a357e019e0022b3850c928125fb769dff6ab38d3
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xa61f=['format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','split','length','join','promisify','sign','secret','options','randomBytes','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','secrets','session','fullname','name','internal','email','userpic','permissions','md5secret','voicePause','mailPause','smsPause','pauseType','lastLoginAt','lastPauseAt','allowmessenger','passwordResetAt','alias','phoneBarEnableSettings','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','user','ChatInteraction','findOne','params','disposition','status','unmanaged','Forbidden.','headers','authorization','startsWith','Basic','authenticate','json','Wrong\x20credentials.','catch','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','User','find','sub','then','Setting','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','blockedAt','minutes','use','User\x20object\x20not\x20found.','canUpdate','getLicense','update','Forbidden','isMiddleware','signToken','setTokenCookie','cookie','redirect','/dashboards/general','send','retrieveApiKey','isNil','generateApiKey','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','toLowerCase'];(function(_0x58dc25,_0x49b9d5){var _0x21b0a7=function(_0x38a186){while(--_0x38a186){_0x58dc25['push'](_0x58dc25['shift']());}};_0x21b0a7(++_0x49b9d5);}(_0xa61f,0x1d5));var _0xfa61=function(_0x8c43de,_0x90ff31){_0x8c43de=_0x8c43de-0x0;var _0xa6591b=_0xa61f[_0x8c43de];return _0xa6591b;};'use strict';var db=require(_0xfa61('0x0'))['db'];var config=require(_0xfa61('0x1'));var hardwareConf=require(_0xfa61('0x2'));var licenseUtil=require(_0xfa61('0x3'));var encryptor=require('../encryptor');var _=require(_0xfa61('0x4'));var jwt=require(_0xfa61('0x5'));var expressJwt=require(_0xfa61('0x6'));var compose=require(_0xfa61('0x7'));var basicAuth=require(_0xfa61('0x8'));var crypto=require(_0xfa61('0x9'));var BPromise=require('bluebird');var util=require('util');var moment=require('moment');var validateJwt=expressJwt({'secret':config[_0xfa61('0xa')][_0xfa61('0xb')]});var userAttributes=['id','role',_0xfa61('0xc'),_0xfa61('0xd'),_0xfa61('0xe'),_0xfa61('0xf'),_0xfa61('0x10'),_0xfa61('0x11'),_0xfa61('0x12'),_0xfa61('0x13'),'chatPause',_0xfa61('0x14'),'faxPause',_0xfa61('0x15'),'openchannelPause',_0xfa61('0x16'),'showWebBar',_0xfa61('0x17'),_0xfa61('0x18'),'crudPermissions',_0xfa61('0x19'),_0xfa61('0x1a'),_0xfa61('0x1b'),'phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone',_0xfa61('0x1c'),'phoneBarExpires','phoneBarPrefixRequired',_0xfa61('0x1d'),_0xfa61('0x1e'),_0xfa61('0x1f'),_0xfa61('0x20'),'userProfileId',_0xfa61('0x21')];exports[_0xfa61('0x22')]=function(){return