6ad7ae6aa31787c3439d3c72d65c0f43d1d40123
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x405e=['startsWith','authorization','Basic','find','authenticate','pass','json','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','User','sub','findOne','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blockedAt','add','canUpdate','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','send','retrieveApiKey','isNil','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','decryptString','split','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','splice','unshift','encryptString','join','promisify','options','verify','randomBytes','toString','hex','floor','now','HS512','../../config/license/hardware','../encryptor','jsonwebtoken','express-jwt','composable-middleware','crypto','bluebird','util','moment','secrets','session','role','fullname','name','internal','email','userpic','permissions','md5secret','voicePause','chatPause','mailPause','faxPause','openchannelPause','pauseType','lastPauseAt','crudPermissions','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','params','closed','disposition','then','status','unmanaged','Unmanaged.','Forbidden.','catch','headers'];(function(_0x34870a,_0x434e3f){var _0x56f666=function(_0x560728){while(--_0x560728){_0x34870a['push'](_0x34870a['shift']());}};_0x56f666(++_0x434e3f);}(_0x405e,0xbf));var _0xe405=function(_0x4b1c06,_0x589d2a){_0x4b1c06=_0x4b1c06-0x0;var _0x3512aa=_0x405e[_0x4b1c06];return _0x3512aa;};'use strict';var db=require('../../mysqldb')['db'];var config=require('../../config/environment');var hardwareConf=require(_0xe405('0x0'));var licenseUtil=require('../../config/license/util');var encryptor=require(_0xe405('0x1'));var _=require('lodash');var jwt=require(_0xe405('0x2'));var expressJwt=require(_0xe405('0x3'));var compose=require(_0xe405('0x4'));var basicAuth=require('basic-auth');var crypto=require(_0xe405('0x5'));var BPromise=require(_0xe405('0x6'));var util=require(_0xe405('0x7'));var moment=require(_0xe405('0x8'));var validateJwt=expressJwt({'secret':config[_0xe405('0x9')][_0xe405('0xa')]});var userAttributes=['id',_0xe405('0xb'),_0xe405('0xc'),_0xe405('0xd'),_0xe405('0xe'),_0xe405('0xf'),_0xe405('0x10'),_0xe405('0x11'),_0xe405('0x12'),_0xe405('0x13'),_0xe405('0x14'),_0xe405('0x15'),_0xe405('0x16'),'smsPause',_0xe405('0x17'),_0xe405('0x18'),'showWebBar','lastLoginAt',_0xe405('0x19'),_0xe405('0x1a'),'allowmessenger',_0xe405('0x1b'),_0xe405('0x1c'),_0xe405('0x1d'),'phoneBarAutoAnswerDelay',_0xe405('0x1e'),_0xe405('0x1f'),_0xe405('0x20'),_0xe405('0x21'),_0xe405('0x22'),_0xe405('0x23'),_0xe405('0x24'),_0xe405('0x25'),_0xe405('0x26'),_0xe405('0x27'),_0xe405('0x28'),_0xe405('0x29')];exports[_0xe405('0x2a')]=function(){return this[_0xe405('0x2b')](!![])[_0xe405('0x2c')](function(_0x1af5c7,_0x4a0cf1,_0x23e02b){if(_0x1af5c7[_0xe405('0x2d')]){_0x23e02b();}else{return db[_0xe405('0x2e')]['findOne']({'where':{'id':_0x1af5c7[_0xe405('0x2f')]['id']},'attributes':['id',_0xe405('0x30'),_0xe405('0x31')],'raw':!![]})[_0xe405('0x32')](function(_0x40dcc7){if(_0x40dcc7&&_0x40dcc7[_0xe405('0x30')]){return _0x4a0cf1[_0xe405('0x33')](_0x40dcc7[_0xe405('0x31')]===_0xe405('0x34')?0x195:0x193)['json']({'message':_0x40dcc7[_0xe405('0x31')]===_0xe405('0x34')?_0xe405('0x35'):_0xe405('0x36')});}else{_0x23e02b();}})[_0xe405('0x37')](function(_0x40d8d6){_0x23e02b(_0x40d8d6);});}});};exports[_0xe405('0x2b')]=function isAuthenticated(_0x187e85){return compose()[_0xe405('0x2c')](function(_0x41ade6,_0x469995,_0x2e20f1){var _0x59f20d;if(_0x41ade6[_0xe405('0x38')]['authorization']){if(_[_0xe405('0x39')](_0x41ade6[_0xe405('0x38')][_0xe405('0x3a')],_0xe405('0x3b'))){var _0x2dd2d8=basicAuth(_0x41ade6);db['User'][_0xe405('0x3c')]({'where':{'name':_0x2dd2d8[_0xe405('0xd')]}})[_0xe405('0x32')](function(_0x11ebe9){if(!