9e2f4367efe01a32cb4bef0d6275bed846295a0f
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xcdd2=['smsAutoanswerDelay','openchannelAutoanswer','openchannelAutoanswerDelay','faxAutoanswerDelay','whatsappAutoanswer','whatsappAutoanswerDelay','isChatInteractionAuthorized','isAuthenticated','ChatInteraction','findOne','closed','disposition','then','query','forceDownload','status','unmanaged','json','Unmanaged.','Forbidden.','use','headers','authorization','Basic','User','find','name','authenticate','pass','Wrong\x20credentials.','startsWith','Unknown\x20authorization\x20format','apikey','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','user','catch','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','Forbidden','isWebrtcLicence','webrtc','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','generateApiKey','apiKeyNonce','apiKeyIat','getUuid','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','splice','join','promisify','secret','options','verify','randomBytes','toString','hex','floor','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','express-jwt','composable-middleware','crypto','bluebird','util','moment','secrets','session','role','internal','email','userpic','permissions','voicePause','chatPause','mailPause','smsPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','allowmessenger','alias','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarExpires','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','userProfileId','wssPort','downloadAttachments','ignorePauseForPreviewCalls','selectRecallMeCampaign','chatAutoanswerDelay','emailAutoanswer','emailAutoanswerDelay','smsAutoanswer'];(function(_0x3dd15e,_0x1f0015){var _0x231fd0=function(_0x4f680a){while(--_0x4f680a){_0x3dd15e['push'](_0x3dd15e['shift']());}};_0x231fd0(++_0x1f0015);}(_0xcdd2,0xe3));var _0x2cdd=function(_0x3dd15e,_0x1f0015){_0x3dd15e=_0x3dd15e-0x0;var _0x231fd0=_0xcdd2[_0x3dd15e];return _0x231fd0;};'use strict';var db=require(_0x2cdd('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x2cdd('0x1'));var licenseUtil=require(_0x2cdd('0x2'));var encryptor=require('../encryptor');var _=require('lodash');var jwt=require('jsonwebtoken');var expressJwt=require(_0x2cdd('0x3'));var compose=require(_0x2cdd('0x4'));var basicAuth=require('basic-auth');var crypto=require(_0x2cdd('0x5'));var BPromise=require(_0x2cdd('0x6'));var util=require(_0x2cdd('0x7'));var moment=require(_0x2cdd('0x8'));var validateJwt=expressJwt({'secret':config[_0x2cdd('0x9')][_0x2cdd('0xa')]});var userAttributes=['id',_0x2cdd('0xb'),'fullname','name',_0x2cdd('0xc'),_0x2cdd('0xd'),_0x2cdd('0xe'),_0x2cdd('0xf'),'md5secret',_0x2cdd('0x10'),_0x2cdd('0x11'),_0x2cdd('0x12'),'faxPause',_0x2cdd('0x13'),_0x2cdd('0x14'),_0x2cdd('0x15'),_0x2cdd('0x16'),_0x2cdd('0x17'),_0x2cdd('0x18'),'crudPermissions',_0x2cdd('0x19'),'passwordResetAt',_0x2cdd('0x1a'),'phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd',_0x2cdd('0x1b'),_0x2cdd('0x1c'),_0x2cdd('0x1d'),_0x2cdd('0x1e'),'phoneBarPrefixRequired',_0x2cdd('0x1f'),_0x2cdd('0x20'),_0x2cdd('0x21'),'interface',_0x2cdd('0x22'),'privacyEnabled','settingsEnabled',_0x2cdd('0x23'),'downloadVoiceRecordings','downloadOmnichannelInteractions',_0x2cdd('0x24'),_0x2cdd('0x25'),_0x2cdd('0x26'),'chatAutoanswer',_0x2cdd('0x27'),_0x2cdd('0x28'),_0x2cdd('0x29'),_0x2cdd('0x2a'),_0x2cdd('0x2b'),_0x2cdd('0x2c'),_0x2cdd('0x2d'),'faxAutoanswer',_0x2cdd('0x2e'),_0x2cdd('0x2f'),_0x2cdd('0x30'),'messengerSoundNotification'];exports[_0x2cdd('0x31')]=function(){return this[_0x2cdd('0x32')](!![])['use'](function(_0x4ed96b,_0x910709,_0x2d2045){if(_0x4ed96b['user']){_0x2d2045();}else{return db[_0x2cdd('0x33')][_0x2cdd('0x34')]({'where':{'id':_0x4ed96b['params']['id']},'attributes':['id',_0x2cdd('0x35'),_0x2cdd('0x36')],'raw':!![]})[_0x2cdd('0x37')](function(_0x51129f){if(_0x51129f&&_0x51129f[_0x2cdd('0x35')]&&!_0x4ed96b[_0x2cdd('0x38')][_0x2cdd('0x39')]){return _0x910709[_0x2cdd('0x3a')](_0x51129f[_0x2cdd('0x36')]===_0x2cdd('0x3b')?0x195:0x193)[_0x2cdd('0x3c')]({'message':_0x51129f[_0x2cdd('0x36')]===_0x2cdd('0x3b')?_0x2cdd('0x3d'):_0x2cdd('0x3e')});}else{_0x2d2045();}})['catch'](function(_0x4d11a1){_0x2d2045(_0x4d11a1);});}});};exports[_0x2cdd('0x32')]=function isAuthenticated(_0x3c5eb6){return compose()[_0x2cdd('0x3f')](function(_0x10cd3b,_0x1b5e37,_0x241266){var _0x3a9da5;if(_0x10cd3b[_0x2cdd('0x40')][_0x2cdd('0x41')]){if(_['startsWith'](_0x10cd3b[_0x2cdd('0x40')][_0x2cdd('0x41')],_0x2cdd('0x42'))){var _0x40cd15=basicAuth(_0x10cd3b);db[_0x2cdd('0x43')][_0x2cdd('0x44')]({'where':{'name':_0x40cd15[_0x2cdd('0x45')]}})[_0x2cdd('0x37')](function(_0x2ba8e7){if(!_0x2ba8e7||!_0x2ba8e7[_0x2cdd('0x46')](_0x40cd15[_0x2cdd('0x47')])){return _0x1b5e37['status'](0x191)['json']({'message':_0x2cdd('0x48')});}_0x10cd3b['user']={'id':_0x2ba8e7['id']};_0x241266();})['catch'](function(_0x9cdca7){_0x241266(_0x9cdca7);});}else if(_[_0x2cdd('0x49')](_0x10cd3b[_0x2cdd('0x40')][_0x2cdd('0x41')],'Bearer')){validateJwt(_0x10cd3b,_0x1b5e37,_0x241266);}else{if(_0x3c5eb6){_0x241266();}else{return _0x1b5e37['status'](0x193)['json']({'message':_0x2cdd('0x4a')});}}}else if(_0x10cd3b[_0x2cdd('0x38')][_0x2cdd('0x4b')]){try{var _0x1b70b0={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x10cd3b[_0x2cdd('0x38')][_0x2cdd('0x4b')],_0x1b70b0)[_0x2cdd('0x37')](function(_0x352b0a){return db[_0x2cdd('0x43')]['find']({'where':{'id':_0x352b0a[_0x2cdd('0x4c')]}})[_0x2cdd('0x37')](function(_0x13e403){_0x3a9da5=_0x13e403;return db[_0x2cdd('0x4d')][_0x2cdd('0x34')]({'where':{'id':0x1},'attributes':[_0x2cdd('0x4e'),_0x2cdd('0x4f')],'raw':!![]});})[_0x2cdd('0x37')](function(_0x455e13){if(!_0x3a9da5||!