Built motion from commit c116dc8b.|2.6.30
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x27e0=['canUpdate','getLicense','update','Forbidden','isWebrtcLicence','webrtc','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','/dashboards/general','isNil','apiKeyIat','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','ValidationError','updatePasswordsHistory','length','splice','unshift','encryptString','promisify','sign','secret','secrets','session','payload','options','verify','toString','hex','floor','now','HS512','../../mysqldb','../../config/environment','../../config/license/hardware','../../config/license/util','../encryptor','lodash','express-jwt','composable-middleware','basic-auth','crypto','moment','role','name','internal','email','userpic','md5secret','voicePause','mailPause','faxPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','passwordResetAt','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','userProfileId','privacyEnabled','settingsEnabled','wssPort','downloadAttachments','ignorePauseForPreviewCalls','chatAutoanswerDelay','emailAutoanswer','emailAutoanswerDelay','smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer','faxAutoanswer','faxAutoanswerDelay','whatsappAutoanswerDelay','messengerSoundNotification','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','then','query','forceDownload','status','unmanaged','json','Unmanaged.','Forbidden.','authorization','startsWith','Basic','User','find','authenticate','Wrong\x20credentials.','catch','headers','Bearer','Unknown\x20authorization\x20format','apikey','getUuid','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','Invalid\x20API\x20access\x20key','blockedAt','minutes','User\x20not\x20found.','User\x20object\x20not\x20found.'];(function(_0x592df4,_0x4e719b){var _0x3b4fe4=function(_0x5ebf53){while(--_0x5ebf53){_0x592df4['push'](_0x592df4['shift']());}};_0x3b4fe4(++_0x4e719b);}(_0x27e0,0x1cd));var _0x027e=function(_0x3a05e6,_0x4a20d0){_0x3a05e6=_0x3a05e6-0x0;var _0x169b5d=_0x27e0[_0x3a05e6];return _0x169b5d;};'use strict';var db=require(_0x027e('0x0'))['db'];var config=require(_0x027e('0x1'));var hardwareConf=require(_0x027e('0x2'));var licenseUtil=require(_0x027e('0x3'));var encryptor=require(_0x027e('0x4'));var _=require(_0x027e('0x5'));var jwt=require('jsonwebtoken');var expressJwt=require(_0x027e('0x6'));var compose=require(_0x027e('0x7'));var basicAuth=require(_0x027e('0x8'));var crypto=require(_0x027e('0x9'));var BPromise=require('bluebird');var util=require('util');var moment=require(_0x027e('0xa'));var validateJwt=expressJwt({'secret':config['secrets']['session']});var