Built motion from commit (unavailable).|2.5.11
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x7082=['status','unmanaged','json','Forbidden.','catch','headers','authorization','startsWith','Basic','User','name','authenticate','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','query','getUuid','find','sub','isEqual','apiKeyNonce','canUpdate','getLicense','Forbidden','isMiddleware','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','role','cookie','/dashboards/general','retrieveApiKey','isNil','apiKeyIat','generateApiKey','regenerateApiKey','apikey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','test','Sequelize','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','split','toLowerCase','format','decryptString','length','splice','unshift','secret','payload','options','promisify','verify','randomBytes','toString','hex','now','../../mysqldb','../../config/environment','../../config/license/util','../encryptor','lodash','jsonwebtoken','express-jwt','composable-middleware','basic-auth','crypto','bluebird','util','secrets','session','fullname','internal','userpic','permissions','md5secret','voicePause','mailPause','smsPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','passwordResetAt','alias','phoneBarDnd','phoneBarEnableDtmfTone','phoneBarExpires','phoneBarRemoteControlPort','hotdesk','interface','userProfileId','settingsEnabled','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','then'];(function(_0x223015,_0x1bbda2){var _0x44f516=function(_0x485918){while(--_0x485918){_0x223015['push'](_0x223015['shift']());}};_0x44f516(++_0x1bbda2);}(_0x7082,0x107));var _0x2708=function(_0x41f4a0,_0x59e659){_0x41f4a0=_0x41f4a0-0x0;var _0x395b4c=_0x7082[_0x41f4a0];return _0x395b4c;};'use strict';var db=require(_0x2708('0x0'))['db'];var config=require(_0x2708('0x1'));var hardwareConf=require('../../config/license/hardware');var licenseUtil=require(_0x2708('0x2'));var encryptor=require(_0x2708('0x3'));var _=require(_0x2708('0x4'));var jwt=require(_0x2708('0x5'));var expressJwt=require(_0x2708('0x6'));var compose=require(_0x2708('0x7'));var basicAuth=require(_0x2708('0x8'));var crypto=require(_0x2708('0x9'));var BPromise=require(_0x2708('0xa'));var util=require(_0x2708('0xb'));var validateJwt=expressJwt({'secret':config[_0x2708('0xc')][_0x2708('0xd')]});var userAttributes=['id','role',_0x2708('0xe'),'name',_0x2708('0xf'),'email',_0x2708('0x10'),_0x2708('0x11'),_0x2708('0x12'),_0x2708('0x13'),'chatPause',_0x2708('0x14'),'faxPause',_0x2708('0x15'),'openchannelPause',_0x2708('0x16'),_0x2708('0x17'),_0x2708('0x18'),_0x2708('0x19'),_0x2708('0x1a'),'allowmessenger',_0x2708('0x1b'),_0x2708('0x1c'),'phoneBarAutoAnswer','phoneBarAutoAnswerDelay',_0x2708('0x1d'),'phoneBarEnableRecording',_0x2708('0x1e'),'phoneBarEnableSettings',_0x2708('0x1f'),'phoneBarPrefixRequired','phoneBarRemoteControl',_0x2708('0x20'),_0x2708('0x21'),_0x2708('0x22'),_0x2708('0x23'),_0x2708('0x24')];exports['isChatInteractionAuthorized']=function(){return this[_0x2708('0x25')](!![])[_0x2708('0x26')](function(_0x2361fb,_0x38c927,_0x20afc3){if(_0x2361fb[_0x2708('0x27')]){_0x20afc3();}else{return db[_0x2708('0x28')][_0x2708('0x29')]({'where':{'id':_0x2361fb[_0x2708('0x2a')]['id']},'attributes':['id',_0x2708('0x2b'),_0x2708('0x2c')],'raw':!![]})[_0x2708('0x2d')](function(_0x5caa4d){if(_0x5caa4d&&_0x5caa4d[_0x2708('0x2b')]){return _0x38c927[_0x2708('0x2e')](_0x5caa4d[_0x2708('0x2c')]===_0x2708('0x2f')?0x195:0x193)[_0x2708('0x30')]({'message':_0x5caa4d[_0x2708('0x2c')]===_0x2708('0x2f')?'Unmanaged.':_0x2708('0x31')});}else{_0x20afc3();}})[_0x2708('0x32')](function(_0x2899df){_0x20afc3(_0x2899df);});}});};exports[_0x2708('0x25')]=function