Built motion from commit (unavailable).|2.5.21
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xd00a=['Invalid\x20API\x20access\x20key','User','User\x20not\x20found.','getLicense','Forbidden','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','motion.token','retrieveApiKey','apiKeyNonce','isNil','generateApiKey','regenerateApiKey','apiKeyIat','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','ValidationError','decryptString','join','promisify','secret','secrets','session','options','verify','randomBytes','toString','hex','floor','now','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','lodash','composable-middleware','basic-auth','bluebird','util','moment','role','fullname','name','email','userpic','permissions','chatPause','mailPause','faxPause','smsPause','pauseType','showWebBar','lastLoginAt','crudPermissions','passwordResetAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','settingsEnabled','isChatInteractionAuthorized','use','user','ChatInteraction','findOne','params','closed','then','status','disposition','json','unmanaged','Unmanaged.','Forbidden.','catch','headers','authorization','startsWith','Basic','find','authenticate','pass','Unknown\x20authorization\x20format','query','apikey','getUuid','sub','Setting','isEqual','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockDuration','blockedAt','add'];(function(_0x3dd15e,_0x1f0015){var _0x231fd0=function(_0x4f680a){while(--_0x4f680a){_0x3dd15e['push'](_0x3dd15e['shift']());}};_0x231fd0(++_0x1f0015);}(_0xd00a,0x17c));var _0xad00=function(_0x886835,_0x522d9a){_0x886835=_0x886835-0x0;var _0x1e81df=_0xd00a[_0x886835];return _0x1e81df;};'use strict';var db=require(_0xad00('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0xad00('0x1'));var licenseUtil=require(_0xad00('0x2'));var encryptor=require(_0xad00('0x3'));var _=require(_0xad00('0x4'));var jwt=require('jsonwebtoken');var expressJwt=require('express-jwt');var compose=require(_0xad00('0x5'));var basicAuth=require(_0xad00('0x6'));var crypto=require('crypto');var BPromise=require(_0xad00('0x7'));var util=require(_0xad00('0x8'));var moment=require(_0xad00('0x9'));var validateJwt=expressJwt({'secret':config['secrets']['session']});var userAttributes=['id',_0xad00('0xa'),_0xad00('0xb'),_0xad00('0xc'),'internal',_0xad00('0xd'),_0xad00('0xe'),_0xad00('0xf'),'md5secret','voicePause',_0xad00('0x10'),_0xad00('0x11'),_0xad00('0x12'),_0xad00('0x13'),'openchannelPause',_0xad00('0x14'),_0xad00('0x15'),_0xad00('0x16'),'lastPauseAt',_0xad00('0x17'),'allowmessenger',_0xad00('0x18'),'alias',_0xad00('0x19'),_0xad00('0x1a'),_0xad00('0x1b'),'phoneBarEnableRecording',_0xad00('0x1c'),'phoneBarEnableSettings',_0xad00('0x1d'),_0xad00('0x1e'),_0xad00('0x1f'),_0xad00('0x20'),_0xad00('0x21'),_0xad00('0x22'),_0xad00('0x23'),_0xad00('0x24')];exports[_0xad00('0x25')]=function(){return this['isAuthenticated'](!![])[_0xad00('0x26')](function(_0x4cf127,_0x523080,_0x16b8cf){if(_0x4cf127[_0xad00('0x27')]){_0x16b8cf();}else{return db[_0xad00('0x28')][_0xad00('0x29')]({'where':{'id':_0x4cf127[_0xad00('0x2a')]['id']},'attributes':['id',_0xad00('0x2b'),'disposition'],'raw':!![]})[_0xad00('0x2c')](function(_0x4ef8d1){if(_0x4ef8d1&&_0x4ef8d1[_0xad00('0x2b')]){return _0x523080[_0xad00('0x2d')](_0x4ef8d1[_0xad00('0x2e')]==='unmanaged'?0x195:0x193)[_0xad00('0x2f')]({'message':_0x4ef8d1[_0xad00('0x2e')]===_0xad00('0x30')?_0xad00('0x31'):_0xad00('0x32')});}else{_0x16b8cf();}})[_0xad00('0x33')](function(_0x18da70){_0x16b8cf(_0x18da70);});}});};exports['isAuthenticated']=function isAuthenticated(_0x2231cb){return compose()[_0xad00('0x26')](function(_0x26e301,_0x3382ac,_0x419d30){var _0x4e4e79;if(_0x26e301[_0xad00('0x34')][_0xad00('0x35')]){if(_[_0xad00('0x36')](_0x26e301[_0xad00('0x34')][_0xad00('0x35')],_0xad00('0x37'))){var _0x48f2dd=basicAuth(_0x26e301);db['User'][_0xad00('0x38')]({'where':{'name':_0x48f2dd[_0xad00('0xc')]}})['then'](function(_0x56fe43){if(!