userAttributes=['id',_0x027e('0xb'),'fullname',_0x027e('0xc'),_0x027e('0xd'),_0x027e('0xe'),_0x027e('0xf'),'permissions',_0x027e('0x10'),_0x027e('0x11'),'chatPause',_0x027e('0x12'),_0x027e('0x13'),'smsPause',_0x027e('0x14'),_0x027e('0x15'),_0x027e('0x16'),_0x027e('0x17'),_0x027e('0x18'),'crudPermissions','allowmessenger',_0x027e('0x19'),_0x027e('0x1a'),_0x027e('0x1b'),_0x027e('0x1c'),'phoneBarDnd',_0x027e('0x1d'),'phoneBarEnableDtmfTone',_0x027e('0x1e'),_0x027e('0x1f'),_0x027e('0x20'),_0x027e('0x21'),_0x027e('0x22'),_0x027e('0x23'),'interface',_0x027e('0x24'),_0x027e('0x25'),_0x027e('0x26'),_0x027e('0x27'),'downloadVoiceRecordings','downloadOmnichannelInteractions',_0x027e('0x28'),_0x027e('0x29'),'selectRecallMeCampaign','chatAutoanswer',_0x027e('0x2a'),_0x027e('0x2b'),_0x027e('0x2c'),_0x027e('0x2d'),_0x027e('0x2e'),_0x027e('0x2f'),'openchannelAutoanswerDelay',_0x027e('0x30'),_0x027e('0x31'),'whatsappAutoanswer',_0x027e('0x32'),_0x027e('0x33')];exports[_0x027e('0x34')]=function(){return this[_0x027e('0x35')](!![])[_0x027e('0x36')](function(_0x320dff,_0x495512,_0x4c76df){if(_0x320dff[_0x027e('0x37')]){_0x4c76df();}else{return db[_0x027e('0x38')][_0x027e('0x39')]({'where':{'id':_0x320dff[_0x027e('0x3a')]['id']},'attributes':['id',_0x027e('0x3b'),_0x027e('0x3c')],'raw':!![]})[_0x027e('0x3d')](function(_0x431762){if(_0x431762&&_0x431762['closed']&&!_0x320dff[_0x027e('0x3e')][_0x027e('0x3f')]){return _0x495512[_0x027e('0x40')](_0x431762['disposition']===_0x027e('0x41')?0x195:0x193)[_0x027e('0x42')]({'message':_0x431762[_0x027e('0x3c')]==='unmanaged'?_0x027e('0x43'):_0x027e('0x44')});}else{_0x4c76df();}})['catch'](function(_0x99eee9){_0x4c76df(_0x99eee9);});}});};exports[_0x027e('0x35')]=function isAuthenticated(_0x169eeb){return compose()[_0x027e('0x36')](function(_0x83c466,_0xd4b678,_0x34d28b){var _0x4392cb;if(_0x83c466['headers'][_0x027e('0x45')]){if(_[_0x027e('0x46')](_0x83c466['headers'][_0x027e('0x45')],_0x027e('0x47'))){var _0x410ad0=basicAuth(_0x83c466);db[_0x027e('0x48')][_0x027e('0x49')]({'where':{'name':_0x410ad0[_0x027e('0xc')]}})['then'](function(_0x1ea20a){if(!_0x1ea20a||!_0x1ea20a[_0x027e('0x4a')](_0x410ad0['pass'])){return _0xd4b678[_0x027e('0x40')](0x191)['json']({'message':_0x027e('0x4b')});}_0x83c466[_0x027e('0x37')]={'id':_0x1ea20a['id']};_0x34d28b();})[_0x027e('0x4c')](function(_0x21d321){_0x34d28b(_0x21d321);});}else if(_[_0x027e('0x46')](_0x83c466[_0x027e('0x4d')][_0x027e('0x45')],_0x027e('0x4e'))){validateJwt(_0x83c466,_0xd4b678,_0x34d28b);}else{if(_0x169eeb){_0x34d28b();}else{return _0xd4b678[_0x027e('0x40')](0x193)[_0x027e('0x42')]({'message':_0x027e('0x4f')});}}}else if(_0x83c466[_0x027e('0x3e')][_0x027e('0x50')]){try{var _0x3b8964={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x027e('0x51')]()};verifyJwt(_0x83c466[_0x027e('0x3e')]['apikey'],_0x3b8964)[_0x027e('0x3d')](function(_0x3c0bc6){return db[_0x027e('0x48')][_0x027e('0x49')]({'where':{'id':_0x3c0bc6[_0x027e('0x52')]}})[_0x027e('0x3d')](function(_0x422e5d){_0x4392cb=_0x422e5d;return db[_0x027e('0x53')][_0x027e('0x39')]({'where':{'id':0x1},'attributes':[_0x027e('0x54'),_0x027e('0x55')],'raw':!![]});})[_0x027e('0x3d')](function(_0x53bd91){if(!_0x4392cb||!