isAuthenticated(_0x17f98b){return compose()[_0x2708('0x26')](function(_0x10a96f,_0x17d8a7,_0x2da7e1){if(_0x10a96f[_0x2708('0x33')][_0x2708('0x34')]){if(_[_0x2708('0x35')](_0x10a96f[_0x2708('0x33')]['authorization'],_0x2708('0x36'))){var _0x525288=basicAuth(_0x10a96f);db[_0x2708('0x37')]['find']({'where':{'name':_0x525288[_0x2708('0x38')]}})[_0x2708('0x2d')](function(_0x3cfa82){if(!_0x3cfa82||!_0x3cfa82[_0x2708('0x39')](_0x525288['pass'])){return _0x17d8a7[_0x2708('0x2e')](0x191)['json']({'message':_0x2708('0x3a')});}_0x10a96f[_0x2708('0x27')]={'id':_0x3cfa82['id']};_0x2da7e1();})[_0x2708('0x32')](function(_0x335b38){_0x2da7e1(_0x335b38);});}else if(_[_0x2708('0x35')](_0x10a96f[_0x2708('0x33')][_0x2708('0x34')],_0x2708('0x3b'))){validateJwt(_0x10a96f,_0x17d8a7,_0x2da7e1);}else{if(_0x17f98b){_0x2da7e1();}else{return _0x17d8a7[_0x2708('0x2e')](0x193)[_0x2708('0x30')]({'message':_0x2708('0x3c')});}}}else if(_0x10a96f[_0x2708('0x3d')]['apikey']){try{var _0x2efc70={'audience':hardwareConf[_0x2708('0x3e')](),'issuer':hardwareConf[_0x2708('0x3e')]()};verifyJwt(_0x10a96f[_0x2708('0x3d')]['apikey'],_0x2efc70)[_0x2708('0x2d')](function(_0x73caf7){return db[_0x2708('0x37')][_0x2708('0x3f')]({'where':{'id':_0x73caf7[_0x2708('0x40')]}})[_0x2708('0x2d')](function(_0x2ee937){if(!_0x2ee937||!_[_0x2708('0x41')](_0x2ee937[_0x2708('0x42')],_0x73caf7['nonce'])){return _0x17d8a7[_0x2708('0x2e')](0x191)['json']({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}_0x10a96f[_0x2708('0x27')]={'id':_0x2ee937['id']};_0x2da7e1();});})[_0x2708('0x32')](function(){return _0x17d8a7[_0x2708('0x2e')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x29436b){_0x2da7e1(_0x29436b);}}else if(_0x17f98b){_0x2da7e1();}else{return _0x17d8a7[_0x2708('0x2e')](0x193)[_0x2708('0x30')]({'message':_0x2708('0x3c')});}})['use'](function(_0x561723,_0x3a55fa,_0x348cbd){if(_0x561723['user']){db[_0x2708('0x37')][_0x2708('0x3f')]({'where':{'id':_0x561723[_0x2708('0x27')]['id']},'attributes':userAttributes})['then'](function(_0x26628d){if(!_0x26628d){return _0x3a55fa[_0x2708('0x2e')](0x194)[_0x2708('0x30')]({'message':'User\x20not\x20found.'});}_0x561723[_0x2708('0x27')]=_0x26628d;_0x348cbd();})[_0x2708('0x32')](function(_0x43a15d){_0x348cbd(_0x43a15d);});}else if(_0x17f98b){_0x348cbd();}else{return _0x3a55fa[_0x2708('0x2e')](0x194)[_0x2708('0x30')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x2708('0x43')]=function canUpdate(){return compose()[_0x2708('0x26')](function(_0x132564,_0x524495,_0x31b852){return licenseUtil[_0x2708('0x44')]()[_0x2708('0x2d')](function(_0x4b0412){if(_0x4b0412['update']){_0x31b852();}else{return _0x524495['status'](0x193)['json']({'message':_0x2708('0x45')});}})[_0x2708('0x32')](function(_0x58b4c9){_0x31b852(_0x58b4c9);});});};exports['isMiddleware']=function(_0x34bca8,_0x5e28d4,_0x28c622){_0x34bca8[_0x2708('0x46')]=!![];return _0x28c622();};exports['signToken']=function signToken(_0x47598e){return signJwt(_0x47598e);};exports[_0x2708('0x47')]=function(_0x3fe925,_0xe01e7f){if(!