_0x11ebe9||!_0x11ebe9[_0xe405('0x3d')](_0x2dd2d8[_0xe405('0x3e')])){return _0x469995[_0xe405('0x33')](0x191)[_0xe405('0x3f')]({'message':'Wrong\x20credentials.'});}_0x41ade6[_0xe405('0x2d')]={'id':_0x11ebe9['id']};_0x2e20f1();})[_0xe405('0x37')](function(_0x3d1893){_0x2e20f1(_0x3d1893);});}else if(_['startsWith'](_0x41ade6['headers'][_0xe405('0x3a')],_0xe405('0x40'))){validateJwt(_0x41ade6,_0x469995,_0x2e20f1);}else{if(_0x187e85){_0x2e20f1();}else{return _0x469995[_0xe405('0x33')](0x193)['json']({'message':_0xe405('0x41')});}}}else if(_0x41ade6[_0xe405('0x42')]['apikey']){try{var _0x521b1f={'audience':hardwareConf[_0xe405('0x43')](),'issuer':hardwareConf[_0xe405('0x43')]()};verifyJwt(_0x41ade6[_0xe405('0x42')][_0xe405('0x44')],_0x521b1f)['then'](function(_0x3503e9){return db[_0xe405('0x45')][_0xe405('0x3c')]({'where':{'id':_0x3503e9[_0xe405('0x46')]}})['then'](function(_0x44955c){_0x59f20d=_0x44955c;return db['Setting'][_0xe405('0x47')]({'where':{'id':0x1},'attributes':[_0xe405('0x48'),_0xe405('0x49')],'raw':!![]});})['then'](function(_0x40324e){if(!_0x59f20d||!_[_0xe405('0x4a')](_0x59f20d[_0xe405('0x4b')],_0x3503e9[_0xe405('0x4c')])){return _0x469995['status'](0x191)['json']({'message':_0xe405('0x4d')});}if(_0x59f20d[_0xe405('0x4e')]){return _0x469995['status'](0x191)[_0xe405('0x3f')]({'message':_0xe405('0x4f')});}if(_0x59f20d['blocked']){if(_0x40324e[_0xe405('0x49')]>0x0){if(moment(_0x59f20d[_0xe405('0x50')])[_0xe405('0x51')](_0x40324e[_0xe405('0x49')],'minutes')>moment()){return _0x469995[_0xe405('0x33')](0x191)[_0xe405('0x3f')]({'message':_0xe405('0x4f')});}}else{return _0x469995['status'](0x191)[_0xe405('0x3f')]({'message':_0xe405('0x4f')});}}_0x41ade6[_0xe405('0x2d')]={'id':_0x59f20d['id']};_0x2e20f1();});})[_0xe405('0x37')](function(){return _0x469995[_0xe405('0x33')](0x191)[_0xe405('0x3f')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x4ae38c){_0x2e20f1(_0x4ae38c);}}else if(_0x187e85){_0x2e20f1();}else{return _0x469995[_0xe405('0x33')](0x193)[_0xe405('0x3f')]({'message':_0xe405('0x41')});}})['use'](function(_0x2ccfbe,_0x45c4c1,_0x67fe46){if(_0x2ccfbe['user']){db[_0xe405('0x45')][_0xe405('0x3c')]({'where':{'id':_0x2ccfbe[_0xe405('0x2d')]['id']},'attributes':userAttributes})[_0xe405('0x32')](function(_0x17e07d){if(!_0x17e07d){return _0x45c4c1[_0xe405('0x33')](0x194)[_0xe405('0x3f')]({'message':'User\x20not\x20found.'});}_0x2ccfbe['user']=_0x17e07d;_0x67fe46();})[_0xe405('0x37')](function(_0x273925){_0x67fe46(_0x273925);});}else if(_0x187e85){_0x67fe46();}else{return _0x45c4c1['status'](0x194)['json']({'message':'User\x20object\x20not\x20found.'});}});};exports[_0xe405('0x52')]=function canUpdate(){return compose()['use'](function(_0x4378f5,_0x189d9e,_0x3c9f60){return licenseUtil[_0xe405('0x53')]()[_0xe405('0x32')](function(_0x4a6aba){if(_0x4a6aba[_0xe405('0x54')]){_0x3c9f60();}else{return _0x189d9e[_0xe405('0x33')](0x193)['json']({'message':_0xe405('0x55')});}})['catch'](function(_0x3f476e){_0x3c9f60(_0x3f476e);});});};exports[_0xe405('0x56')]=function(_0x1fbefc,_0x4b7cd6,_0x2abfd6){_0x1fbefc[_0xe405('0x56')]=!![];return _0x2abfd6();};exports[_0xe405('0x57')]=function signToken(_0x14df00){return signJwt(_0x14df00);};exports[_0xe405('0x58')]=function(_0x2a5e9e,_0x4dc5a5){if(!