this[_0xfa61('0x23')](!![])['use'](function(_0x5cb578,_0x5ae5a8,_0x2806e2){if(_0x5cb578[_0xfa61('0x24')]){_0x2806e2();}else{return db[_0xfa61('0x25')][_0xfa61('0x26')]({'where':{'id':_0x5cb578[_0xfa61('0x27')]['id']},'attributes':['id','closed',_0xfa61('0x28')],'raw':!![]})['then'](function(_0x3978d4){if(_0x3978d4&&_0x3978d4['closed']){return _0x5ae5a8[_0xfa61('0x29')](_0x3978d4[_0xfa61('0x28')]===_0xfa61('0x2a')?0x195:0x193)['json']({'message':_0x3978d4[_0xfa61('0x28')]===_0xfa61('0x2a')?'Unmanaged.':_0xfa61('0x2b')});}else{_0x2806e2();}})['catch'](function(_0x3e6f24){_0x2806e2(_0x3e6f24);});}});};exports[_0xfa61('0x23')]=function isAuthenticated(_0x2563a0){return compose()['use'](function(_0x5d5f1a,_0x3c0d77,_0xcb6b15){var _0x56584f;if(_0x5d5f1a[_0xfa61('0x2c')][_0xfa61('0x2d')]){if(_[_0xfa61('0x2e')](_0x5d5f1a[_0xfa61('0x2c')][_0xfa61('0x2d')],_0xfa61('0x2f'))){var _0x131132=basicAuth(_0x5d5f1a);db['User']['find']({'where':{'name':_0x131132[_0xfa61('0xd')]}})['then'](function(_0x13909e){if(!_0x13909e||!_0x13909e[_0xfa61('0x30')](_0x131132['pass'])){return _0x3c0d77['status'](0x191)[_0xfa61('0x31')]({'message':_0xfa61('0x32')});}_0x5d5f1a[_0xfa61('0x24')]={'id':_0x13909e['id']};_0xcb6b15();})[_0xfa61('0x33')](function(_0x25e29f){_0xcb6b15(_0x25e29f);});}else if(_[_0xfa61('0x2e')](_0x5d5f1a['headers']['authorization'],_0xfa61('0x34'))){validateJwt(_0x5d5f1a,_0x3c0d77,_0xcb6b15);}else{if(_0x2563a0){_0xcb6b15();}else{return _0x3c0d77[_0xfa61('0x29')](0x193)[_0xfa61('0x31')]({'message':_0xfa61('0x35')});}}}else if(_0x5d5f1a[_0xfa61('0x36')]['apikey']){try{var _0x123157={'audience':hardwareConf[_0xfa61('0x37')](),'issuer':hardwareConf[_0xfa61('0x37')]()};verifyJwt(_0x5d5f1a['query'][_0xfa61('0x38')],_0x123157)['then'](function(_0x305636){return db[_0xfa61('0x39')][_0xfa61('0x3a')]({'where':{'id':_0x305636[_0xfa61('0x3b')]}})[_0xfa61('0x3c')](function(_0x30fe0d){_0x56584f=_0x30fe0d;return db[_0xfa61('0x3d')][_0xfa61('0x26')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts',_0xfa61('0x3e')],'raw':!![]});})['then'](function(_0x3ab4a7){if(!_0x56584f||!_[_0xfa61('0x3f')](_0x56584f[_0xfa61('0x40')],_0x305636[_0xfa61('0x41')])){return _0x3c0d77[_0xfa61('0x29')](0x191)[_0xfa61('0x31')]({'message':_0xfa61('0x42')});}if(_0x56584f['disabled']){return _0x3c0d77[_0xfa61('0x29')](0x191)['json']({'message':_0xfa61('0x43')});}if(_0x56584f['blocked']){if(_0x3ab4a7[_0xfa61('0x3e')]>0x0){if(moment(_0x56584f[_0xfa61('0x44')])['add'](_0x3ab4a7[_0xfa61('0x3e')],_0xfa61('0x45'))>moment()){return _0x3c0d77[_0xfa61('0x29')](0x191)[_0xfa61('0x31')]({'message':'Invalid\x20API\x20access\x20key'});}}else{return _0x3c0d77[_0xfa61('0x29')](0x191)[_0xfa61('0x31')]({'message':'Invalid\x20API\x20access\x20key'});}}_0x5d5f1a[_0xfa61('0x24')]={'id':_0x56584f['id']};_0xcb6b15();});})['catch'](function(){return _0x3c0d77[_0xfa61('0x29')](0x191)[_0xfa61('0x31')]({'message':_0xfa61('0x43')});});}catch(_0x22a039){_0xcb6b15(_0x22a039);}}else if(_0x2563a0){_0xcb6b15();}else{return _0x3c0d77[_0xfa61('0x29')](0x193)[_0xfa61('0x31')]({'message':'Unknown\x20authorization\x20format'});}})[_0xfa61('0x46')](function(_0x3c9178,_0x2052c5,_0x21b5e9){if(_0x3c9178['user']){db[_0xfa61('0x39')][_0xfa61('0x3a')]({'where':{'id':_0x3c9178[_0xfa61('0x24')]['id']},'attributes':userAttributes})[_0xfa61('0x3c')](function(_0x3e43a3){if(!_0x3e43a3){return _0x2052c5[_0xfa61('0x29')](0x194)['json']({'message':'User\x20not\x20found.'});}_0x3c9178[_0xfa61('0x24')]=_0x3e43a3;_0x21b5e9();})['catch'](function(_0x1d30fd){_0x21b5e9(_0x1d30fd);});}else if(_0x2563a0){_0x21b5e9();}else{return _0x2052c5[_0xfa61('0x29')](0x194)[_0xfa61('0x31')]({'message':_0xfa61('0x47')});}});};exports[_0xfa61('0x48')]=function canUpdate(){return compose()[_0xfa61('0x46')](function(_0x46a93d,_0x70492,_0x26538f){return licenseUtil[_0xfa61('0x49')]()[_0xfa61('0x3c')](function(_0x486a8b){if(_0x486a8b[_0xfa61('0x4a')]){_0x26538f();}else{return _0x70492[_0xfa61('0x29')](0x193)[_0xfa61('0x31')]({'message':_0xfa61('0x4b')});}})['catch'](function(_0x5b30f4){_0x26538f(_0x5b30f4);});});};exports[_0xfa61('0x4c')]=function(_0x585f70,_0xf1cf59,_0x5921c6){_0x585f70[_0xfa61('0x4c')]=!![];return _0x5921c6();};exports[_0xfa61('0x4d')]=function signToken(_0x49ddb7){return signJwt(_0x49ddb7);};exports[_0xfa61('0x4e')]=function(_0x3c5f6a,_0x515dae){if(!_0x3c5f6a[_0xfa61('0x24')]){return _0x515dae[_0xfa61('0x29')](0x194)['json']({'message':'It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.'});}var _0x463c64={'payload':{'id':_0x3c5f6a['user']['id'],'role':_0x3c5f6a[_0xfa61('0x24')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x463c64)[_0xfa61('0x3c')](function(_0x3dd9b0){_0x515dae[_0xfa61('0x4f')]('motion.token',_0x3dd9b0);_0x515dae[_0xfa61('0x50')](_0xfa61('0x51'));})[_0xfa61('0x33')](function(_0xfc7d8b){return _0x515dae[_0xfa61('0x29')](0x1f4)[_0xfa61('0x52')](_0xfc7d8b);});};exports[_0xfa61('0x53')]=function(_0x289dbf){if(_[_0xfa61('0x54')](_0x289dbf['apiKeyNonce'])||_['isNil'](_0x289dbf['apiKeyIat'])){return null;}else{return createJwt(_0x289dbf);}};exports[_0xfa61('0x55')]=function(_0x202bf8){_0x202bf8[_0xfa61('0x40')]=generateNonce();_0x202bf8[_0xfa61('0x56')]=generateIssuedAt();return createJwt(_0x202bf8);};exports[_0xfa61('0x57')]=function(_0x4df9b1,_0x17009c){var _0x4facd4=_0x4df9b1[_0xfa61('0x36')]['apikey'];if(_0x4facd4){var _0x4cc2e3={'nonce':_0x17009c[_0xfa61('0x40')],'iat':_0x17009c[_0xfa61('0x56')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0xfa61('0x37')]()};return verifyJwt(_0x4facd4,_0x4cc2e3)['then'](function(){return generateApiKey(_0x17009c);});}else{throw{'message':_0xfa61('0x58')};}};exports['validatePasswordPattern']=function(_0x2e0cf9){var _0x20bbaa=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x20bbaa[_0xfa61('0x59')](_0x2e0cf9))throw new db[(_0xfa61('0x5a'))][(_0xfa61('0x5b'))](_0xfa61('0x5c'));return;};exports[_0xfa61('0x5d')]=function(_0x3e84a5,_0x5cf5d7,_0x388d0f){var _0x2125fd=encryptor[_0xfa61('0x5e')](_0x5cf5d7)['split'](',');for(var _0x5885f4=0x0;_0x5885f4<_0x388d0f;_0x5885f4++){if(!_0x2125fd[_0x5885f4])break;if(_0x3e84a5['toLowerCase']()===_0x2125fd[_0x5885f4][_0xfa61('0x5f')]()){var _0x260136=util[_0xfa61('0x60')](_0xfa61('0x61'),_0x388d0f);if(_0x388d0f===0x1){_0x260136=_0xfa61('0x62');}throw new db['Sequelize'][(_0xfa61('0x5b'))](_0x260136);}}return;};exports[_0xfa61('0x63')]=function(_0x4f78e3,_0x3eb0c7){var _0x40bb6c=_0x3eb0c7?encryptor[_0xfa61('0x5e')](_0x3eb0c7)[_0xfa61('0x64')](','):[];if(_0x40bb6c[_0xfa61('0x65')]===0x5){_0x40bb6c['splice'](-0x1,0x1);}_0x40bb6c['unshift'](_0x4f78e3);return encryptor['encryptString'](_0x40bb6c[_0xfa61('0x66')](','));};function signJwt(_0x4fa273){var _0x2eb38d=BPromise[_0xfa61('0x67')](jwt[_0xfa61('0x68')],{'context':jwt});var _0x4735f3=_0x4fa273[_0xfa61('0x69')]||config[_0xfa61('0xa')][_0xfa61('0xb')];return new BPromise(function(_0x531ece,_0x4c26d3){_0x2eb38d(_0x4fa273['payload'],_0x4735f3,_0x4fa273[_0xfa61('0x6a')])['then'](function(_0x2fea98){_0x531ece(_0x2fea98);})[_0xfa61('0x33')](function(_0x1c95dd){_0x4c26d3(_0x1c95dd);});});}function verifyJwt(_0x47bbb6,_0x1a1bd0,_0x3a87a0){var _0x4f0fc7=BPromise[_0xfa61('0x67')](jwt['verify'],{'context':jwt});var _0x58b9da=_0x3a87a0||config[_0xfa61('0xa')][_0xfa61('0xb')];return new BPromise(function(_0x17fc74,_0x4017d7){_0x4f0fc7(_0x47bbb6,_0x58b9da,_0x1a1bd0)[_0xfa61('0x3c')](function(_0x4505b4){_0x17fc74(_0x4505b4);})[_0xfa61('0x33')](function(_0x472d80){_0x4017d7(_0x472d80);});});}function generateNonce(){return crypto[_0xfa61('0x6b')](0x10)[_0xfa61('0x6c')](_0xfa61('0x6d'));}function generateIssuedAt(){return Math[_0xfa61('0x6e')](Date[_0xfa61('0x6f')]()/0x3e8)[_0xfa61('0x6c')]();}function createJwt(_0x34aac4){var _0x473175={'payload':{'iat':_0x34aac4['apiKeyIat'],'nonce':_0x34aac4['apiKeyNonce']},'options':{'algorithm':_0xfa61('0x70'),'subject':_0x34aac4['id'][_0xfa61('0x6c')](),'issuer':hardwareConf[_0xfa61('0x37')](),'audience':hardwareConf[_0xfa61('0x37')]()}};return signJwt(_0x473175)[_0xfa61('0x3c')](function(_0x34ce22){return{'iat':_0x34aac4[_0xfa61('0x56')],'nonce':_0x34aac4[_0xfa61('0x40')],'token':_0x34ce22};});}