9379eef35d31e824e9cd02dd05ec757faad0b6ea
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xebcd=['blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User\x20not\x20found.','User\x20object\x20not\x20found.','getLicense','update','Forbidden','isMiddleware','setTokenCookie','cookie','motion.token','redirect','/dashboards/general','send','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','decryptString','length','splice','encryptString','join','promisify','sign','secret','session','options','toString','floor','now','../../mysqldb','../../config/license/hardware','lodash','express-jwt','basic-auth','crypto','bluebird','util','moment','secrets','role','internal','email','userpic','permissions','md5secret','voicePause','chatPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','use','user','findOne','params','closed','then','unmanaged','json','disposition','Forbidden.','catch','isAuthenticated','headers','authorization','Basic','User','find','name','authenticate','pass','startsWith','Unknown\x20authorization\x20format','query','getUuid','apikey','Setting','isEqual','apiKeyNonce','nonce','status','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','blocked','blockDuration'];(function(_0x415c3e,_0x2a9fcf){var _0x360c00=function(_0x17f375){while(--_0x17f375){_0x415c3e['push'](_0x415c3e['shift']());}};_0x360c00(++_0x2a9fcf);}(_0xebcd,0x18c));var _0xdebc=function(_0x53c256,_0x382a24){_0x53c256=_0x53c256-0x0;var _0x25feb6=_0xebcd[_0x53c256];return _0x25feb6;};'use strict';var db=require(_0xdebc('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0xdebc('0x1'));var licenseUtil=require('../../config/license/util');var encryptor=require('../encryptor');var _=require(_0xdebc('0x2'));var jwt=require('jsonwebtoken');var expressJwt=require(_0xdebc('0x3'));var compose=require('composable-middleware');var basicAuth=require(_0xdebc('0x4'));var crypto=require(_0xdebc('0x5'));var BPromise=require(_0xdebc('0x6'));var util=require(_0xdebc('0x7'));var moment=require(_0xdebc('0x8'));var validateJwt=expressJwt({'secret':config[_0xdebc('0x9')]['session']});var userAttributes=['id',_0xdebc('0xa'),'fullname','name',_0xdebc('0xb'),_0xdebc('0xc'),_0xdebc('0xd'),_0xdebc('0xe'),_0xdebc('0xf'),_0xdebc('0x10'),_0xdebc('0x11'),'mailPause','faxPause',_0xdebc('0x12'),_0xdebc('0x13'),_0xdebc('0x14'),_0xdebc('0x15'),_0xdebc('0x16'),_0xdebc('0x17'),_0xdebc('0x18'),_0xdebc('0x19'),_0xdebc('0x1a'),_0xdebc('0x1b'),_0xdebc('0x1c'),_0xdebc('0x1d'),_0xdebc('0x1e'),_0xdebc('0x1f'),_0xdebc('0x20'),_0xdebc('0x21'),_0xdebc('0x22'),_0xdebc('0x23'),_0xdebc('0x24'),_0xdebc('0x25'),_0xdebc('0x26'),_0xdebc('0x27'),_0xdebc('0x28'),_0xdebc('0x29'),_0xdebc('0x2a')];exports['isChatInteractionAuthorized']=function(){return this['isAuthenticated'](!![])[_0xdebc('0x2b')](function(_0x57405c,_0x3e9526,_0x280c40){if(_0x57405c[_0xdebc('0x2c')]){_0x280c40();}else{return db['ChatInteraction'][_0xdebc('0x2d')]({'where':{'id':_0x57405c[_0xdebc('0x2e')]['id']},'attributes':['id',_0xdebc('0x2f'),'disposition'],'raw':!![]})[_0xdebc('0x30')](function(_0x59501b){if(_0x59501b&&_0x59501b[_0xdebc('0x2f')]){return _0x3e9526['status'](_0x59501b['disposition']===_0xdebc('0x31')?0x195:0x193)[_0xdebc('0x32')]({'message':_0x59501b[_0xdebc('0x33')]===_0xdebc('0x31')?'Unmanaged.':_0xdebc('0x34')});}else{_0x280c40();}})[_0xdebc('0x35')](function(_0x2ba78e){_0x280c40(_0x2ba78e);});}});};exports[_0xdebc('0x36')]=function isAuthenticated(_0x19e843){return compose()['use'](function(_0x1326f7,_0x280499,_0x40d23c){var _0x411315;if(_0x1326f7[_0xdebc('0x37')][_0xdebc('0x38')]){if(_['startsWith'](_0x1326f7['headers'][_0xdebc('0x38')],_0xdebc('0x39'))){var _0x43b0f5=basicAuth(_0x1326f7);db[_0xdebc('0x3a')][_0xdebc('0x3b')]({'where':{'name':_0x43b0f5[_0xdebc('0x3c')]}})[_0xdebc('0x30')](function(_0x4a805e){if(!