8618e5824c0a842649127e53b42e4c45feb47094
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xc705=['retrieveApiKey','apiKeyIat','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','splice','unshift','encryptString','sign','secret','payload','options','promisify','verify','randomBytes','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','jsonwebtoken','composable-middleware','basic-auth','crypto','util','moment','secrets','session','fullname','name','email','userpic','permissions','md5secret','voicePause','mailPause','faxPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarDnd','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','privacyEnabled','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','ignorePauseForPreviewCalls','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','then','status','unmanaged','json','Unmanaged.','catch','headers','authorization','Basic','User','find','pass','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','query','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','Invalid\x20API\x20access\x20key','blockedAt','minutes','User\x20not\x20found.','canUpdate','getLicense','isWebrtcLicence','webrtc','isMiddleware','signToken','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send'];(function(_0x2c91e9,_0x2fb965){var _0x13f0ff=function(_0xb39edf){while(--_0xb39edf){_0x2c91e9['push'](_0x2c91e9['shift']());}};_0x13f0ff(++_0x2fb965);}(_0xc705,0x114));var _0x5c70=function(_0x5311e8,_0x57c5bb){_0x5311e8=_0x5311e8-0x0;var _0x582ad8=_0xc705[_0x5311e8];return _0x582ad8;};'use strict';var db=require(_0x5c70('0x0'))['db'];var config=require(_0x5c70('0x1'));var hardwareConf=require(_0x5c70('0x2'));var licenseUtil=require(_0x5c70('0x3'));var encryptor=require(_0x5c70('0x4'));var _=require('lodash');var jwt=require(_0x5c70('0x5'));var expressJwt=require('express-jwt');var compose=require(_0x5c70('0x6'));var basicAuth=require(_0x5c70('0x7'));var crypto=require(_0x5c70('0x8'));var BPromise=require('bluebird');var util=require(_0x5c70('0x9'));var moment=require(_0x5c70('0xa'));var validateJwt=expressJwt({'secret':config[_0x5c70('0xb')][_0x5c70('0xc')]});var userAttributes=['id','role',_0x5c70('0xd'),_0x5c70('0xe'),'internal',_0x5c70('0xf'),_0x5c70('0x10'),_0x5c70('0x11'),_0x5c70('0x12'),_0x5c70('0x13'),'chatPause',_0x5c70('0x14'),_0x5c70('0x15'),'smsPause','openchannelPause',_0x5c70('0x16'),_0x5c70('0x17'),_0x5c70('0x18'),_0x5c70('0x19'),_0x5c70('0x1a'),'allowmessenger',_0x5c70('0x1b'),_0x5c70('0x1c'),_0x5c70('0x1d'),'phoneBarAutoAnswerDelay',_0x5c70('0x1e'),'phoneBarEnableRecording',_0x5c70('0x1f'),'phoneBarEnableSettings',_0x5c70('0x20'),_0x5c70('0x21'),'phoneBarRemoteControl',_0x5c70('0x22'),_0x5c70('0x23'),_0x5c70('0x24'),_0x5c70('0x25'),_0x5c70('0x26'),'settingsEnabled',_0x5c70('0x27'),_0x5c70('0x28'),_0x5c70('0x29'),_0x5c70('0x2a'),_0x5c70('0x2b'),'selectRecallMeCampaign'];exports[_0x5c70('0x2c')]=function(){return