_0x2a5e9e[_0xe405('0x2d')]){return _0x4dc5a5[_0xe405('0x33')](0x194)[_0xe405('0x3f')]({'message':_0xe405('0x59')});}var _0x22b0e4={'payload':{'id':_0x2a5e9e['user']['id'],'role':_0x2a5e9e[_0xe405('0x2d')][_0xe405('0xb')]},'options':{'expiresIn':0x15180}};return signJwt(_0x22b0e4)[_0xe405('0x32')](function(_0x19a076){_0x4dc5a5[_0xe405('0x5a')](_0xe405('0x5b'),_0x19a076);_0x4dc5a5['redirect']('/dashboards/general');})[_0xe405('0x37')](function(_0x37d803){return _0x4dc5a5['status'](0x1f4)[_0xe405('0x5c')](_0x37d803);});};exports[_0xe405('0x5d')]=function(_0x1404e9){if(_[_0xe405('0x5e')](_0x1404e9[_0xe405('0x4b')])||_[_0xe405('0x5e')](_0x1404e9[_0xe405('0x5f')])){return null;}else{return createJwt(_0x1404e9);}};exports[_0xe405('0x60')]=function(_0x938616){_0x938616[_0xe405('0x4b')]=generateNonce();_0x938616[_0xe405('0x5f')]=generateIssuedAt();return createJwt(_0x938616);};exports[_0xe405('0x61')]=function(_0x104033,_0x5c0c40){var _0x3e8189=_0x104033[_0xe405('0x42')][_0xe405('0x44')];if(_0x3e8189){var _0x2b0726={'nonce':_0x5c0c40[_0xe405('0x4b')],'iat':_0x5c0c40[_0xe405('0x5f')],'audience':hardwareConf[_0xe405('0x43')](),'issuer':hardwareConf['getUuid']()};return verifyJwt(_0x3e8189,_0x2b0726)[_0xe405('0x32')](function(){return generateApiKey(_0x5c0c40);});}else{throw{'message':_0xe405('0x62')};}};exports[_0xe405('0x63')]=function(_0x560852){var _0x2f0b07=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x2f0b07[_0xe405('0x64')](_0x560852))throw new db[(_0xe405('0x65'))][(_0xe405('0x66'))](_0xe405('0x67'));return;};exports['validatePasswordHistory']=function(_0xffead1,_0x7a7ba6,_0x4735e5){var _0x4d1e7a=encryptor[_0xe405('0x68')](_0x7a7ba6)[_0xe405('0x69')](',');for(var _0xb90f0c=0x0;_0xb90f0c<_0x4735e5;_0xb90f0c++){if(!_0x4d1e7a[_0xb90f0c])break;if(_0xffead1['toLowerCase']()===_0x4d1e7a[_0xb90f0c]['toLowerCase']()){var _0x26e710=util[_0xe405('0x6a')](_0xe405('0x6b'),_0x4735e5);if(_0x4735e5===0x1){_0x26e710=_0xe405('0x6c');}throw new db[(_0xe405('0x65'))][(_0xe405('0x66'))](_0x26e710);}}return;};exports[_0xe405('0x6d')]=function(_0x311c82,_0x22abf7){var _0x29dd27=_0x22abf7?encryptor[_0xe405('0x68')](_0x22abf7)['split'](','):[];if(_0x29dd27[_0xe405('0x6e')]===0x5){_0x29dd27[_0xe405('0x6f')](-0x1,0x1);}_0x29dd27[_0xe405('0x70')](_0x311c82);return encryptor[_0xe405('0x71')](_0x29dd27[_0xe405('0x72')](','));};function signJwt(_0x26d72e){var _0x18ab29=BPromise[_0xe405('0x73')](jwt['sign'],{'context':jwt});var _0x3a286c=_0x26d72e['secret']||config[_0xe405('0x9')][_0xe405('0xa')];return new BPromise(function(_0x487b68,_0x5bff3e){_0x18ab29(_0x26d72e['payload'],_0x3a286c,_0x26d72e[_0xe405('0x74')])['then'](function(_0x3c2620){_0x487b68(_0x3c2620);})[_0xe405('0x37')](function(_0x1ca538){_0x5bff3e(_0x1ca538);});});}function verifyJwt(_0x331dbd,_0x45f3c0,_0x1b8d24){var _0x4fb05d=BPromise[_0xe405('0x73')](jwt[_0xe405('0x75')],{'context':jwt});var _0x37f099=_0x1b8d24||config[_0xe405('0x9')][_0xe405('0xa')];return new BPromise(function(_0x590173,_0x499d22){_0x4fb05d(_0x331dbd,_0x37f099,_0x45f3c0)['then'](function(_0x454579){_0x590173(_0x454579);})[_0xe405('0x37')](function(_0x1c777d){_0x499d22(_0x1c777d);});});}function generateNonce(){return crypto[_0xe405('0x76')](0x10)[_0xe405('0x77')](_0xe405('0x78'));}function generateIssuedAt(){return Math[_0xe405('0x79')](Date[_0xe405('0x7a')]()/0x3e8)[_0xe405('0x77')]();}function createJwt(_0x3f82eb){var _0x55cdb8={'payload':{'iat':_0x3f82eb[_0xe405('0x5f')],'nonce':_0x3f82eb[_0xe405('0x4b')]},'options':{'algorithm':_0xe405('0x7b'),'subject':_0x3f82eb['id'][_0xe405('0x77')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0xe405('0x43')]()}};return signJwt(_0x55cdb8)[_0xe405('0x32')](function(_0x2ea9f0){return{'iat':_0x3f82eb[_0xe405('0x5f')],'nonce':_0x3f82eb[_0xe405('0x4b')],'token':_0x2ea9f0};});}