_0x4a805e||!_0x4a805e[_0xdebc('0x3d')](_0x43b0f5[_0xdebc('0x3e')])){return _0x280499['status'](0x191)['json']({'message':'Wrong\x20credentials.'});}_0x1326f7[_0xdebc('0x2c')]={'id':_0x4a805e['id']};_0x40d23c();})[_0xdebc('0x35')](function(_0x4c18e4){_0x40d23c(_0x4c18e4);});}else if(_[_0xdebc('0x3f')](_0x1326f7[_0xdebc('0x37')][_0xdebc('0x38')],'Bearer')){validateJwt(_0x1326f7,_0x280499,_0x40d23c);}else{if(_0x19e843){_0x40d23c();}else{return _0x280499['status'](0x193)['json']({'message':_0xdebc('0x40')});}}}else if(_0x1326f7[_0xdebc('0x41')]['apikey']){try{var _0x2c1a97={'audience':hardwareConf[_0xdebc('0x42')](),'issuer':hardwareConf[_0xdebc('0x42')]()};verifyJwt(_0x1326f7[_0xdebc('0x41')][_0xdebc('0x43')],_0x2c1a97)[_0xdebc('0x30')](function(_0x1b4b96){return db[_0xdebc('0x3a')][_0xdebc('0x3b')]({'where':{'id':_0x1b4b96['sub']}})[_0xdebc('0x30')](function(_0x20ad61){_0x411315=_0x20ad61;return db[_0xdebc('0x44')][_0xdebc('0x2d')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts','blockDuration'],'raw':!![]});})['then'](function(_0x287393){if(!_0x411315||!_[_0xdebc('0x45')](_0x411315[_0xdebc('0x46')],_0x1b4b96[_0xdebc('0x47')])){return _0x280499[_0xdebc('0x48')](0x191)[_0xdebc('0x32')]({'message':_0xdebc('0x49')});}if(_0x411315['disabled']){return _0x280499[_0xdebc('0x48')](0x191)[_0xdebc('0x32')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x411315[_0xdebc('0x4a')]){if(_0x287393[_0xdebc('0x4b')]>0x0){if(moment(_0x411315[_0xdebc('0x4c')])[_0xdebc('0x4d')](_0x287393[_0xdebc('0x4b')],_0xdebc('0x4e'))>moment()){return _0x280499[_0xdebc('0x48')](0x191)[_0xdebc('0x32')]({'message':'Invalid\x20API\x20access\x20key'});}}else{return _0x280499['status'](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}}_0x1326f7[_0xdebc('0x2c')]={'id':_0x411315['id']};_0x40d23c();});})[_0xdebc('0x35')](function(){return _0x280499[_0xdebc('0x48')](0x191)[_0xdebc('0x32')]({'message':_0xdebc('0x4f')});});}catch(_0x58e140){_0x40d23c(_0x58e140);}}else if(_0x19e843){_0x40d23c();}else{return _0x280499[_0xdebc('0x48')](0x193)[_0xdebc('0x32')]({'message':_0xdebc('0x40')});}})[_0xdebc('0x2b')](function(_0x45a83e,_0x4e56ce,_0x4476e2){if(_0x45a83e['user']){db[_0xdebc('0x3a')][_0xdebc('0x3b')]({'where':{'id':_0x45a83e[_0xdebc('0x2c')]['id']},'attributes':userAttributes})[_0xdebc('0x30')](function(_0x586a0a){if(!_0x586a0a){return _0x4e56ce[_0xdebc('0x48')](0x194)['json']({'message':_0xdebc('0x50')});}_0x45a83e[_0xdebc('0x2c')]=_0x586a0a;_0x4476e2();})[_0xdebc('0x35')](function(_0x50cbdc){_0x4476e2(_0x50cbdc);});}else if(_0x19e843){_0x4476e2();}else{return _0x4e56ce[_0xdebc('0x48')](0x194)['json']({'message':_0xdebc('0x51')});}});};exports['canUpdate']=function canUpdate(){return compose()[_0xdebc('0x2b')](function(_0x3aef58,_0xb4b687,_0xbe0591){return licenseUtil[_0xdebc('0x52')]()[_0xdebc('0x30')](function(_0x2f0dbf){if(_0x2f0dbf[_0xdebc('0x53')]){_0xbe0591();}else{return _0xb4b687[_0xdebc('0x48')](0x193)[_0xdebc('0x32')]({'message':_0xdebc('0x54')});}})['catch'](function(_0xdc10cb){_0xbe0591(_0xdc10cb);});});};exports[_0xdebc('0x55')]=function(_0x267468,_0xb77b70,_0x2fd3d3){_0x267468[_0xdebc('0x55')]=!![];return _0x2fd3d3();};exports['signToken']=function signToken(_0x125633){return signJwt(_0x125633);};exports[_0xdebc('0x56')]=function(_0x124bc7,_0x4bc541){if(!