aed79c23047e3dbd12d6dccbc18a2d003ea548e0
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x8b5c=['find','pass','status','Wrong\x20credentials.','startsWith','Bearer','json','apikey','getUuid','query','then','sub','Setting','blockDuration','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockedAt','minutes','Invalid\x20API\x20access\x20key','Unknown\x20authorization\x20format','User','User\x20not\x20found.','User\x20object\x20not\x20found.','canUpdate','getLicense','update','Forbidden','isMiddleware','signToken','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','apiKeyNonce','apiKeyIat','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','ValidationError','updatePasswordsHistory','split','length','splice','unshift','encryptString','join','promisify','sign','secret','payload','options','verify','session','toString','floor','now','HS512','../../mysqldb','../../config/license/hardware','lodash','jsonwebtoken','composable-middleware','basic-auth','crypto','bluebird','moment','secrets','fullname','name','internal','email','userpic','md5secret','voicePause','mailPause','faxPause','smsPause','pauseType','lastPauseAt','crudPermissions','allowmessenger','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','Unmanaged.','Forbidden.','catch','headers','authorization','Basic'];(function(_0x1601e4,_0x19f1c4){var _0x162f87=function(_0x32d68e){while(--_0x32d68e){_0x1601e4['push'](_0x1601e4['shift']());}};_0x162f87(++_0x19f1c4);}(_0x8b5c,0xc0));var _0xc8b5=function(_0x22363e,_0x2c66c6){_0x22363e=_0x22363e-0x0;var _0x31e9e8=_0x8b5c[_0x22363e];return _0x31e9e8;};'use strict';var db=require(_0xc8b5('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0xc8b5('0x1'));var licenseUtil=require('../../config/license/util');var encryptor=require('../encryptor');var _=require(_0xc8b5('0x2'));var jwt=require(_0xc8b5('0x3'));var expressJwt=require('express-jwt');var compose=require(_0xc8b5('0x4'));var basicAuth=require(_0xc8b5('0x5'));var crypto=require(_0xc8b5('0x6'));var BPromise=require(_0xc8b5('0x7'));var util=require('util');var moment=require(_0xc8b5('0x8'));var validateJwt=expressJwt({'secret':config[_0xc8b5('0x9')]['session']});var userAttributes=['id','role',_0xc8b5('0xa'),_0xc8b5('0xb'),_0xc8b5('0xc'),_0xc8b5('0xd'),_0xc8b5('0xe'),'permissions',_0xc8b5('0xf'),_0xc8b5('0x10'),'chatPause',_0xc8b5('0x11'),_0xc8b5('0x12'),_0xc8b5('0x13'),'openchannelPause',_0xc8b5('0x14'),'showWebBar','lastLoginAt',_0xc8b5('0x15'),_0xc8b5('0x16'),_0xc8b5('0x17'),'passwordResetAt',_0xc8b5('0x18'),_0xc8b5('0x19'),_0xc8b5('0x1a'),_0xc8b5('0x1b'),_0xc8b5('0x1c'),_0xc8b5('0x1d'),'phoneBarEnableSettings',_0xc8b5('0x1e'),_0xc8b5('0x1f'),_0xc8b5('0x20'),_0xc8b5('0x21'),_0xc8b5('0x22'),_0xc8b5('0x23'),'userProfileId','settingsEnabled'];exports['isChatInteractionAuthorized']=function(){return