Built motion from commit c738b9ac.|2.6.25
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0x9855=['role','internal','userpic','permissions','md5secret','chatPause','openchannelPause','pauseType','showWebBar','lastLoginAt','lastPauseAt','crudPermissions','allowmessenger','passwordResetAt','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarEnableRecording','phoneBarEnableDtmfTone','phoneBarPrefixRequired','phoneBarRemoteControl','hotdesk','interface','userProfileId','privacyEnabled','settingsEnabled','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','ignorePauseForPreviewCalls','chatAutoanswer','chatAutoanswerDelay','emailAutoanswerDelay','smsAutoanswer','smsAutoanswerDelay','openchannelAutoanswer','openchannelAutoanswerDelay','faxAutoanswer','messengerSoundNotification','isChatInteractionAuthorized','isAuthenticated','use','user','ChatInteraction','findOne','closed','forceDownload','status','unmanaged','json','disposition','Unmanaged.','Forbidden.','headers','authorization','find','name','then','pass','Wrong\x20credentials.','catch','startsWith','Bearer','Unknown\x20authorization\x20format','query','User','sub','Setting','allowedLoginAttempts','blockDuration','isEqual','apiKeyNonce','nonce','disabled','Invalid\x20API\x20access\x20key','blocked','add','minutes','User\x20not\x20found.','canUpdate','update','Forbidden','isWebrtcLicence','isMiddleware','signToken','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','cookie','motion.token','/dashboards/general','send','isNil','apiKeyIat','generateApiKey','regenerateApiKey','apikey','getUuid','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','test','Sequelize','ValidationError','decryptString','split','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','length','splice','encryptString','secret','options','promisify','randomBytes','toString','hex','now','HS512','../../mysqldb','../../config/license/hardware','../../config/license/util','../encryptor','lodash','express-jwt','basic-auth','bluebird','moment','secrets','session'];(function(_0x293455,_0xe11128){var _0x306819=function(_0x148af8){while(--_0x148af8){_0x293455['push'](_0x293455['shift']());}};_0x306819(++_0xe11128);}(_0x9855,0x175));var _0x5985=function(_0x56afe,_0x3a781a){_0x56afe=_0x56afe-0x0;var _0x1a15a2=_0x9855[_0x56afe];return _0x1a15a2;};'use strict';var db=require(_0x5985('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require(_0x5985('0x1'));var licenseUtil=require(_0x5985('0x2'));var encryptor=require(_0x5985('0x3'));var _=require(_0x5985('0x4'));var jwt=require('jsonwebtoken');var expressJwt=require(_0x5985('0x5'));var compose=require('composable-middleware');var basicAuth=require(_0x5985('0x6'));var crypto=require('crypto');var BPromise=require(_0x5985('0x7'));var util=require('util');var moment=require(_0x5985('0x8'));var validateJwt=expressJwt({'secret':config[_0x5985('0x9')][_0x5985('0xa')]});var