x1e5572['apiKeyNonce']},'options':{'algorithm':_0xe38e('0x77'),'subject':_0x1e5572['id'][_0xe38e('0x73')](),'issuer':hardwareConf[_0xe38e('0x3b')](),'audience':hardwareConf[_0xe38e('0x3b')]()}};return signJwt(_0x1c5bd6)[_0xe38e('0x2a')](function(_0x1b1d5b){return{'iat':_0x1e5572[_0xe38e('0x5c')],'nonce':_0x1e5572['apiKeyNonce'],'token':_0x1b1d5b};});}