faf2957bfd7e0f6848351456ce3010904c001caf
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x3e74=['User\x20not\x20found.','User\x20object\x20not\x20found.','getLicense','update','Forbidden','isMiddleware','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','isNil','apiKeyNonce','apiKeyIat','generateApiKey','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','validatePasswordHistory','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','split','length','splice','unshift','encryptString','join','promisify','secret','secrets','payload','verify','randomBytes','toString','hex','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','express-jwt','basic-auth','crypto','bluebird','util','moment','session','role','fullname','name','internal','userpic','voicePause','chatPause','faxPause','openchannelPause','pauseType','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableSettings','phoneBarExpires','phoneBarPrefixRequired','phoneBarRemoteControl','interface','userProfileId','privacyEnabled','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','params','closed','disposition','unmanaged','json','Unmanaged.','catch','authorization','startsWith','headers','User','then','authenticate','status','Wrong\x20credentials.','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','find','sub','allowedLoginAttempts','blockDuration','isEqual','blocked','blockedAt','add','minutes','Invalid\x20API\x20access\x20key'];(function(_0x42d6eb,_0x53d001){var _0x3c360b=function(_0x44fafe){while(--_0x44fafe){_0x42d6eb['push'](_0x42d6eb['shift']());}};_0x3c360b(++_0x53d001);}(_0x3e74,0x175));var _0x43e7=function(_0x3e88e5,_0x4940ae){_0x3e88e5=_0x3e88e5-0x0;var _0x13cd12=_0x3e74[_0x3e88e5];return _0x13cd12;};'use strict';var db=require(_0x43e7('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x43e7('0x1'));var licenseUtil=require(_0x43e7('0x2'));var encryptor=require(_0x43e7('0x3'));var _=require('lodash');var jwt=require('jsonwebtoken');var expressJwt=require(_0x43e7('0x4'));var compose=require('composable-middleware');var basicAuth=require(_0x43e7('0x5'));var crypto=require(_0x43e7('0x6'));var BPromise=require(_0x43e7('0x7'));var util=require(_0x43e7('0x8'));var moment=require(_0x43e7('0x9'));var validateJwt=expressJwt({'secret':config['secrets'][_0x43e7('0xa')]});var userAttributes=['id',_0x43e7('0xb'),_0x43e7('0xc'),_0x43e7('0xd'),_0x43e7('0xe'),'email',_0x43e7('0xf'),'permissions','md5secret',_0x43e7('0x10'),_0x43e7('0x11'),'mailPause',_0x43e7('0x12'),'smsPause',_0x43e7('0x13'),_0x43e7('0x14'),'showWebBar',_0x43e7('0x15'),_0x43e7('0x16'),_0x43e7('0x17'),_0x43e7('0x18'),'passwordResetAt','alias',_0x43e7('0x19'),_0x43e7('0x1a'),_0x43e7('0x1b'),'phoneBarEnableRecording','phoneBarEnableDtmfTone',_0x43e7('0x1c'),_0x43e7('0x1d'),_0x43e7('0x1e'),_0x43e7('0x1f'),'phoneBarRemoteControlPort','hotdesk',_0x43e7('0x20'),_0x43e7('0x21'),_0x43e7('0x22'),'settingsEnabled','wssPort'];exports[_0x43e7('0x23')]=function(){return