userAttributes=['id',_0x5985('0xb'),'fullname','name',_0x5985('0xc'),'email',_0x5985('0xd'),_0x5985('0xe'),_0x5985('0xf'),'voicePause',_0x5985('0x10'),'mailPause','faxPause','smsPause',_0x5985('0x11'),_0x5985('0x12'),_0x5985('0x13'),_0x5985('0x14'),_0x5985('0x15'),_0x5985('0x16'),_0x5985('0x17'),_0x5985('0x18'),'alias',_0x5985('0x19'),_0x5985('0x1a'),'phoneBarDnd',_0x5985('0x1b'),_0x5985('0x1c'),'phoneBarEnableSettings','phoneBarExpires',_0x5985('0x1d'),_0x5985('0x1e'),'phoneBarRemoteControlPort',_0x5985('0x1f'),_0x5985('0x20'),_0x5985('0x21'),_0x5985('0x22'),_0x5985('0x23'),'wssPort',_0x5985('0x24'),_0x5985('0x25'),_0x5985('0x26'),_0x5985('0x27'),'selectRecallMeCampaign',_0x5985('0x28'),_0x5985('0x29'),'emailAutoanswer',_0x5985('0x2a'),_0x5985('0x2b'),_0x5985('0x2c'),_0x5985('0x2d'),_0x5985('0x2e'),_0x5985('0x2f'),'faxAutoanswerDelay','whatsappAutoanswer','whatsappAutoanswerDelay',_0x5985('0x30')];exports[_0x5985('0x31')]=function(){return this[_0x5985('0x32')](!![])[_0x5985('0x33')](function(_0x1ba53a,_0x126e8a,_0x52ab0a){if(_0x1ba53a[_0x5985('0x34')]){_0x52ab0a();}else{return db[_0x5985('0x35')][_0x5985('0x36')]({'where':{'id':_0x1ba53a['params']['id']},'attributes':['id',_0x5985('0x37'),'disposition'],'raw':!![]})['then'](function(_0x1316e9){if(_0x1316e9&&_0x1316e9[_0x5985('0x37')]&&!_0x1ba53a['query'][_0x5985('0x38')]){return _0x126e8a[_0x5985('0x39')](_0x1316e9['disposition']===_0x5985('0x3a')?0x195:0x193)[_0x5985('0x3b')]({'message':_0x1316e9[_0x5985('0x3c')]==='unmanaged'?_0x5985('0x3d'):_0x5985('0x3e')});}else{_0x52ab0a();}})['catch'](function(_0x3047cb){_0x52ab0a(_0x3047cb);});}});};exports[_0x5985('0x32')]=function isAuthenticated(_0x45c96b){return compose()['use'](function(_0x5f25da,_0x58affa,_0xbb4278){var _0x36c415;if(_0x5f25da[_0x5985('0x3f')]['authorization']){if(_['startsWith'](_0x5f25da[_0x5985('0x3f')][_0x5985('0x40')],'Basic')){var _0x515675=basicAuth(_0x5f25da);db['User'][_0x5985('0x41')]({'where':{'name':_0x515675[_0x5985('0x42')]}})[_0x5985('0x43')](function(_0x125b04){if(!_0x125b04||!_0x125b04['authenticate'](_0x515675[_0x5985('0x44')])){return _0x58affa[_0x5985('0x39')](0x191)['json']({'message':_0x5985('0x45')});}_0x5f25da['user']={'id':_0x125b04['id']};_0xbb4278();})[_0x5985('0x46')](function(_0x105d70){_0xbb4278(_0x105d70);});}else if(_[_0x5985('0x47')](_0x5f25da[_0x5985('0x3f')][_0x5985('0x40')],_0x5985('0x48'))){validateJwt(_0x5f25da,_0x58affa,_0xbb4278);}else{if(_0x45c96b){_0xbb4278();}else{return _0x58affa['status'](0x193)[_0x5985('0x3b')]({'message':_0x5985('0x49')});}}}else if(_0x5f25da['query']['apikey']){try{var _0x44f852={'audience':hardwareConf['getUuid'](),'issuer':hardwareConf['getUuid']()};verifyJwt(_0x5f25da[_0x5985('0x4a')]['apikey'],_0x44f852)['then'](function(_0xc44338){return db[_0x5985('0x4b')][_0x5985('0x41')]({'where':{'id':_0xc44338[_0x5985('0x4c')]}})[_0x5985('0x43')](function(_0x26f449){_0x36c415=_0x26f449;return db[_0x5985('0x4d')][_0x5985('0x36')]({'where':{'id':0x1},'attributes':[_0x5985('0x4e'),_0x5985('0x4f')],'raw':!![]});})[_0x5985('0x43')](function(_0x45538b){if(!_0x36c415||!