_[_0x027e('0x56')](_0x4392cb[_0x027e('0x57')],_0x3c0bc6[_0x027e('0x58')])){return _0xd4b678['status'](0x191)[_0x027e('0x42')]({'message':_0x027e('0x59')});}if(_0x4392cb['disabled']){return _0xd4b678[_0x027e('0x40')](0x191)['json']({'message':_0x027e('0x5a')});}if(_0x4392cb['blocked']){if(_0x53bd91[_0x027e('0x55')]>0x0){if(moment(_0x4392cb[_0x027e('0x5b')])['add'](_0x53bd91[_0x027e('0x55')],_0x027e('0x5c'))>moment()){return _0xd4b678['status'](0x191)['json']({'message':_0x027e('0x5a')});}}else{return _0xd4b678[_0x027e('0x40')](0x191)[_0x027e('0x42')]({'message':_0x027e('0x5a')});}}_0x83c466[_0x027e('0x37')]={'id':_0x4392cb['id']};_0x34d28b();});})['catch'](function(){return _0xd4b678[_0x027e('0x40')](0x191)[_0x027e('0x42')]({'message':_0x027e('0x5a')});});}catch(_0x3ff24f){_0x34d28b(_0x3ff24f);}}else if(_0x169eeb){_0x34d28b();}else{return _0xd4b678[_0x027e('0x40')](0x193)[_0x027e('0x42')]({'message':_0x027e('0x4f')});}})[_0x027e('0x36')](function(_0x10746c,_0x29f2a2,_0x232da0){if(_0x10746c[_0x027e('0x37')]){db[_0x027e('0x48')][_0x027e('0x49')]({'where':{'id':_0x10746c[_0x027e('0x37')]['id']},'attributes':userAttributes})[_0x027e('0x3d')](function(_0x20199b){if(!_0x20199b){return _0x29f2a2['status'](0x194)['json']({'message':_0x027e('0x5d')});}_0x10746c[_0x027e('0x37')]=_0x20199b;_0x232da0();})['catch'](function(_0x3bdc70){_0x232da0(_0x3bdc70);});}else if(_0x169eeb){_0x232da0();}else{return _0x29f2a2[_0x027e('0x40')](0x194)['json']({'message':_0x027e('0x5e')});}});};exports[_0x027e('0x5f')]=function canUpdate(){return compose()[_0x027e('0x36')](function(_0x3867d0,_0x4e6390,_0x1c9f56){return licenseUtil[_0x027e('0x60')]()[_0x027e('0x3d')](function(_0x5c334d){if(_0x5c334d[_0x027e('0x61')]){_0x1c9f56();}else{return _0x4e6390[_0x027e('0x40')](0x193)['json']({'message':_0x027e('0x62')});}})[_0x027e('0x4c')](function(_0x4a10b3){_0x1c9f56(_0x4a10b3);});});};exports[_0x027e('0x63')]=function isWebrtcLicence(){return compose()[_0x027e('0x36')](function(_0x112ddf,_0x1362c0,_0x23d517){return licenseUtil[_0x027e('0x60')]()[_0x027e('0x3d')](function(_0x514ad1){if(_0x514ad1[_0x027e('0x64')]){_0x23d517();}else{return _0x1362c0['status'](0x193)[_0x027e('0x42')]({'message':'Forbidden'});}})['catch'](function(_0x253c96){_0x23d517(_0x253c96);});});};exports[_0x027e('0x65')]=function(_0x611911,_0x2c939a,_0x2eb9b7){_0x611911[_0x027e('0x65')]=!![];return _0x2eb9b7();};exports[_0x027e('0x66')]=function signToken(_0x5428d8){return signJwt(_0x5428d8);};exports[_0x027e('0x67')]=function(_0x1f63f6,_0x2e9459){if(!_0x1f63f6[_0x027e('0x37')]){return _0x2e9459[_0x027e('0x40')](0x194)['json']({'message':_0x027e('0x68')});}var _0x5ae246={'payload':{'id':_0x1f63f6[_0x027e('0x37')]['id'],'role':_0x1f63f6[_0x027e('0x37')]['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x5ae246)[_0x027e('0x3d')](function(_0x40b8e5){_0x2e9459[_0x027e('0x69')](_0x027e('0x6a'),_0x40b8e5);_0x2e9459['redirect'](_0x027e('0x6b'));})[_0x027e('0x4c')](function(_0x485184){return _0x2e9459[_0x027e('0x40')](0x1f4)['send'](_0x485184);});};exports['retrieveApiKey']=function(_0xde505e){if(_['isNil'](_0xde505e[_0x027e('0x57')])||_[_0x027e('0x6c')](_0xde505e[_0x027e('0x6d')])){return null;}else{return createJwt(_0xde505e);}};exports['generateApiKey']=function(_0x214d39){_0x214d39[_0x027e('0x57')]=generateNonce();_0x214d39['apiKeyIat']=generateIssuedAt();return