this[_0xc8b5('0x24')](!![])[_0xc8b5('0x25')](function(_0x24b50f,_0x1dc00c,_0x129716){if(_0x24b50f[_0xc8b5('0x26')]){_0x129716();}else{return db[_0xc8b5('0x27')][_0xc8b5('0x28')]({'where':{'id':_0x24b50f[_0xc8b5('0x29')]['id']},'attributes':['id',_0xc8b5('0x2a'),_0xc8b5('0x2b')],'raw':!![]})['then'](function(_0x1bb408){if(_0x1bb408&&_0x1bb408['closed']){return _0x1dc00c['status'](_0x1bb408[_0xc8b5('0x2b')]==='unmanaged'?0x195:0x193)['json']({'message':_0x1bb408['disposition']==='unmanaged'?_0xc8b5('0x2c'):_0xc8b5('0x2d')});}else{_0x129716();}})[_0xc8b5('0x2e')](function(_0x28f37a){_0x129716(_0x28f37a);});}});};exports[_0xc8b5('0x24')]=function isAuthenticated(_0x31d2fc){return compose()[_0xc8b5('0x25')](function(_0x235fe8,_0x5b532a,_0x473018){var _0x5562de;if(_0x235fe8[_0xc8b5('0x2f')][_0xc8b5('0x30')]){if(_['startsWith'](_0x235fe8[_0xc8b5('0x2f')][_0xc8b5('0x30')],_0xc8b5('0x31'))){var _0x3c37d8=basicAuth(_0x235fe8);db['User'][_0xc8b5('0x32')]({'where':{'name':_0x3c37d8[_0xc8b5('0xb')]}})['then'](function(_0x37971d){if(!_0x37971d||!_0x37971d['authenticate'](_0x3c37d8[_0xc8b5('0x33')])){return _0x5b532a[_0xc8b5('0x34')](0x191)['json']({'message':_0xc8b5('0x35')});}_0x235fe8[_0xc8b5('0x26')]={'id':_0x37971d['id']};_0x473018();})[_0xc8b5('0x2e')](function(_0x11a06c){_0x473018(_0x11a06c);});}else if(_[_0xc8b5('0x36')](_0x235fe8[_0xc8b5('0x2f')]['authorization'],_0xc8b5('0x37'))){validateJwt(_0x235fe8,_0x5b532a,_0x473018);}else{if(_0x31d2fc){_0x473018();}else{return _0x5b532a['status'](0x193)[_0xc8b5('0x38')]({'message':'Unknown\x20authorization\x20format'});}}}else if(_0x235fe8['query'][_0xc8b5('0x39')]){try{var _0x53b10b={'audience':hardwareConf[_0xc8b5('0x3a')](),'issuer':hardwareConf[_0xc8b5('0x3a')]()};verifyJwt(_0x235fe8[_0xc8b5('0x3b')][_0xc8b5('0x39')],_0x53b10b)[_0xc8b5('0x3c')](function(_0x295f00){return db['User'][_0xc8b5('0x32')]({'where':{'id':_0x295f00[_0xc8b5('0x3d')]}})[_0xc8b5('0x3c')](function(_0x1e09c3){_0x5562de=_0x1e09c3;return db[_0xc8b5('0x3e')][_0xc8b5('0x28')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts',_0xc8b5('0x3f')],'raw':!![]});})[_0xc8b5('0x3c')](function(_0x553502){if(!_0x5562de||!_['isEqual'](_0x5562de['apiKeyNonce'],_0x295f00[_0xc8b5('0x40')])){return _0x5b532a[_0xc8b5('0x34')](0x191)[_0xc8b5('0x38')]({'message':_0xc8b5('0x41')});}if(_0x5562de[_0xc8b5('0x42')]){return _0x5b532a[_0xc8b5('0x34')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}if(_0x5562de[_0xc8b5('0x43')]){if(_0x553502[_0xc8b5('0x3f')]>0x0){if(moment(_0x5562de[_0xc8b5('0x44')])['add'](_0x553502[_0xc8b5('0x3f')],_0xc8b5('0x45'))>moment()){return _0x5b532a[_0xc8b5('0x34')](0x191)[_0xc8b5('0x38')]({'message':_0xc8b5('0x46')});}}else{return _0x5b532a[_0xc8b5('0x34')](0x191)[_0xc8b5('0x38')]({'message':_0xc8b5('0x46')});}}_0x235fe8['user']={'id':_0x5562de['id']};_0x473018();});})[_0xc8b5('0x2e')](function(){return _0x5b532a[_0xc8b5('0x34')](0x191)[_0xc8b5('0x38')]({'message':_0xc8b5('0x46')});});}catch(_0x281a1c){_0x473018(_0x281a1c);}}else if(_0x31d2fc){_0x473018();}else{return _0x5b532a[_0xc8b5('0x34')](0x193)[_0xc8b5('0x38')]({'message':_0xc8b5('0x47')});}})[_0xc8b5('0x25')](function(_0x4816cf,_0x27edbd,_0x4b2cba){if(_0x4816cf[_0xc8b5('0x26')]){db[_0xc8b5('0x48')]['find']({'where':{'id':_0x4816cf[_0xc8b5('0x26')]['id']},'attributes':userAttributes})[_0xc8b5('0x3c')](function(_0x237e9d){if(!_0x237e9d){return _0x27edbd[_0xc8b5('0x34')](0x194)[_0xc8b5('0x38')]({'message':_0xc8b5('0x49')});}_0x4816cf[_0xc8b5('0x26')]=_0x237e9d;_0x4b2cba();})['catch'](function(_0x5769c9){_0x4b2cba(_0x5769c9);});}else if(_0x31d2fc){_0x4b2cba();}else{return _0x27edbd[_0xc8b5('0x34')](0x194)[_0xc8b5('0x38')]({'message':_0xc8b5('0x4a')});}});};exports[_0xc8b5('0x4b')]=function canUpdate(){return compose()['use'](function(_0xe864d9,_0x15e94f,_0x344347){return licenseUtil[_0xc8b5('0x4c')]()[_0xc8b5('0x3c')](function(_0x263fb6){if(_0x263fb6[_0xc8b5('0x4d')]){_0x344347();}else{return _0x15e94f['status'](0x193)[_0xc8b5('0x38')]({'message':_0xc8b5('0x4e')});}})[_0xc8b5('0x2e')](function(_0x35a02c){_0x344347(_0x35a02c);});});};exports['isMiddleware']=function(_0x361819,_0x21632a,_0x54b0c3){_0x361819[_0xc8b5('0x4f')]=!![];return _0x54b0c3();};exports[_0xc8b5('0x50')]=function signToken(_0x3c9deb){return signJwt(_0x3c9deb);};exports['setTokenCookie']=function(_0x17234b,_0x17c937){if(!_0x17234b[_0xc8b5('0x26')]){return _0x17c937[_0xc8b5('0x34')](0x194)[_0xc8b5('0x38')]({'message':_0xc8b5('0x51')});}var _0x51c308={'payload':{'id':_0x17234b[_0xc8b5('0x26')]['id'],'role':_0x17234b[_0xc8b5('0x26')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x51c308)[_0xc8b5('0x3c')](function(_0x5e0dd1){_0x17c937[_0xc8b5('0x52')](_0xc8b5('0x53'),_0x5e0dd1);_0x17c937[_0xc8b5('0x54')](_0xc8b5('0x55'));})[_0xc8b5('0x2e')](function(_0x86db76){return _0x17c937[_0xc8b5('0x34')](0x1f4)[_0xc8b5('0x56')](_0x86db76);});};exports[_0xc8b5('0x57')]=function(_0x5d3e25){if(_['isNil'](_0x5d3e25[_0xc8b5('0x58')])||_['isNil'](_0x5d3e25[_0xc8b5('0x59')])){return null;}else{return createJwt(_0x5d3e25);}};exports[_0xc8b5('0x5a')]=function(_0x25ab7c){_0x25ab7c[_0xc8b5('0x58')]=generateNonce();_0x25ab7c['apiKeyIat']=generateIssuedAt();return createJwt(_0x25ab7c);};exports[_0xc8b5('0x5b')]=function(_0x43f059,_0x183a38){var _0x468c1f=_0x43f059[_0xc8b5('0x3b')][_0xc8b5('0x39')];if(_0x468c1f){var _0x5cbd80={'nonce':_0x183a38[_0xc8b5('0x58')],'iat':_0x183a38[_0xc8b5('0x59')],'audience':hardwareConf[_0xc8b5('0x3a')](),'issuer':hardwareConf[_0xc8b5('0x3a')]()};return verifyJwt(_0x468c1f,_0x5cbd80)['then'](function(){return generateApiKey(_0x183a38);});}else{throw{'message':_0xc8b5('0x5c')};}};exports['validatePasswordPattern']=function(_0x3dda48){var _0x4bca56=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x4bca56[_0xc8b5('0x5d')](_0x3dda48))throw new db[(_0xc8b5('0x5e'))]['ValidationError'](_0xc8b5('0x5f'));return;};exports[_0xc8b5('0x60')]=function(_0x57d82b,_0x11c96f,_0x2c54cc){var _0x173f9c=encryptor[_0xc8b5('0x61')](_0x11c96f)['split'](',');for(var _0x155589=0x0;_0x155589<_0x2c54cc;_0x155589++){if(!_0x173f9c[_0x155589])break;if(_0x57d82b['toLowerCase']()===_0x173f9c[_0x155589][_0xc8b5('0x62')]()){var _0x375b9d=util[_0xc8b5('0x63')](_0xc8b5('0x64'),_0x2c54cc);if(_0x2c54cc===0x1){_0x375b9d=_0xc8b5('0x65');}throw new db['Sequelize'][(_0xc8b5('0x66'))](_0x375b9d);}}return;};exports[_0xc8b5('0x67')]=function(_0x3607e7,_0x35f4be){var _0x236ea5=_0x35f4be?encryptor[_0xc8b5('0x61')](_0x35f4be)[_0xc8b5('0x68')](','):[];if(_0x236ea5[_0xc8b5('0x69')]===0x5){_0x236ea5[_0xc8b5('0x6a')](-0x1,0x1);}_0x236ea5[_0xc8b5('0x6b')](_0x3607e7);return encryptor[_0xc8b5('0x6c')](_0x236ea5[_0xc8b5('0x6d')](','));};function signJwt(_0x486869){var _0x57fc35=BPromise[_0xc8b5('0x6e')](jwt[_0xc8b5('0x6f')],{'context':jwt});var _0x1332f1=_0x486869[_0xc8b5('0x70')]||config['secrets']['session'];return new BPromise(function(_0x2beb8e,_0x2c2d32){_0x57fc35(_0x486869[_0xc8b5('0x71')],_0x1332f1,_0x486869[_0xc8b5('0x72')])['then'](function(_0x119697){_0x2beb8e(_0x119697);})[_0xc8b5('0x2e')](function(_0x4e1171){_0x2c2d32(_0x4e1171);});});}function verifyJwt(_0x238a58,_0xad1061,_0x3eccbd){var _0x3bc64f=BPromise[_0xc8b5('0x6e')](jwt[_0xc8b5('0x73')],{'context':jwt});var _0x5ec81c=_0x3eccbd||config[_0xc8b5('0x9')][_0xc8b5('0x74')];return new BPromise(function(_0x33a776,_0x238be3){_0x3bc64f(_0x238a58,_0x5ec81c,_0xad1061)[_0xc8b5('0x3c')](function(_0x4b9b7b){_0x33a776(_0x4b9b7b);})[_0xc8b5('0x2e')](function(_0x4f531b){_0x238be3(_0x4f531b);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0xc8b5('0x75')]('hex');}function generateIssuedAt(){return Math[_0xc8b5('0x76')](Date[_0xc8b5('0x77')]()/0x3e8)['toString']();}function createJwt(_0x1ccfd1){var _0x1a7408={'payload':{'iat':_0x1ccfd1[_0xc8b5('0x59')],'nonce':_0x1ccfd1[_0xc8b5('0x58')]},'options':{'algorithm':_0xc8b5('0x78'),'subject':_0x1ccfd1['id']['toString'](),'issuer':hardwareConf[_0xc8b5('0x3a')](),'audience':hardwareConf[_0xc8b5('0x3a')]()}};return signJwt(_0x1a7408)[_0xc8b5('0x3c')](function(_0x254acf){return{'iat':_0x1ccfd1['apiKeyIat'],'nonce':_0x1ccfd1['apiKeyNonce'],'token':_0x254acf};});}