bac00c6b3fa97bdc4e1b4e3e43dccedb77a11cb1
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xd095=['moment','secrets','session','role','fullname','name','internal','email','permissions','md5secret','chatPause','faxPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','alias','phoneBarAutoAnswerDelay','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','settingsEnabled','isChatInteractionAuthorized','isAuthenticated','use','user','findOne','params','closed','disposition','then','status','unmanaged','json','Unmanaged.','catch','headers','authorization','authenticate','Wrong\x20credentials.','startsWith','Bearer','Unknown\x20authorization\x20format','query','apikey','getUuid','User','find','Setting','isEqual','apiKeyNonce','nonce','disabled','Invalid\x20API\x20access\x20key','blockedAt','canUpdate','update','Forbidden','isMiddleware','signToken','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','redirect','/dashboards/general','send','retrieveApiKey','isNil','generateApiKey','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','length','splice','promisify','secret','payload','options','randomBytes','toString','hex','floor','apiKeyIat','../../mysqldb','../../config/environment','../../config/license/util','../encryptor','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util'];(function(_0x310504,_0x26ad95){var _0x5b36d0=function(_0x253f28){while(--_0x253f28){_0x310504['push'](_0x310504['shift']());}};_0x5b36d0(++_0x26ad95);}(_0xd095,0x1b5));var _0x5d09=function(_0x346737,_0x3e6081){_0x346737=_0x346737-0x0;var _0x1ade2e=_0xd095[_0x346737];return _0x1ade2e;};'use strict';var db=require(_0x5d09('0x0'))['db'];var config=require(_0x5d09('0x1'));var hardwareConf=require('../../config/license/hardware');var licenseUtil=require(_0x5d09('0x2'));var encryptor=require(_0x5d09('0x3'));var _=require('lodash');var jwt=require(_0x5d09('0x4'));var expressJwt=require(_0x5d09('0x5'));var compose=require(_0x5d09('0x6'));var basicAuth=require(_0x5d09('0x7'));var crypto=require(_0x5d09('0x8'));var BPromise=require(_0x5d09('0x9'));var util=require(_0x5d09('0xa'));var moment=require(_0x5d09('0xb'));var validateJwt=expressJwt({'secret':config[_0x5d09('0xc')][_0x5d09('0xd')]});var userAttributes=['id',_0x5d09('0xe'),_0x5d09('0xf'),_0x5d09('0x10'),_0x5d09('0x11'),_0x5d09('0x12'),'userpic',_0x5d09('0x13'),_0x5d09('0x14'),'voicePause',_0x5d09('0x15'),'mailPause',_0x5d09('0x16'),'smsPause',_0x5d09('0x17'),_0x5d09('0x18'),_0x5d09('0x19'),_0x5d09('0x1a'),_0x5d09('0x1b'),_0x5d09('0x1c'),_0x5d09('0x1d'),'passwordResetAt',_0x5d09('0x1e'),'phoneBarAutoAnswer',_0x5d09('0x1f'),'phoneBarDnd','phoneBarEnableRecording',_0x5d09('0x20'),'phoneBarEnableSettings',_0x5d09('0x21'),_0x5d09('0x22'),_0x5d09('0x23'),_0x5d09('0x24'),_0x5d09('0x25'),_0x5d09('0x26'),_0x5d09('0x27'),_0x5d09('0x28')];exports[_0x5d09('0x29')]=function(){return