_[_0x2cdd('0x50')](_0x3a9da5['apiKeyNonce'],_0x352b0a[_0x2cdd('0x51')])){return _0x1b5e37[_0x2cdd('0x3a')](0x191)[_0x2cdd('0x3c')]({'message':_0x2cdd('0x52')});}if(_0x3a9da5[_0x2cdd('0x53')]){return _0x1b5e37[_0x2cdd('0x3a')](0x191)[_0x2cdd('0x3c')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x3a9da5['blocked']){if(_0x455e13[_0x2cdd('0x4f')]>0x0){if(moment(_0x3a9da5[_0x2cdd('0x54')])[_0x2cdd('0x55')](_0x455e13['blockDuration'],_0x2cdd('0x56'))>moment()){return _0x1b5e37[_0x2cdd('0x3a')](0x191)['json']({'message':_0x2cdd('0x57')});}}else{return _0x1b5e37[_0x2cdd('0x3a')](0x191)['json']({'message':_0x2cdd('0x57')});}}_0x10cd3b[_0x2cdd('0x58')]={'id':_0x3a9da5['id']};_0x241266();});})[_0x2cdd('0x59')](function(){return _0x1b5e37[_0x2cdd('0x3a')](0x191)[_0x2cdd('0x3c')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0xe0dfd2){_0x241266(_0xe0dfd2);}}else if(_0x3c5eb6){_0x241266();}else{return _0x1b5e37[_0x2cdd('0x3a')](0x193)[_0x2cdd('0x3c')]({'message':_0x2cdd('0x4a')});}})[_0x2cdd('0x3f')](function(_0x5075c9,_0xc9c218,_0xe9f1c5){if(_0x5075c9[_0x2cdd('0x58')]){db['User'][_0x2cdd('0x44')]({'where':{'id':_0x5075c9['user']['id']},'attributes':userAttributes})[_0x2cdd('0x37')](function(_0x32066f){if(!_0x32066f){return _0xc9c218[_0x2cdd('0x3a')](0x194)[_0x2cdd('0x3c')]({'message':_0x2cdd('0x5a')});}_0x5075c9[_0x2cdd('0x58')]=_0x32066f;_0xe9f1c5();})[_0x2cdd('0x59')](function(_0x5f4be8){_0xe9f1c5(_0x5f4be8);});}else if(_0x3c5eb6){_0xe9f1c5();}else{return _0xc9c218[_0x2cdd('0x3a')](0x194)[_0x2cdd('0x3c')]({'message':_0x2cdd('0x5b')});}});};exports[_0x2cdd('0x5c')]=function canUpdate(){return compose()[_0x2cdd('0x3f')](function(_0x338dd4,_0x2f0c86,_0x42f6fd){return licenseUtil['getLicense']()[_0x2cdd('0x37')](function(_0x34ec42){if(_0x34ec42['update']){_0x42f6fd();}else{return _0x2f0c86[_0x2cdd('0x3a')](0x193)['json']({'message':_0x2cdd('0x5d')});}})['catch'](function(_0x124648){_0x42f6fd(_0x124648);});});};exports[_0x2cdd('0x5e')]=function isWebrtcLicence(){return compose()[_0x2cdd('0x3f')](function(_0x5deff4,_0x1d9d13,_0x2edfde){return licenseUtil['getLicense']()['then'](function(_0x3fd4cf){if(_0x3fd4cf[_0x2cdd('0x5f')]){_0x2edfde();}else{return _0x1d9d13[_0x2cdd('0x3a')](0x193)['json']({'message':_0x2cdd('0x5d')});}})[_0x2cdd('0x59')](function(_0x112afd){_0x2edfde(_0x112afd);});});};exports[_0x2cdd('0x60')]=function(_0x58d041,_0x4092a7,_0x21e0f4){_0x58d041[_0x2cdd('0x60')]=!![];return _0x21e0f4();};exports[_0x2cdd('0x61')]=function signToken(_0x46d3de){return signJwt(_0x46d3de);};exports[_0x2cdd('0x62')]=function(_0x26025b,_0x302772){if(!_0x26025b[_0x2cdd('0x58')]){return _0x302772[_0x2cdd('0x3a')](0x194)[_0x2cdd('0x3c')]({'message':_0x2cdd('0x63')});}var _0xba9728={'payload':{'id':_0x26025b[_0x2cdd('0x58')]['id'],'role':_0x26025b[_0x2cdd('0x58')][_0x2cdd('0xb')]},'options':{'expiresIn':0x15180}};return signJwt(_0xba9728)[_0x2cdd('0x37')](function(_0x4c1033){_0x302772['cookie'](_0x2cdd('0x64'),_0x4c1033);_0x302772[_0x2cdd('0x65')](_0x2cdd('0x66'));})[_0x2cdd('0x59')](function(_0x5b6b41){return _0x302772['status'](0x1f4)[_0x2cdd('0x67')](_0x5b6b41);});};exports[_0x2cdd('0x68')]=function(_0x4f4eee){if(_[_0x2cdd('0x69')](_0x4f4eee['apiKeyNonce'])||_[_0x2cdd('0x69')](_0x4f4eee['apiKeyIat'])){return null;}else{return createJwt(_0x4f4eee);}};exports[_0x2cdd('0x6a')]=function(_0x23839e){_0x23839e[_0x2cdd('0x6b')]=generateNonce();_0x23839e[_0x2cdd('0x6c')]=generateIssuedAt();return