createJwt(_0x214d39);};exports[_0x027e('0x6e')]=function(_0x242e8c,_0x44a417){var _0x46e717=_0x242e8c[_0x027e('0x3e')][_0x027e('0x50')];if(_0x46e717){var _0xebf587={'nonce':_0x44a417[_0x027e('0x57')],'iat':_0x44a417[_0x027e('0x6d')],'audience':hardwareConf[_0x027e('0x51')](),'issuer':hardwareConf[_0x027e('0x51')]()};return verifyJwt(_0x46e717,_0xebf587)[_0x027e('0x3d')](function(){return generateApiKey(_0x44a417);});}else{throw{'message':_0x027e('0x6f')};}};exports[_0x027e('0x70')]=function(_0x133c18){var _0x2ab98d=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x2ab98d['test'](_0x133c18))throw new db[(_0x027e('0x71'))]['ValidationError'](_0x027e('0x72'));return;};exports[_0x027e('0x73')]=function(_0x4ea6d9,_0x307866,_0xad7cb){var _0xcc76bd=encryptor[_0x027e('0x74')](_0x307866)[_0x027e('0x75')](',');for(var _0xdf0bfb=0x0;_0xdf0bfb<_0xad7cb;_0xdf0bfb++){if(!_0xcc76bd[_0xdf0bfb])break;if(_0x4ea6d9[_0x027e('0x76')]()===_0xcc76bd[_0xdf0bfb][_0x027e('0x76')]()){var _0xdf09a1=util['format']('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0xad7cb);if(_0xad7cb===0x1){_0xdf09a1=_0x027e('0x77');}throw new db[(_0x027e('0x71'))][(_0x027e('0x78'))](_0xdf09a1);}}return;};exports[_0x027e('0x79')]=function(_0x33edd8,_0x47c61d){var _0x1c364b=_0x47c61d?encryptor[_0x027e('0x74')](_0x47c61d)[_0x027e('0x75')](','):[];if(_0x1c364b[_0x027e('0x7a')]===0x5){_0x1c364b[_0x027e('0x7b')](-0x1,0x1);}_0x1c364b[_0x027e('0x7c')](_0x33edd8);return encryptor[_0x027e('0x7d')](_0x1c364b['join'](','));};function signJwt(_0x1785fa){var _0x5c83ee=BPromise[_0x027e('0x7e')](jwt[_0x027e('0x7f')],{'context':jwt});var _0x270869=_0x1785fa[_0x027e('0x80')]||config[_0x027e('0x81')][_0x027e('0x82')];return new BPromise(function(_0x26f28e,_0x2a5071){_0x5c83ee(_0x1785fa[_0x027e('0x83')],_0x270869,_0x1785fa[_0x027e('0x84')])[_0x027e('0x3d')](function(_0x27db0d){_0x26f28e(_0x27db0d);})[_0x027e('0x4c')](function(_0x420a2d){_0x2a5071(_0x420a2d);});});}function verifyJwt(_0x3110f3,_0x85d717,_0x4315df){var _0x45274e=BPromise['promisify'](jwt[_0x027e('0x85')],{'context':jwt});var _0x12e5e3=_0x4315df||config['secrets'][_0x027e('0x82')];return new BPromise(function(_0x4114ad,_0x955771){_0x45274e(_0x3110f3,_0x12e5e3,_0x85d717)[_0x027e('0x3d')](function(_0x4fb1b8){_0x4114ad(_0x4fb1b8);})[_0x027e('0x4c')](function(_0x5bffe6){_0x955771(_0x5bffe6);});});}function generateNonce(){return crypto['randomBytes'](0x10)[_0x027e('0x86')](_0x027e('0x87'));}function generateIssuedAt(){return Math[_0x027e('0x88')](Date[_0x027e('0x89')]()/0x3e8)[_0x027e('0x86')]();}function createJwt(_0x21e681){var _0x36cad4={'payload':{'iat':_0x21e681[_0x027e('0x6d')],'nonce':_0x21e681[_0x027e('0x57')]},'options':{'algorithm':_0x027e('0x8a'),'subject':_0x21e681['id']['toString'](),'issuer':hardwareConf[_0x027e('0x51')](),'audience':hardwareConf[_0x027e('0x51')]()}};return signJwt(_0x36cad4)[_0x027e('0x3d')](function(_0x15c4c5){return{'iat':_0x21e681[_0x027e('0x6d')],'nonce':_0x21e681['apiKeyNonce'],'token':_0x15c4c5};});}