this[_0x5d09('0x2a')](!![])[_0x5d09('0x2b')](function(_0x3965d8,_0x559c4f,_0xb8cb4b){if(_0x3965d8[_0x5d09('0x2c')]){_0xb8cb4b();}else{return db['ChatInteraction'][_0x5d09('0x2d')]({'where':{'id':_0x3965d8[_0x5d09('0x2e')]['id']},'attributes':['id',_0x5d09('0x2f'),_0x5d09('0x30')],'raw':!![]})[_0x5d09('0x31')](function(_0x3f276a){if(_0x3f276a&&_0x3f276a['closed']){return _0x559c4f[_0x5d09('0x32')](_0x3f276a['disposition']===_0x5d09('0x33')?0x195:0x193)[_0x5d09('0x34')]({'message':_0x3f276a[_0x5d09('0x30')]==='unmanaged'?_0x5d09('0x35'):'Forbidden.'});}else{_0xb8cb4b();}})[_0x5d09('0x36')](function(_0x531e54){_0xb8cb4b(_0x531e54);});}});};exports[_0x5d09('0x2a')]=function isAuthenticated(_0xc28318){return compose()[_0x5d09('0x2b')](function(_0x4361dd,_0x3c9c3b,_0x2e4446){var _0x2f6a0e;if(_0x4361dd[_0x5d09('0x37')][_0x5d09('0x38')]){if(_['startsWith'](_0x4361dd[_0x5d09('0x37')][_0x5d09('0x38')],'Basic')){var _0x411f7f=basicAuth(_0x4361dd);db['User']['find']({'where':{'name':_0x411f7f[_0x5d09('0x10')]}})['then'](function(_0x49c1d4){if(!_0x49c1d4||!_0x49c1d4[_0x5d09('0x39')](_0x411f7f['pass'])){return _0x3c9c3b[_0x5d09('0x32')](0x191)['json']({'message':_0x5d09('0x3a')});}_0x4361dd['user']={'id':_0x49c1d4['id']};_0x2e4446();})[_0x5d09('0x36')](function(_0x2a9bcb){_0x2e4446(_0x2a9bcb);});}else if(_[_0x5d09('0x3b')](_0x4361dd[_0x5d09('0x37')][_0x5d09('0x38')],_0x5d09('0x3c'))){validateJwt(_0x4361dd,_0x3c9c3b,_0x2e4446);}else{if(_0xc28318){_0x2e4446();}else{return _0x3c9c3b['status'](0x193)['json']({'message':_0x5d09('0x3d')});}}}else if(_0x4361dd[_0x5d09('0x3e')][_0x5d09('0x3f')]){try{var _0x39c1ba={'audience':hardwareConf[_0x5d09('0x40')](),'issuer':hardwareConf[_0x5d09('0x40')]()};verifyJwt(_0x4361dd['query'][_0x5d09('0x3f')],_0x39c1ba)[_0x5d09('0x31')](function(_0x423167){return db[_0x5d09('0x41')][_0x5d09('0x42')]({'where':{'id':_0x423167['sub']}})[_0x5d09('0x31')](function(_0x46c453){_0x2f6a0e=_0x46c453;return db[_0x5d09('0x43')][_0x5d09('0x2d')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts','blockDuration'],'raw':!![]});})['then'](function(_0x360ee7){if(!_0x2f6a0e||!_[_0x5d09('0x44')](_0x2f6a0e[_0x5d09('0x45')],_0x423167[_0x5d09('0x46')])){return _0x3c9c3b[_0x5d09('0x32')](0x191)['json']({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x2f6a0e[_0x5d09('0x47')]){return _0x3c9c3b[_0x5d09('0x32')](0x191)[_0x5d09('0x34')]({'message':_0x5d09('0x48')});}if(_0x2f6a0e['blocked']){if(_0x360ee7['blockDuration']>0x0){if(moment(_0x2f6a0e[_0x5d09('0x49')])['add'](_0x360ee7['blockDuration'],'minutes')>moment()){return _0x3c9c3b[_0x5d09('0x32')](0x191)['json']({'message':_0x5d09('0x48')});}}else{return _0x3c9c3b[_0x5d09('0x32')](0x191)[_0x5d09('0x34')]({'message':_0x5d09('0x48')});}}_0x4361dd[_0x5d09('0x2c')]={'id':_0x2f6a0e['id']};_0x2e4446();});})['catch'](function(){return _0x3c9c3b[_0x5d09('0x32')](0x191)[_0x5d09('0x34')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x19d1a7){_0x2e4446(_0x19d1a7);}}else if(_0xc28318){_0x2e4446();}else{return _0x3c9c3b['status'](0x193)[_0x5d09('0x34')]({'message':_0x5d09('0x3d')});}})['use'](function(_0x53f25a,_0xe43843,_0x332346){if(_0x53f25a[_0x5d09('0x2c')]){db[_0x5d09('0x41')]['find']({'where':{'id':_0x53f25a['user']['id']},'attributes':userAttributes})[_0x5d09('0x31')](function(_0x4b5172){if(!_0x4b5172){return _0xe43843[_0x5d09('0x32')](0x194)[_0x5d09('0x34')]({'message':'User\x20not\x20found.'});}_0x53f25a[_0x5d09('0x2c')]=_0x4b5172;_0x332346();})[_0x5d09('0x36')](function(_0x129f89){_0x332346(_0x129f89);});}else if(_0xc28318){_0x332346();}else{return _0xe43843[_0x5d09('0x32')](0x194)[_0x5d09('0x34')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x5d09('0x4a')]=function canUpdate(){return compose()['use'](function(_0x5479d7,_0x256f05,_0x12918e){return licenseUtil['getLicense']()['then'](function(_0x11bd2c){if(_0x11bd2c[_0x5d09('0x4b')]){_0x12918e();}else{return _0x256f05[_0x5d09('0x32')](0x193)[_0x5d09('0x34')]({'message':_0x5d09('0x4c')});}})[_0x5d09('0x36')](function(_0x2eb4b6){_0x12918e(_0x2eb4b6);});});};exports[_0x5d09('0x4d')]=function(_0x2ddb9a,_0x4744ef,_0x3ffb3c){_0x2ddb9a[_0x5d09('0x4d')]=!![];return _0x3ffb3c();};exports[_0x5d09('0x4e')]=function signToken(_0x1ebba1){return signJwt(_0x1ebba1);};exports['setTokenCookie']=function(_0x425916,_0x3156e3){if(!_0x425916[_0x5d09('0x2c')]){return _0x3156e3['status'](0x194)[_0x5d09('0x34')]({'message':_0x5d09('0x4f')});}var _0x512642={'payload':{'id':_0x425916[_0x5d09('0x2c')]['id'],'role':_0x425916[_0x5d09('0x2c')][_0x5d09('0xe')]},'options':{'expiresIn':0x15180}};return signJwt(_0x512642)[_0x5d09('0x31')](function(_0x4d92af){_0x3156e3[_0x5d09('0x50')](_0x5d09('0x51'),_0x4d92af);_0x3156e3[_0x5d09('0x52')](_0x5d09('0x53'));})['catch'](function(_0x2c5ac9){return _0x3156e3[_0x5d09('0x32')](0x1f4)[_0x5d09('0x54')](_0x2c5ac9);});};exports[_0x5d09('0x55')]=function(_0x10587a){if(_[_0x5d09('0x56')](_0x10587a[_0x5d09('0x45')])||_[_0x5d09('0x56')](_0x10587a['apiKeyIat'])){return null;}else{return createJwt(_0x10587a);}};exports[_0x5d09('0x57')]=function(_0x2334f2){_0x2334f2[_0x5d09('0x45')]=generateNonce();_0x2334f2['apiKeyIat']=generateIssuedAt();return createJwt(_0x2334f2);};exports[_0x5d09('0x58')]=function(_0x57984e,_0x2f2db9){var _0x6486f0=_0x57984e[_0x5d09('0x3e')][_0x5d09('0x3f')];if(_0x6486f0){var _0x4592ba={'nonce':_0x2f2db9[_0x5d09('0x45')],'iat':_0x2f2db9['apiKeyIat'],'audience':hardwareConf[_0x5d09('0x40')](),'issuer':hardwareConf[_0x5d09('0x40')]()};return verifyJwt(_0x6486f0,_0x4592ba)['then'](function(){return generateApiKey(_0x2f2db9);});}else{throw{'message':_0x5d09('0x59')};}};exports[_0x5d09('0x5a')]=function(_0x1cf974){var _0x2d8a35=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x2d8a35[_0x5d09('0x5b')](_0x1cf974))throw new db['Sequelize'][(_0x5d09('0x5c'))](_0x5d09('0x5d'));return;};exports[_0x5d09('0x5e')]=function(_0x277a14,_0x3a9bbe,_0x5df985){var _0x29514b=encryptor[_0x5d09('0x5f')](_0x3a9bbe)[_0x5d09('0x60')](',');for(var _0x211475=0x0;_0x211475<_0x5df985;_0x211475++){if(!_0x29514b[_0x211475])break;if(_0x277a14['toLowerCase']()===_0x29514b[_0x211475][_0x5d09('0x61')]()){var _0x5d522b=util[_0x5d09('0x62')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x5df985);if(_0x5df985===0x1){_0x5d522b=_0x5d09('0x63');}throw new db['Sequelize'][(_0x5d09('0x5c'))](_0x5d522b);}}return;};exports[_0x5d09('0x64')]=function(_0x56c31c,_0x561541){var _0x485f2b=_0x561541?encryptor[_0x5d09('0x5f')](_0x561541)[_0x5d09('0x60')](','):[];if(_0x485f2b[_0x5d09('0x65')]===0x5){_0x485f2b[_0x5d09('0x66')](-0x1,0x1);}_0x485f2b['unshift'](_0x56c31c);return encryptor['encryptString'](_0x485f2b['join'](','));};function signJwt(_0x43c773){var _0x1dc282=BPromise[_0x5d09('0x67')](jwt['sign'],{'context':jwt});var _0x33380c=_0x43c773[_0x5d09('0x68')]||config[_0x5d09('0xc')][_0x5d09('0xd')];return new BPromise(function(_0x854a73,_0x416868){_0x1dc282(_0x43c773[_0x5d09('0x69')],_0x33380c,_0x43c773[_0x5d09('0x6a')])[_0x5d09('0x31')](function(_0x3ab587){_0x854a73(_0x3ab587);})[_0x5d09('0x36')](function(_0x309200){_0x416868(_0x309200);});});}function verifyJwt(_0x55d15f,_0x1d756d,_0x21ef7d){var _0x39acd1=BPromise[_0x5d09('0x67')](jwt['verify'],{'context':jwt});var _0x4d0f4d=_0x21ef7d||config[_0x5d09('0xc')][_0x5d09('0xd')];return new BPromise(function(_0x126630,_0xa6aede){_0x39acd1(_0x55d15f,_0x4d0f4d,_0x1d756d)[_0x5d09('0x31')](function(_0x36f419){_0x126630(_0x36f419);})['catch'](function(_0x2f761f){_0xa6aede(_0x2f761f);});});}function generateNonce(){return crypto[_0x5d09('0x6b')](0x10)[_0x5d09('0x6c')](_0x5d09('0x6d'));}function generateIssuedAt(){return Math[_0x5d09('0x6e')](Date['now']()/0x3e8)[_0x5d09('0x6c')]();}function createJwt(_0xffe04d){var _0x26c81a={'payload':{'iat':_0xffe04d[_0x5d09('0x6f')],'nonce':_0xffe04d[_0x5d09('0x45')]},'options':{'algorithm':'HS512','subject':_0xffe04d['id']['toString'](),'issuer':hardwareConf[_0x5d09('0x40')](),'audience':hardwareConf[_0x5d09('0x40')]()}};return signJwt(_0x26c81a)[_0x5d09('0x31')](function(_0x3517ae){return{'iat':_0xffe04d[_0x5d09('0x6f')],'nonce':_0xffe04d[_0x5d09('0x45')],'token':_0x3517ae};});}