this[_0x5c70('0x2d')](!![])[_0x5c70('0x2e')](function(_0x33999d,_0x10f8de,_0x1c4b6a){if(_0x33999d[_0x5c70('0x2f')]){_0x1c4b6a();}else{return db[_0x5c70('0x30')][_0x5c70('0x31')]({'where':{'id':_0x33999d[_0x5c70('0x32')]['id']},'attributes':['id',_0x5c70('0x33'),_0x5c70('0x34')],'raw':!![]})[_0x5c70('0x35')](function(_0x2ce399){if(_0x2ce399&&_0x2ce399[_0x5c70('0x33')]){return _0x10f8de[_0x5c70('0x36')](_0x2ce399['disposition']===_0x5c70('0x37')?0x195:0x193)[_0x5c70('0x38')]({'message':_0x2ce399[_0x5c70('0x34')]===_0x5c70('0x37')?_0x5c70('0x39'):'Forbidden.'});}else{_0x1c4b6a();}})[_0x5c70('0x3a')](function(_0x51ed38){_0x1c4b6a(_0x51ed38);});}});};exports[_0x5c70('0x2d')]=function isAuthenticated(_0x58d969){return compose()[_0x5c70('0x2e')](function(_0x28cda6,_0x5d2c56,_0x2fb21e){var _0x1934ff;if(_0x28cda6[_0x5c70('0x3b')]['authorization']){if(_['startsWith'](_0x28cda6['headers'][_0x5c70('0x3c')],_0x5c70('0x3d'))){var _0x1e1bbe=basicAuth(_0x28cda6);db[_0x5c70('0x3e')][_0x5c70('0x3f')]({'where':{'name':_0x1e1bbe[_0x5c70('0xe')]}})['then'](function(_0x316584){if(!_0x316584||!_0x316584['authenticate'](_0x1e1bbe[_0x5c70('0x40')])){return _0x5d2c56['status'](0x191)[_0x5c70('0x38')]({'message':_0x5c70('0x41')});}_0x28cda6[_0x5c70('0x2f')]={'id':_0x316584['id']};_0x2fb21e();})['catch'](function(_0xc166d7){_0x2fb21e(_0xc166d7);});}else if(_['startsWith'](_0x28cda6[_0x5c70('0x3b')]['authorization'],_0x5c70('0x42'))){validateJwt(_0x28cda6,_0x5d2c56,_0x2fb21e);}else{if(_0x58d969){_0x2fb21e();}else{return _0x5d2c56[_0x5c70('0x36')](0x193)[_0x5c70('0x38')]({'message':_0x5c70('0x43')});}}}else if(_0x28cda6['query'][_0x5c70('0x44')]){try{var _0x11accc={'audience':hardwareConf[_0x5c70('0x45')](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x28cda6[_0x5c70('0x46')][_0x5c70('0x44')],_0x11accc)[_0x5c70('0x35')](function(_0x38f91f){return db[_0x5c70('0x3e')]['find']({'where':{'id':_0x38f91f[_0x5c70('0x47')]}})[_0x5c70('0x35')](function(_0x3d04df){_0x1934ff=_0x3d04df;return db[_0x5c70('0x48')][_0x5c70('0x31')]({'where':{'id':0x1},'attributes':[_0x5c70('0x49'),_0x5c70('0x4a')],'raw':!![]});})[_0x5c70('0x35')](function(_0x3ec913){if(!_0x1934ff||!_[_0x5c70('0x4b')](_0x1934ff[_0x5c70('0x4c')],_0x38f91f[_0x5c70('0x4d')])){return _0x5d2c56[_0x5c70('0x36')](0x191)[_0x5c70('0x38')]({'message':_0x5c70('0x4e')});}if(_0x1934ff[_0x5c70('0x4f')]){return _0x5d2c56[_0x5c70('0x36')](0x191)[_0x5c70('0x38')]({'message':_0x5c70('0x50')});}if(_0x1934ff['blocked']){if(_0x3ec913[_0x5c70('0x4a')]>0x0){if(moment(_0x1934ff[_0x5c70('0x51')])['add'](_0x3ec913[_0x5c70('0x4a')],_0x5c70('0x52'))>moment()){return _0x5d2c56['status'](0x191)[_0x5c70('0x38')]({'message':_0x5c70('0x50')});}}else{return _0x5d2c56[_0x5c70('0x36')](0x191)[_0x5c70('0x38')]({'message':_0x5c70('0x50')});}}_0x28cda6[_0x5c70('0x2f')]={'id':_0x1934ff['id']};_0x2fb21e();});})['catch'](function(){return _0x5d2c56[_0x5c70('0x36')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0xa6e46e){_0x2fb21e(_0xa6e46e);}}else if(_0x58d969){_0x2fb21e();}else{return _0x5d2c56[_0x5c70('0x36')](0x193)[_0x5c70('0x38')]({'message':_0x5c70('0x43')});}})['use'](function(_0x3f417d,_0x40e1a4,_0x3d15bf){if(_0x3f417d[_0x5c70('0x2f')]){db[_0x5c70('0x3e')][_0x5c70('0x3f')]({'where':{'id':_0x3f417d[_0x5c70('0x2f')]['id']},'attributes':userAttributes})[_0x5c70('0x35')](function(_0x47ce7f){if(!_0x47ce7f){return _0x40e1a4[_0x5c70('0x36')](0x194)[_0x5c70('0x38')]({'message':_0x5c70('0x53')});}_0x3f417d[_0x5c70('0x2f')]=_0x47ce7f;_0x3d15bf();})[_0x5c70('0x3a')](function(_0x4f428a){_0x3d15bf(_0x4f428a);});}else if(_0x58d969){_0x3d15bf();}else{return _0x40e1a4[_0x5c70('0x36')](0x194)['json']({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x5c70('0x54')]=function canUpdate(){return compose()['use'](function(_0x2f3142,_0x376ef1,_0x28d21f){return licenseUtil[_0x5c70('0x55')]()[_0x5c70('0x35')](function(_0xe6db1b){if(_0xe6db1b['update']){_0x28d21f();}else{return _0x376ef1[_0x5c70('0x36')](0x193)[_0x5c70('0x38')]({'message':'Forbidden'});}})[_0x5c70('0x3a')](function(_0x1f3fd0){_0x28d21f(_0x1f3fd0);});});};exports[_0x5c70('0x56')]=function isWebrtcLicence(){return compose()[_0x5c70('0x2e')](function(_0x332f6a,_0x2b5e22,_0x6681ad){return licenseUtil[_0x5c70('0x55')]()[_0x5c70('0x35')](function(_0x2bf607){if(_0x2bf607[_0x5c70('0x57')]){_0x6681ad();}else{return _0x2b5e22[_0x5c70('0x36')](0x193)[_0x5c70('0x38')]({'message':'Forbidden'});}})['catch'](function(_0x5e7ce4){_0x6681ad(_0x5e7ce4);});});};exports[_0x5c70('0x58')]=function(_0x3a7604,_0x1f9c51,_0x36a28e){_0x3a7604[_0x5c70('0x58')]=!![];return _0x36a28e();};exports[_0x5c70('0x59')]=function signToken(_0x3007c6){return signJwt(_0x3007c6);};exports['setTokenCookie']=function(_0x4b3a64,_0x1e8d49){if(!_0x4b3a64[_0x5c70('0x2f')]){return _0x1e8d49[_0x5c70('0x36')](0x194)['json']({'message':_0x5c70('0x5a')});}var _0x17e06b={'payload':{'id':_0x4b3a64[_0x5c70('0x2f')]['id'],'role':_0x4b3a64[_0x5c70('0x2f')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x17e06b)[_0x5c70('0x35')](function(_0x18cde9){_0x1e8d49[_0x5c70('0x5b')](_0x5c70('0x5c'),_0x18cde9);_0x1e8d49[_0x5c70('0x5d')](_0x5c70('0x5e'));})[_0x5c70('0x3a')](function(_0x20e479){return _0x1e8d49['status'](0x1f4)[_0x5c70('0x5f')](_0x20e479);});};exports[_0x5c70('0x60')]=function(_0x5d68f1){if(_['isNil'](_0x5d68f1[_0x5c70('0x4c')])||_['isNil'](_0x5d68f1[_0x5c70('0x61')])){return null;}else{return createJwt(_0x5d68f1);}};exports['generateApiKey']=function(_0x2d96c5){_0x2d96c5[_0x5c70('0x4c')]=generateNonce();_0x2d96c5[_0x5c70('0x61')]=generateIssuedAt();return createJwt(_0x2d96c5);};exports['regenerateApiKey']=function(_0x20f8f5,_0x5d5a0c){var _0x24bb3f=_0x20f8f5[_0x5c70('0x46')][_0x5c70('0x44')];if(_0x24bb3f){var _0x24fa4c={'nonce':_0x5d5a0c[_0x5c70('0x4c')],'iat':_0x5d5a0c['apiKeyIat'],'audience':hardwareConf[_0x5c70('0x45')](),'issuer':hardwareConf[_0x5c70('0x45')]()};return verifyJwt(_0x24bb3f,_0x24fa4c)[_0x5c70('0x35')](function(){return generateApiKey(_0x5d5a0c);});}else{throw{'message':_0x5c70('0x62')};}};exports['validatePasswordPattern']=function(_0x10b2f3){var _0x487c0f=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x487c0f['test'](_0x10b2f3))throw new db['Sequelize'][(_0x5c70('0x63'))](_0x5c70('0x64'));return;};exports[_0x5c70('0x65')]=function(_0x17681a,_0x2dd55f,_0x1cbac8){var _0x3b5951=encryptor[_0x5c70('0x66')](_0x2dd55f)[_0x5c70('0x67')](',');for(var _0x2585fc=0x0;_0x2585fc<_0x1cbac8;_0x2585fc++){if(!_0x3b5951[_0x2585fc])break;if(_0x17681a[_0x5c70('0x68')]()===_0x3b5951[_0x2585fc]['toLowerCase']()){var _0x1857e1=util['format'](_0x5c70('0x69'),_0x1cbac8);if(_0x1cbac8===0x1){_0x1857e1=_0x5c70('0x6a');}throw new db['Sequelize'][(_0x5c70('0x63'))](_0x1857e1);}}return;};exports[_0x5c70('0x6b')]=function(_0x496613,_0x45cc4b){var _0x5761dd=_0x45cc4b?encryptor[_0x5c70('0x66')](_0x45cc4b)[_0x5c70('0x67')](','):[];if(_0x5761dd[_0x5c70('0x6c')]===0x5){_0x5761dd[_0x5c70('0x6d')](-0x1,0x1);}_0x5761dd[_0x5c70('0x6e')](_0x496613);return encryptor[_0x5c70('0x6f')](_0x5761dd['join'](','));};function signJwt(_0x5c6861){var _0xea08b5=BPromise['promisify'](jwt[_0x5c70('0x70')],{'context':jwt});var _0xc53e36=_0x5c6861[_0x5c70('0x71')]||config[_0x5c70('0xb')][_0x5c70('0xc')];return new BPromise(function(_0x1646d,_0x4f7fba){_0xea08b5(_0x5c6861[_0x5c70('0x72')],_0xc53e36,_0x5c6861[_0x5c70('0x73')])[_0x5c70('0x35')](function(_0x31e102){_0x1646d(_0x31e102);})[_0x5c70('0x3a')](function(_0x52a5ab){_0x4f7fba(_0x52a5ab);});});}function verifyJwt(_0x1ae6f8,_0x21b3e6,_0x28f45b){var _0x52856c=BPromise[_0x5c70('0x74')](jwt[_0x5c70('0x75')],{'context':jwt});var _0x4fcd4=_0x28f45b||config[_0x5c70('0xb')][_0x5c70('0xc')];return new BPromise(function(_0x55d03a,_0x2294f1){_0x52856c(_0x1ae6f8,_0x4fcd4,_0x21b3e6)[_0x5c70('0x35')](function(_0x1038bd){_0x55d03a(_0x1038bd);})[_0x5c70('0x3a')](function(_0x3a8731){_0x2294f1(_0x3a8731);});});}function generateNonce(){return crypto[_0x5c70('0x76')](0x10)[_0x5c70('0x77')](_0x5c70('0x78'));}function generateIssuedAt(){return Math[_0x5c70('0x79')](Date[_0x5c70('0x7a')]()/0x3e8)[_0x5c70('0x77')]();}function createJwt(_0x5c628d){var _0x529940={'payload':{'iat':_0x5c628d[_0x5c70('0x61')],'nonce':_0x5c628d[_0x5c70('0x4c')]},'options':{'algorithm':_0x5c70('0x7b'),'subject':_0x5c628d['id'][_0x5c70('0x77')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x5c70('0x45')]()}};return signJwt(_0x529940)['then'](function(_0xf61881){return{'iat':_0x5c628d[_0x5c70('0x61')],'nonce':_0x5c628d[_0x5c70('0x4c')],'token':_0xf61881};});}