_0x56fe43||!_0x56fe43[_0xad00('0x39')](_0x48f2dd[_0xad00('0x3a')])){return _0x3382ac[_0xad00('0x2d')](0x191)[_0xad00('0x2f')]({'message':'Wrong\x20credentials.'});}_0x26e301[_0xad00('0x27')]={'id':_0x56fe43['id']};_0x419d30();})[_0xad00('0x33')](function(_0x5ea9db){_0x419d30(_0x5ea9db);});}else if(_[_0xad00('0x36')](_0x26e301[_0xad00('0x34')][_0xad00('0x35')],'Bearer')){validateJwt(_0x26e301,_0x3382ac,_0x419d30);}else{if(_0x2231cb){_0x419d30();}else{return _0x3382ac[_0xad00('0x2d')](0x193)[_0xad00('0x2f')]({'message':_0xad00('0x3b')});}}}else if(_0x26e301[_0xad00('0x3c')][_0xad00('0x3d')]){try{var _0x24b67d={'audience':hardwareConf[_0xad00('0x3e')](),'issuer':hardwareConf[_0xad00('0x3e')]()};verifyJwt(_0x26e301[_0xad00('0x3c')][_0xad00('0x3d')],_0x24b67d)[_0xad00('0x2c')](function(_0x4a5b52){return db['User'][_0xad00('0x38')]({'where':{'id':_0x4a5b52[_0xad00('0x3f')]}})[_0xad00('0x2c')](function(_0x10fba9){_0x4e4e79=_0x10fba9;return db[_0xad00('0x40')][_0xad00('0x29')]({'where':{'id':0x1},'attributes':['allowedLoginAttempts','blockDuration'],'raw':!![]});})['then'](function(_0x5e21d0){if(!_0x4e4e79||!_[_0xad00('0x41')](_0x4e4e79['apiKeyNonce'],_0x4a5b52['nonce'])){return _0x3382ac['status'](0x191)[_0xad00('0x2f')]({'message':_0xad00('0x42')});}if(_0x4e4e79[_0xad00('0x43')]){return _0x3382ac[_0xad00('0x2d')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}if(_0x4e4e79[_0xad00('0x44')]){if(_0x5e21d0[_0xad00('0x45')]>0x0){if(moment(_0x4e4e79[_0xad00('0x46')])[_0xad00('0x47')](_0x5e21d0[_0xad00('0x45')],'minutes')>moment()){return _0x3382ac[_0xad00('0x2d')](0x191)['json']({'message':_0xad00('0x48')});}}else{return _0x3382ac[_0xad00('0x2d')](0x191)['json']({'message':_0xad00('0x48')});}}_0x26e301[_0xad00('0x27')]={'id':_0x4e4e79['id']};_0x419d30();});})[_0xad00('0x33')](function(){return _0x3382ac[_0xad00('0x2d')](0x191)['json']({'message':_0xad00('0x48')});});}catch(_0x183f5e){_0x419d30(_0x183f5e);}}else if(_0x2231cb){_0x419d30();}else{return _0x3382ac[_0xad00('0x2d')](0x193)[_0xad00('0x2f')]({'message':'Unknown\x20authorization\x20format'});}})[_0xad00('0x26')](function(_0x491d27,_0x2f6e31,_0x14c2cb){if(_0x491d27['user']){db[_0xad00('0x49')][_0xad00('0x38')]({'where':{'id':_0x491d27[_0xad00('0x27')]['id']},'attributes':userAttributes})['then'](function(_0x1c72d9){if(!_0x1c72d9){return _0x2f6e31[_0xad00('0x2d')](0x194)[_0xad00('0x2f')]({'message':_0xad00('0x4a')});}_0x491d27['user']=_0x1c72d9;_0x14c2cb();})[_0xad00('0x33')](function(_0x171a50){_0x14c2cb(_0x171a50);});}else if(_0x2231cb){_0x14c2cb();}else{return _0x2f6e31[_0xad00('0x2d')](0x194)[_0xad00('0x2f')]({'message':'User\x20object\x20not\x20found.'});}});};exports['canUpdate']=function canUpdate(){return compose()[_0xad00('0x26')](function(_0xf91213,_0x2fb9d9,_0x531d73){return licenseUtil[_0xad00('0x4b')]()['then'](function(_0x88b5be){if(_0x88b5be['update']){_0x531d73();}else{return _0x2fb9d9[_0xad00('0x2d')](0x193)[_0xad00('0x2f')]({'message':_0xad00('0x4c')});}})[_0xad00('0x33')](function(_0x3cabda){_0x531d73(_0x3cabda);});});};exports[_0xad00('0x4d')]=function(_0x258f9a,_0x5f4e68,_0x527e75){_0x258f9a['isMiddleware']=!![];return _0x527e75();};exports[_0xad00('0x4e')]=function signToken(_0x3f49ab){return signJwt(_0x3f49ab);};exports[_0xad00('0x4f')]=function(_0x42039e,_0x5c2590){if(!