_0x3fe925['user']){return _0xe01e7f[_0x2708('0x2e')](0x194)['json']({'message':_0x2708('0x48')});}var _0x568bb9={'payload':{'id':_0x3fe925[_0x2708('0x27')]['id'],'role':_0x3fe925[_0x2708('0x27')][_0x2708('0x49')]},'options':{'expiresIn':0x15180}};return signJwt(_0x568bb9)[_0x2708('0x2d')](function(_0x4ec0cf){_0xe01e7f[_0x2708('0x4a')]('motion.token',_0x4ec0cf);_0xe01e7f['redirect'](_0x2708('0x4b'));})[_0x2708('0x32')](function(_0x7f6ca8){return _0xe01e7f[_0x2708('0x2e')](0x1f4)['send'](_0x7f6ca8);});};exports[_0x2708('0x4c')]=function(_0x3935cb){if(_[_0x2708('0x4d')](_0x3935cb[_0x2708('0x42')])||_[_0x2708('0x4d')](_0x3935cb[_0x2708('0x4e')])){return null;}else{return createJwt(_0x3935cb);}};exports[_0x2708('0x4f')]=function(_0x312e8a){_0x312e8a[_0x2708('0x42')]=generateNonce();_0x312e8a[_0x2708('0x4e')]=generateIssuedAt();return createJwt(_0x312e8a);};exports[_0x2708('0x50')]=function(_0x1e2bc7,_0x1f18f1){var _0x648a0f=_0x1e2bc7[_0x2708('0x3d')][_0x2708('0x51')];if(_0x648a0f){var _0x29b99f={'nonce':_0x1f18f1[_0x2708('0x42')],'iat':_0x1f18f1[_0x2708('0x4e')],'audience':hardwareConf[_0x2708('0x3e')](),'issuer':hardwareConf[_0x2708('0x3e')]()};return verifyJwt(_0x648a0f,_0x29b99f)[_0x2708('0x2d')](function(){return generateApiKey(_0x1f18f1);});}else{throw{'message':_0x2708('0x52')};}};exports['validatePasswordPattern']=function(_0x5934c4){var _0x5c2cc2=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x5c2cc2[_0x2708('0x53')](_0x5934c4))throw new db[(_0x2708('0x54'))]['ValidationError'](_0x2708('0x55'));return;};exports[_0x2708('0x56')]=function(_0x95c585,_0x48f10b,_0x22fe5e){var _0x2f4031=encryptor['decryptString'](_0x48f10b)[_0x2708('0x57')](',');for(var _0x341318=0x0;_0x341318<_0x22fe5e;_0x341318++){if(!_0x2f4031[_0x341318])break;if(_0x95c585['toLowerCase']()===_0x2f4031[_0x341318][_0x2708('0x58')]()){var _0x437b4b=util[_0x2708('0x59')]('The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.',_0x22fe5e);if(_0x22fe5e===0x1){_0x437b4b='The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.';}throw new db[(_0x2708('0x54'))]['ValidationError'](_0x437b4b);}}return;};exports['updatePasswordsHistory']=function(_0x2d79c5,_0x514566){var _0x224f25=_0x514566?encryptor[_0x2708('0x5a')](_0x514566)[_0x2708('0x57')](','):[];if(_0x224f25[_0x2708('0x5b')]===0x5){_0x224f25[_0x2708('0x5c')](-0x1,0x1);}_0x224f25[_0x2708('0x5d')](_0x2d79c5);return encryptor['encryptString'](_0x224f25['join'](','));};function signJwt(_0x48f972){var _0x2db52e=BPromise['promisify'](jwt['sign'],{'context':jwt});var _0x12e7c5=_0x48f972[_0x2708('0x5e')]||config['secrets'][_0x2708('0xd')];return new BPromise(function(_0x434e96,_0x46ea61){_0x2db52e(_0x48f972[_0x2708('0x5f')],_0x12e7c5,_0x48f972[_0x2708('0x60')])[_0x2708('0x2d')](function(_0x46e7be){_0x434e96(_0x46e7be);})[_0x2708('0x32')](function(_0x9b5025){_0x46ea61(_0x9b5025);});});}function verifyJwt(_0x39eca0,_0x2bd6d2,_0x1b33aa){var _0x1f96a5=BPromise[_0x2708('0x61')](jwt[_0x2708('0x62')],{'context':jwt});var _0x45e07e=_0x1b33aa||config[_0x2708('0xc')][_0x2708('0xd')];return new BPromise(function(_0x1df6d8,_0x27f9cc){_0x1f96a5(_0x39eca0,_0x45e07e,_0x2bd6d2)[_0x2708('0x2d')](function(_0x2b5957){_0x1df6d8(_0x2b5957);})[_0x2708('0x32')](function(_0x2ebe9b){_0x27f9cc(_0x2ebe9b);});});}function generateNonce(){return crypto[_0x2708('0x63')](0x10)[_0x2708('0x64')](_0x2708('0x65'));}function generateIssuedAt(){return Math['floor'](Date[_0x2708('0x66')]()/0x3e8)[_0x2708('0x64')]();}function createJwt(_0x555694){var _0x1fae2f={'payload':{'iat':_0x555694['apiKeyIat'],'nonce':_0x555694[_0x2708('0x42')]},'options':{'algorithm':'HS512','subject':_0x555694['id']['toString'](),'issuer':hardwareConf['getUuid'](),'audience':hardwareConf[_0x2708('0x3e')]()}};return signJwt(_0x1fae2f)[_0x2708('0x2d')](function(_0x498dcd){return{'iat':_0x555694[_0x2708('0x4e')],'nonce':_0x555694['apiKeyNonce'],'token':_0x498dcd};});}