this[_0x43e7('0x24')](!![])[_0x43e7('0x25')](function(_0x140657,_0x3776f5,_0x1f24fb){if(_0x140657[_0x43e7('0x26')]){_0x1f24fb();}else{return db[_0x43e7('0x27')][_0x43e7('0x28')]({'where':{'id':_0x140657[_0x43e7('0x29')]['id']},'attributes':['id',_0x43e7('0x2a'),_0x43e7('0x2b')],'raw':!![]})['then'](function(_0xef1a5a){if(_0xef1a5a&&_0xef1a5a[_0x43e7('0x2a')]){return _0x3776f5['status'](_0xef1a5a[_0x43e7('0x2b')]===_0x43e7('0x2c')?0x195:0x193)[_0x43e7('0x2d')]({'message':_0xef1a5a[_0x43e7('0x2b')]===_0x43e7('0x2c')?_0x43e7('0x2e'):'Forbidden.'});}else{_0x1f24fb();}})[_0x43e7('0x2f')](function(_0x4eea52){_0x1f24fb(_0x4eea52);});}});};exports['isAuthenticated']=function isAuthenticated(_0x47204e){return compose()[_0x43e7('0x25')](function(_0x4b2b9f,_0x1f0673,_0x4ca5cf){var _0x326dab;if(_0x4b2b9f['headers'][_0x43e7('0x30')]){if(_[_0x43e7('0x31')](_0x4b2b9f[_0x43e7('0x32')][_0x43e7('0x30')],'Basic')){var _0x52b7b3=basicAuth(_0x4b2b9f);db[_0x43e7('0x33')]['find']({'where':{'name':_0x52b7b3[_0x43e7('0xd')]}})[_0x43e7('0x34')](function(_0x3565cf){if(!_0x3565cf||!_0x3565cf[_0x43e7('0x35')](_0x52b7b3['pass'])){return _0x1f0673[_0x43e7('0x36')](0x191)[_0x43e7('0x2d')]({'message':_0x43e7('0x37')});}_0x4b2b9f[_0x43e7('0x26')]={'id':_0x3565cf['id']};_0x4ca5cf();})[_0x43e7('0x2f')](function(_0x84dd4d){_0x4ca5cf(_0x84dd4d);});}else if(_[_0x43e7('0x31')](_0x4b2b9f[_0x43e7('0x32')][_0x43e7('0x30')],_0x43e7('0x38'))){validateJwt(_0x4b2b9f,_0x1f0673,_0x4ca5cf);}else{if(_0x47204e){_0x4ca5cf();}else{return _0x1f0673[_0x43e7('0x36')](0x193)[_0x43e7('0x2d')]({'message':_0x43e7('0x39')});}}}else if(_0x4b2b9f[_0x43e7('0x3a')]['apikey']){try{var _0x238321={'audience':hardwareConf[_0x43e7('0x3b')](),'issuer':hardwareConf[_0x43e7('0x3b')]()};verifyJwt(_0x4b2b9f[_0x43e7('0x3a')][_0x43e7('0x3c')],_0x238321)['then'](function(_0x1eba65){return db[_0x43e7('0x33')][_0x43e7('0x3d')]({'where':{'id':_0x1eba65[_0x43e7('0x3e')]}})['then'](function(_0x5a7342){_0x326dab=_0x5a7342;return db['Setting'][_0x43e7('0x28')]({'where':{'id':0x1},'attributes':[_0x43e7('0x3f'),_0x43e7('0x40')],'raw':!![]});})[_0x43e7('0x34')](function(_0x108313){if(!_0x326dab||!_[_0x43e7('0x41')](_0x326dab['apiKeyNonce'],_0x1eba65['nonce'])){return _0x1f0673['status'](0x191)['json']({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x326dab['disabled']){return _0x1f0673['status'](0x191)[_0x43e7('0x2d')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x326dab[_0x43e7('0x42')]){if(_0x108313[_0x43e7('0x40')]>0x0){if(moment(_0x326dab[_0x43e7('0x43')])[_0x43e7('0x44')](_0x108313[_0x43e7('0x40')],_0x43e7('0x45'))>moment()){return _0x1f0673[_0x43e7('0x36')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});}}else{return _0x1f0673['status'](0x191)[_0x43e7('0x2d')]({'message':_0x43e7('0x46')});}}_0x4b2b9f[_0x43e7('0x26')]={'id':_0x326dab['id']};_0x4ca5cf();});})[_0x43e7('0x2f')](function(){return _0x1f0673[_0x43e7('0x36')](0x191)[_0x43e7('0x2d')]({'message':_0x43e7('0x46')});});}catch(_0x2ffd43){_0x4ca5cf(_0x2ffd43);}}else if(_0x47204e){_0x4ca5cf();}else{return _0x1f0673['status'](0x193)[_0x43e7('0x2d')]({'message':_0x43e7('0x39')});}})['use'](function(_0x2d54c1,_0x4c0c7a,_0x44d8e4){if(_0x2d54c1[_0x43e7('0x26')]){db[_0x43e7('0x33')][_0x43e7('0x3d')]({'where':{'id':_0x2d54c1[_0x43e7('0x26')]['id']},'attributes':userAttributes})[_0x43e7('0x34')](function(_0x5e731b){if(!_0x5e731b){return _0x4c0c7a['status'](0x194)[_0x43e7('0x2d')]({'message':_0x43e7('0x47')});}_0x2d54c1[_0x43e7('0x26')]=_0x5e731b;_0x44d8e4();})[_0x43e7('0x2f')](function(_0x127d77){_0x44d8e4(_0x127d77);});}else if(_0x47204e){_0x44d8e4();}else{return _0x4c0c7a['status'](0x194)[_0x43e7('0x2d')]({'message':_0x43e7('0x48')});}});};exports['canUpdate']=function canUpdate(){return compose()[_0x43e7('0x25')](function(_0x51a69c,_0x2ad8ef,_0x504101){return licenseUtil[_0x43e7('0x49')]()[_0x43e7('0x34')](function(_0x3a5807){if(_0x3a5807[_0x43e7('0x4a')]){_0x504101();}else{return _0x2ad8ef['status'](0x193)['json']({'message':_0x43e7('0x4b')});}})[_0x43e7('0x2f')](function(_0xe979b5){_0x504101(_0xe979b5);});});};exports[_0x43e7('0x4c')]=function(_0x56346a,_0x583047,_0x5dd988){_0x56346a[_0x43e7('0x4c')]=!![];return _0x5dd988();};exports['signToken']=function signToken(_0x2ab022){return signJwt(_0x2ab022);};exports['setTokenCookie']=function(_0x5b28db,_0x46b2e6){if(!_0x5b28db['user']){return _0x46b2e6[_0x43e7('0x36')](0x194)[_0x43e7('0x2d')]({'message':_0x43e7('0x4d')});}var _0x99b9e1={'payload':{'id':_0x5b28db['user']['id'],'role':_0x5b28db[_0x43e7('0x26')][_0x43e7('0xb')]},'options':{'expiresIn':0x15180}};return signJwt(_0x99b9e1)[_0x43e7('0x34')](function(_0x1fd277){_0x46b2e6[_0x43e7('0x4e')](_0x43e7('0x4f'),_0x1fd277);_0x46b2e6['redirect']('/dashboards/general');})[_0x43e7('0x2f')](function(_0x36a09e){return _0x46b2e6[_0x43e7('0x36')](0x1f4)['send'](_0x36a09e);});};exports['retrieveApiKey']=function(_0x56489b){if(_[_0x43e7('0x50')](_0x56489b[_0x43e7('0x51')])||_['isNil'](_0x56489b[_0x43e7('0x52')])){return null;}else{return createJwt(_0x56489b);}};exports[_0x43e7('0x53')]=function(_0x3c96fe){_0x3c96fe['apiKeyNonce']=generateNonce();_0x3c96fe['apiKeyIat']=generateIssuedAt();return createJwt(_0x3c96fe);};exports['regenerateApiKey']=function(_0x4de644,_0x214e7e){var _0xe955fc=_0x4de644['query'][_0x43e7('0x3c')];if(_0xe955fc){var _0x82d32f={'nonce':_0x214e7e[_0x43e7('0x51')],'iat':_0x214e7e[_0x43e7('0x52')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x43e7('0x3b')]()};return verifyJwt(_0xe955fc,_0x82d32f)['then'](function(){return generateApiKey(_0x214e7e);});}else{throw{'message':'Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one'};}};exports[_0x43e7('0x54')]=function(_0x12f9ba){var _0x22d98e=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x22d98e[_0x43e7('0x55')](_0x12f9ba))throw new db[(_0x43e7('0x56'))][(_0x43e7('0x57'))](_0x43e7('0x58'));return;};exports[_0x43e7('0x59')]=function(_0x473fca,_0x2b5515,_0x58dfd0){var _0x119d34=encryptor[_0x43e7('0x5a')](_0x2b5515)['split'](',');for(var _0x39e3ca=0x0;_0x39e3ca<_0x58dfd0;_0x39e3ca++){if(!_0x119d34[_0x39e3ca])break;if(_0x473fca['toLowerCase']()===_0x119d34[_0x39e3ca][_0x43e7('0x5b')]()){var _0x520857=util[_0x43e7('0x5c')](_0x43e7('0x5d'),_0x58dfd0);if(_0x58dfd0===0x1){_0x520857=_0x43e7('0x5e');}throw new db['Sequelize']['ValidationError'](_0x520857);}}return;};exports[_0x43e7('0x5f')]=function(_0x2ab7ee,_0x399942){var _0x29c53d=_0x399942?encryptor[_0x43e7('0x5a')](_0x399942)[_0x43e7('0x60')](','):[];if(_0x29c53d[_0x43e7('0x61')]===0x5){_0x29c53d[_0x43e7('0x62')](-0x1,0x1);}_0x29c53d[_0x43e7('0x63')](_0x2ab7ee);return encryptor[_0x43e7('0x64')](_0x29c53d[_0x43e7('0x65')](','));};function signJwt(_0x4ace49){var _0x1ec35a=BPromise[_0x43e7('0x66')](jwt['sign'],{'context':jwt});var _0x4314d8=_0x4ace49[_0x43e7('0x67')]||config[_0x43e7('0x68')]['session'];return new BPromise(function(_0x5d63c6,_0x459c13){_0x1ec35a(_0x4ace49[_0x43e7('0x69')],_0x4314d8,_0x4ace49['options'])[_0x43e7('0x34')](function(_0x54506d){_0x5d63c6(_0x54506d);})['catch'](function(_0x1fa3f6){_0x459c13(_0x1fa3f6);});});}function verifyJwt(_0x4b6b7f,_0x1f7c02,_0x40155c){var _0x68697=BPromise['promisify'](jwt[_0x43e7('0x6a')],{'context':jwt});var _0xdb9fbe=_0x40155c||config['secrets'][_0x43e7('0xa')];return new BPromise(function(_0x1267c5,_0x296a0d){_0x68697(_0x4b6b7f,_0xdb9fbe,_0x1f7c02)['then'](function(_0x5a4c95){_0x1267c5(_0x5a4c95);})['catch'](function(_0x2ada55){_0x296a0d(_0x2ada55);});});}function generateNonce(){return crypto[_0x43e7('0x6b')](0x10)[_0x43e7('0x6c')](_0x43e7('0x6d'));}function generateIssuedAt(){return Math['floor'](Date['now']()/0x3e8)[_0x43e7('0x6c')]();}function createJwt(_0x8b50bb){var _0x140438={'payload':{'iat':_0x8b50bb[_0x43e7('0x52')],'nonce':_0x8b50bb['apiKeyNonce']},'options':{'algorithm':_0x43e7('0x6e'),'subject':_0x8b50bb['id'][_0x43e7('0x6c')](),'issuer':hardwareConf[_0x43e7('0x3b')](),'audience':hardwareConf[_0x43e7('0x3b')]()}};return signJwt(_0x140438)[_0x43e7('0x34')](function(_0xd41e79){return{'iat':_0x8b50bb[_0x43e7('0x52')],'nonce':_0x8b50bb[_0x43e7('0x51')],'token':_0xd41e79};});}