_0x124bc7['user']){return _0x4bc541[_0xdebc('0x48')](0x194)[_0xdebc('0x32')]({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x1969ae={'payload':{'id':_0x124bc7[_0xdebc('0x2c')]['id'],'role':_0x124bc7[_0xdebc('0x2c')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x1969ae)['then'](function(_0x3739a7){_0x4bc541[_0xdebc('0x57')](_0xdebc('0x58'),_0x3739a7);_0x4bc541[_0xdebc('0x59')](_0xdebc('0x5a'));})['catch'](function(_0x383ef6){return _0x4bc541[_0xdebc('0x48')](0x1f4)[_0xdebc('0x5b')](_0x383ef6);});};exports['retrieveApiKey']=function(_0xd0201d){if(_['isNil'](_0xd0201d[_0xdebc('0x46')])||_['isNil'](_0xd0201d[_0xdebc('0x5c')])){return null;}else{return createJwt(_0xd0201d);}};exports[_0xdebc('0x5d')]=function(_0x327e7a){_0x327e7a['apiKeyNonce']=generateNonce();_0x327e7a[_0xdebc('0x5c')]=generateIssuedAt();return createJwt(_0x327e7a);};exports[_0xdebc('0x5e')]=function(_0x1d03ce,_0x2cb013){var _0x1e84f2=_0x1d03ce[_0xdebc('0x41')]['apikey'];if(_0x1e84f2){var _0x2f95ec={'nonce':_0x2cb013[_0xdebc('0x46')],'iat':_0x2cb013[_0xdebc('0x5c')],'audience':hardwareConf[_0xdebc('0x42')](),'issuer':hardwareConf['getUuid']()};return verifyJwt(_0x1e84f2,_0x2f95ec)['then'](function(){return generateApiKey(_0x2cb013);});}else{throw{'message':_0xdebc('0x5f')};}};exports[_0xdebc('0x60')]=function(_0x5b7a31){var _0x3fe968=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x3fe968['test'](_0x5b7a31))throw new db[(_0xdebc('0x61'))][(_0xdebc('0x62'))](_0xdebc('0x63'));return;};exports['validatePasswordHistory']=function(_0x376dbe,_0x32d74b,_0x41af22){var _0x3d782a=encryptor['decryptString'](_0x32d74b)[_0xdebc('0x64')](',');for(var _0x194d84=0x0;_0x194d84<_0x41af22;_0x194d84++){if(!_0x3d782a[_0x194d84])break;if(_0x376dbe[_0xdebc('0x65')]()===_0x3d782a[_0x194d84][_0xdebc('0x65')]()){var _0x35ed09=util[_0xdebc('0x66')](_0xdebc('0x67'),_0x41af22);if(_0x41af22===0x1){_0x35ed09=_0xdebc('0x68');}throw new db[(_0xdebc('0x61'))][(_0xdebc('0x62'))](_0x35ed09);}}return;};exports['updatePasswordsHistory']=function(_0x1dfee7,_0x5d80fa){var _0x2e0676=_0x5d80fa?encryptor[_0xdebc('0x69')](_0x5d80fa)[_0xdebc('0x64')](','):[];if(_0x2e0676[_0xdebc('0x6a')]===0x5){_0x2e0676[_0xdebc('0x6b')](-0x1,0x1);}_0x2e0676['unshift'](_0x1dfee7);return encryptor[_0xdebc('0x6c')](_0x2e0676[_0xdebc('0x6d')](','));};function signJwt(_0x8a302f){var _0x1d3be3=BPromise[_0xdebc('0x6e')](jwt[_0xdebc('0x6f')],{'context':jwt});var _0x49aad2=_0x8a302f[_0xdebc('0x70')]||config[_0xdebc('0x9')][_0xdebc('0x71')];return new BPromise(function(_0x3c3bf9,_0x57f2ec){_0x1d3be3(_0x8a302f['payload'],_0x49aad2,_0x8a302f[_0xdebc('0x72')])[_0xdebc('0x30')](function(_0x396eb4){_0x3c3bf9(_0x396eb4);})[_0xdebc('0x35')](function(_0x1a2de2){_0x57f2ec(_0x1a2de2);});});}function verifyJwt(_0x99d2da,_0x3e6eaf,_0x41c703){var _0x43794d=BPromise[_0xdebc('0x6e')](jwt['verify'],{'context':jwt});var _0x13d5cb=_0x41c703||config['secrets']['session'];return new BPromise(function(_0x23332e,_0x3e35e6){_0x43794d(_0x99d2da,_0x13d5cb,_0x3e6eaf)[_0xdebc('0x30')](function(_0x4f84ce){_0x23332e(_0x4f84ce);})[_0xdebc('0x35')](function(_0x587c3a){_0x3e35e6(_0x587c3a);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0xdebc('0x73')]('hex');}function generateIssuedAt(){return Math[_0xdebc('0x74')](Date[_0xdebc('0x75')]()/0x3e8)[_0xdebc('0x73')]();}function createJwt(_0x4ee583){var _0x509321={'payload':{'iat':_0x4ee583[_0xdebc('0x5c')],'nonce':_0x4ee583[_0xdebc('0x46')]},'options':{'algorithm':'HS512','subject':_0x4ee583['id'][_0xdebc('0x73')](),'issuer':hardwareConf[_0xdebc('0x42')](),'audience':hardwareConf[_0xdebc('0x42')]()}};return signJwt(_0x509321)[_0xdebc('0x30')](function(_0x1268d9){return{'iat':_0x4ee583[_0xdebc('0x5c')],'nonce':_0x4ee583[_0xdebc('0x46')],'token':_0x1268d9};});}