_0x42039e[_0xad00('0x27')]){return _0x5c2590[_0xad00('0x2d')](0x194)[_0xad00('0x2f')]({'message':_0xad00('0x50')});}var _0x5f557d={'payload':{'id':_0x42039e['user']['id'],'role':_0x42039e['user']['role']},'options':{'expiresIn':0x15180}};return signJwt(_0x5f557d)[_0xad00('0x2c')](function(_0x1e358a){_0x5c2590['cookie'](_0xad00('0x51'),_0x1e358a);_0x5c2590['redirect']('/dashboards/general');})[_0xad00('0x33')](function(_0x1f0887){return _0x5c2590['status'](0x1f4)['send'](_0x1f0887);});};exports[_0xad00('0x52')]=function(_0x1db204){if(_['isNil'](_0x1db204[_0xad00('0x53')])||_[_0xad00('0x54')](_0x1db204['apiKeyIat'])){return null;}else{return createJwt(_0x1db204);}};exports[_0xad00('0x55')]=function(_0x235b08){_0x235b08[_0xad00('0x53')]=generateNonce();_0x235b08['apiKeyIat']=generateIssuedAt();return createJwt(_0x235b08);};exports[_0xad00('0x56')]=function(_0x355848,_0x2aad74){var _0x5368c0=_0x355848[_0xad00('0x3c')][_0xad00('0x3d')];if(_0x5368c0){var _0x3b100c={'nonce':_0x2aad74[_0xad00('0x53')],'iat':_0x2aad74[_0xad00('0x57')],'audience':hardwareConf[_0xad00('0x3e')](),'issuer':hardwareConf[_0xad00('0x3e')]()};return verifyJwt(_0x5368c0,_0x3b100c)['then'](function(){return generateApiKey(_0x2aad74);});}else{throw{'message':_0xad00('0x58')};}};exports[_0xad00('0x59')]=function(_0x2c73d7){var _0x33ba68=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x33ba68[_0xad00('0x5a')](_0x2c73d7))throw new db[(_0xad00('0x5b'))]['ValidationError'](_0xad00('0x5c'));return;};exports[_0xad00('0x5d')]=function(_0x4660ac,_0x58bfb4,_0x941c42){var _0x10597d=encryptor['decryptString'](_0x58bfb4)[_0xad00('0x5e')](',');for(var _0x69149e=0x0;_0x69149e<_0x941c42;_0x69149e++){if(!_0x10597d[_0x69149e])break;if(_0x4660ac[_0xad00('0x5f')]()===_0x10597d[_0x69149e][_0xad00('0x5f')]()){var _0x1f5f51=util[_0xad00('0x60')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x941c42);if(_0x941c42===0x1){_0x1f5f51=_0xad00('0x61');}throw new db[(_0xad00('0x5b'))][(_0xad00('0x62'))](_0x1f5f51);}}return;};exports['updatePasswordsHistory']=function(_0x4ea5d9,_0x3c23f4){var _0x4c12cf=_0x3c23f4?encryptor[_0xad00('0x63')](_0x3c23f4)[_0xad00('0x5e')](','):[];if(_0x4c12cf['length']===0x5){_0x4c12cf['splice'](-0x1,0x1);}_0x4c12cf['unshift'](_0x4ea5d9);return encryptor['encryptString'](_0x4c12cf[_0xad00('0x64')](','));};function signJwt(_0xba728a){var _0xd2cd49=BPromise[_0xad00('0x65')](jwt['sign'],{'context':jwt});var _0x2e690e=_0xba728a[_0xad00('0x66')]||config[_0xad00('0x67')][_0xad00('0x68')];return new BPromise(function(_0x40e45e,_0x2d9a92){_0xd2cd49(_0xba728a['payload'],_0x2e690e,_0xba728a[_0xad00('0x69')])['then'](function(_0x2605b0){_0x40e45e(_0x2605b0);})['catch'](function(_0x1915f2){_0x2d9a92(_0x1915f2);});});}function verifyJwt(_0x53eb9c,_0x14aaa2,_0x360c7b){var _0x309a5b=BPromise[_0xad00('0x65')](jwt[_0xad00('0x6a')],{'context':jwt});var _0x384b93=_0x360c7b||config[_0xad00('0x67')][_0xad00('0x68')];return new BPromise(function(_0x6c669,_0x449f3c){_0x309a5b(_0x53eb9c,_0x384b93,_0x14aaa2)[_0xad00('0x2c')](function(_0x47f79f){_0x6c669(_0x47f79f);})[_0xad00('0x33')](function(_0x291ef7){_0x449f3c(_0x291ef7);});});}function generateNonce(){return crypto[_0xad00('0x6b')](0x10)[_0xad00('0x6c')](_0xad00('0x6d'));}function generateIssuedAt(){return Math[_0xad00('0x6e')](Date[_0xad00('0x6f')]()/0x3e8)[_0xad00('0x6c')]();}function createJwt(_0x2fa271){var _0x58d7f9={'payload':{'iat':_0x2fa271['apiKeyIat'],'nonce':_0x2fa271[_0xad00('0x53')]},'options':{'algorithm':_0xad00('0x70'),'subject':_0x2fa271['id'][_0xad00('0x6c')](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0xad00('0x3e')]()}};return signJwt(_0x58d7f9)[_0xad00('0x2c')](function(_0x4609dc){return{'iat':_0x2fa271['apiKeyIat'],'nonce':_0x2fa271['apiKeyNonce'],'token':_0x4609dc};});}