createJwt(_0x23839e);};exports['regenerateApiKey']=function(_0x40a358,_0x3edb9b){var _0x3e79f8=_0x40a358['query'][_0x2cdd('0x4b')];if(_0x3e79f8){var _0x4b6c7a={'nonce':_0x3edb9b[_0x2cdd('0x6b')],'iat':_0x3edb9b[_0x2cdd('0x6c')],'audience':hardwareConf[_0x2cdd('0x6d')](),'issuer':hardwareConf[_0x2cdd('0x6d')]()};return verifyJwt(_0x3e79f8,_0x4b6c7a)[_0x2cdd('0x37')](function(){return generateApiKey(_0x3edb9b);});}else{throw{'message':_0x2cdd('0x6e')};}};exports[_0x2cdd('0x6f')]=function(_0x572371){var _0x4b9f71=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x4b9f71[_0x2cdd('0x70')](_0x572371))throw new db[(_0x2cdd('0x71'))][(_0x2cdd('0x72'))](_0x2cdd('0x73'));return;};exports['validatePasswordHistory']=function(_0x4d4a50,_0x17f556,_0xcc63e6){var _0xeab301=encryptor[_0x2cdd('0x74')](_0x17f556)[_0x2cdd('0x75')](',');for(var _0x268a86=0x0;_0x268a86<_0xcc63e6;_0x268a86++){if(!_0xeab301[_0x268a86])break;if(_0x4d4a50[_0x2cdd('0x76')]()===_0xeab301[_0x268a86][_0x2cdd('0x76')]()){var _0x3903b2=util[_0x2cdd('0x77')](_0x2cdd('0x78'),_0xcc63e6);if(_0xcc63e6===0x1){_0x3903b2=_0x2cdd('0x79');}throw new db['Sequelize'][(_0x2cdd('0x72'))](_0x3903b2);}}return;};exports[_0x2cdd('0x7a')]=function(_0x482c36,_0x336497){var _0x160462=_0x336497?encryptor[_0x2cdd('0x74')](_0x336497)[_0x2cdd('0x75')](','):[];if(_0x160462[_0x2cdd('0x7b')]===0x5){_0x160462[_0x2cdd('0x7c')](-0x1,0x1);}_0x160462['unshift'](_0x482c36);return encryptor['encryptString'](_0x160462[_0x2cdd('0x7d')](','));};function signJwt(_0x4023a9){var _0x297470=BPromise[_0x2cdd('0x7e')](jwt['sign'],{'context':jwt});var _0x3ff1bb=_0x4023a9[_0x2cdd('0x7f')]||config[_0x2cdd('0x9')][_0x2cdd('0xa')];return new BPromise(function(_0x1ad5b2,_0x27934a){_0x297470(_0x4023a9['payload'],_0x3ff1bb,_0x4023a9[_0x2cdd('0x80')])['then'](function(_0x5a5712){_0x1ad5b2(_0x5a5712);})[_0x2cdd('0x59')](function(_0x2ed284){_0x27934a(_0x2ed284);});});}function verifyJwt(_0x54f9f6,_0x3486ba,_0x23196d){var _0x34fade=BPromise[_0x2cdd('0x7e')](jwt[_0x2cdd('0x81')],{'context':jwt});var _0x461f63=_0x23196d||config[_0x2cdd('0x9')][_0x2cdd('0xa')];return new BPromise(function(_0x1bf7fb,_0x19f7e4){_0x34fade(_0x54f9f6,_0x461f63,_0x3486ba)[_0x2cdd('0x37')](function(_0x3b1eda){_0x1bf7fb(_0x3b1eda);})[_0x2cdd('0x59')](function(_0x4a5ed1){_0x19f7e4(_0x4a5ed1);});});}function generateNonce(){return crypto[_0x2cdd('0x82')](0x10)[_0x2cdd('0x83')](_0x2cdd('0x84'));}function generateIssuedAt(){return Math[_0x2cdd('0x85')](Date['now']()/0x3e8)['toString']();}function createJwt(_0x1181b9){var _0x26c49f={'payload':{'iat':_0x1181b9[_0x2cdd('0x6c')],'nonce':_0x1181b9[_0x2cdd('0x6b')]},'options':{'algorithm':_0x2cdd('0x86'),'subject':_0x1181b9['id']['toString'](),'issuer':hardwareConf[_0x2cdd('0x6d')](),'audience':hardwareConf['getUuid']()}};return signJwt(_0x26c49f)[_0x2cdd('0x37')](function(_0x3faaaa){return{'iat':_0x1181b9[_0x2cdd('0x6c')],'nonce':_0x1181b9['apiKeyNonce'],'token':_0x3faaaa};});}