_[_0x5985('0x50')](_0x36c415[_0x5985('0x51')],_0xc44338[_0x5985('0x52')])){return _0x58affa[_0x5985('0x39')](0x191)[_0x5985('0x3b')]({'message':'API\x20access\x20key\x20is\x20not\x20valid\x20anymore'});}if(_0x36c415[_0x5985('0x53')]){return _0x58affa[_0x5985('0x39')](0x191)[_0x5985('0x3b')]({'message':_0x5985('0x54')});}if(_0x36c415[_0x5985('0x55')]){if(_0x45538b[_0x5985('0x4f')]>0x0){if(moment(_0x36c415['blockedAt'])[_0x5985('0x56')](_0x45538b[_0x5985('0x4f')],_0x5985('0x57'))>moment()){return _0x58affa['status'](0x191)[_0x5985('0x3b')]({'message':_0x5985('0x54')});}}else{return _0x58affa[_0x5985('0x39')](0x191)[_0x5985('0x3b')]({'message':_0x5985('0x54')});}}_0x5f25da[_0x5985('0x34')]={'id':_0x36c415['id']};_0xbb4278();});})[_0x5985('0x46')](function(){return _0x58affa[_0x5985('0x39')](0x191)['json']({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x7de618){_0xbb4278(_0x7de618);}}else if(_0x45c96b){_0xbb4278();}else{return _0x58affa[_0x5985('0x39')](0x193)['json']({'message':'Unknown\x20authorization\x20format'});}})['use'](function(_0x48925f,_0x50e2c5,_0x3f45e1){if(_0x48925f['user']){db[_0x5985('0x4b')]['find']({'where':{'id':_0x48925f[_0x5985('0x34')]['id']},'attributes':userAttributes})[_0x5985('0x43')](function(_0x27ecbd){if(!_0x27ecbd){return _0x50e2c5[_0x5985('0x39')](0x194)[_0x5985('0x3b')]({'message':_0x5985('0x58')});}_0x48925f[_0x5985('0x34')]=_0x27ecbd;_0x3f45e1();})[_0x5985('0x46')](function(_0x2f85f5){_0x3f45e1(_0x2f85f5);});}else if(_0x45c96b){_0x3f45e1();}else{return _0x50e2c5[_0x5985('0x39')](0x194)[_0x5985('0x3b')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x5985('0x59')]=function canUpdate(){return compose()[_0x5985('0x33')](function(_0xa83268,_0x4f24cf,_0x3ca129){return licenseUtil['getLicense']()[_0x5985('0x43')](function(_0x3087a8){if(_0x3087a8[_0x5985('0x5a')]){_0x3ca129();}else{return _0x4f24cf['status'](0x193)[_0x5985('0x3b')]({'message':_0x5985('0x5b')});}})[_0x5985('0x46')](function(_0x511a76){_0x3ca129(_0x511a76);});});};exports[_0x5985('0x5c')]=function isWebrtcLicence(){return compose()['use'](function(_0x5b5d92,_0x1ec1de,_0x2be676){return licenseUtil['getLicense']()[_0x5985('0x43')](function(_0x2059d2){if(_0x2059d2['webrtc']){_0x2be676();}else{return _0x1ec1de['status'](0x193)[_0x5985('0x3b')]({'message':'Forbidden'});}})[_0x5985('0x46')](function(_0x372cd2){_0x2be676(_0x372cd2);});});};exports[_0x5985('0x5d')]=function(_0x1a0f83,_0x53152e,_0x20c55b){_0x1a0f83['isMiddleware']=!![];return _0x20c55b();};exports[_0x5985('0x5e')]=function signToken(_0x2bf9be){return signJwt(_0x2bf9be);};exports[_0x5985('0x5f')]=function(_0x54cb96,_0x4091ea){if(!_0x54cb96[_0x5985('0x34')]){return _0x4091ea[_0x5985('0x39')](0x194)[_0x5985('0x3b')]({'message':_0x5985('0x60')});}var _0x2dce84={'payload':{'id':_0x54cb96[_0x5985('0x34')]['id'],'role':_0x54cb96[_0x5985('0x34')][_0x5985('0xb')]},'options':{'expiresIn':0x15180}};return signJwt(_0x2dce84)[_0x5985('0x43')](function(_0x51a21e){_0x4091ea[_0x5985('0x61')](_0x5985('0x62'),_0x51a21e);_0x4091ea['redirect'](_0x5985('0x63'));})[_0x5985('0x46')](function(_0x3b627e){return _0x4091ea[_0x5985('0x39')](0x1f4)[_0x5985('0x64')](_0x3b627e);});};exports['retrieveApiKey']=function(_0x40008c){if(_[_0x5985('0x65')](_0x40008c[_0x5985('0x51')])||_['isNil'](_0x40008c[_0x5985('0x66')])){return null;}else{return createJwt(_0x40008c);}};exports[_0x5985('0x67')]=function(_0x20f433){_0x20f433[_0x5985('0x51')]=generateNonce();_0x20f433[_0x5985('0x66')]=generateIssuedAt();return createJwt(_0x20f433);};exports[_0x5985('0x68')]=function(_0x780a3,_0x407174){var _0x3ac0b7=_0x780a3[_0x5985('0x4a')][_0x5985('0x69')];if(_0x3ac0b7){var _0x27dd4a={'nonce':_0x407174[_0x5985('0x51')],'iat':_0x407174[_0x5985('0x66')],'audience':hardwareConf[_0x5985('0x6a')](),'issuer':hardwareConf[_0x5985('0x6a')]()};return verifyJwt(_0x3ac0b7,_0x27dd4a)[_0x5985('0x43')](function(){return generateApiKey(_0x407174);});}else{throw{'message':_0x5985('0x6b')};}};exports['validatePasswordPattern']=function(_0x2fb838){var _0x52108b=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x52108b[_0x5985('0x6c')](_0x2fb838))throw new db[(_0x5985('0x6d'))][(_0x5985('0x6e'))]('The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.');return;};exports['validatePasswordHistory']=function(_0x29a8c6,_0x1112b5,_0x4e6d21){var _0x32fd86=encryptor[_0x5985('0x6f')](_0x1112b5)[_0x5985('0x70')](',');for(var _0x1e9be8=0x0;_0x1e9be8<_0x4e6d21;_0x1e9be8++){if(!_0x32fd86[_0x1e9be8])break;if(_0x29a8c6[_0x5985('0x71')]()===_0x32fd86[_0x1e9be8][_0x5985('0x71')]()){var _0x29097d=util[_0x5985('0x72')](_0x5985('0x73'),_0x4e6d21);if(_0x4e6d21===0x1){_0x29097d=_0x5985('0x74');}throw new db['Sequelize'][(_0x5985('0x6e'))](_0x29097d);}}return;};exports['updatePasswordsHistory']=function(_0x27d971,_0x1f7e6f){var _0x124757=_0x1f7e6f?encryptor['decryptString'](_0x1f7e6f)[_0x5985('0x70')](','):[];if(_0x124757[_0x5985('0x75')]===0x5){_0x124757[_0x5985('0x76')](-0x1,0x1);}_0x124757['unshift'](_0x27d971);return encryptor[_0x5985('0x77')](_0x124757['join'](','));};function signJwt(_0x3a3362){var _0x50d0d9=BPromise['promisify'](jwt['sign'],{'context':jwt});var _0x5d2391=_0x3a3362[_0x5985('0x78')]||config[_0x5985('0x9')][_0x5985('0xa')];return new BPromise(function(_0x4684f8,_0x3edfa8){_0x50d0d9(_0x3a3362['payload'],_0x5d2391,_0x3a3362[_0x5985('0x79')])[_0x5985('0x43')](function(_0x41c8d7){_0x4684f8(_0x41c8d7);})[_0x5985('0x46')](function(_0x360eb2){_0x3edfa8(_0x360eb2);});});}function verifyJwt(_0x4c00bf,_0x4f7f60,_0x1d5827){var _0x598141=BPromise[_0x5985('0x7a')](jwt['verify'],{'context':jwt});var _0x5521e8=_0x1d5827||config[_0x5985('0x9')]['session'];return new BPromise(function(_0x3895b5,_0x3cb780){_0x598141(_0x4c00bf,_0x5521e8,_0x4f7f60)[_0x5985('0x43')](function(_0x15d8e8){_0x3895b5(_0x15d8e8);})[_0x5985('0x46')](function(_0x505201){_0x3cb780(_0x505201);});});}function generateNonce(){return crypto[_0x5985('0x7b')](0x10)[_0x5985('0x7c')](_0x5985('0x7d'));}function generateIssuedAt(){return Math['floor'](Date[_0x5985('0x7e')]()/0x3e8)[_0x5985('0x7c')]();}function createJwt(_0x52632d){var _0x5b3d35={'payload':{'iat':_0x52632d[_0x5985('0x66')],'nonce':_0x52632d[_0x5985('0x51')]},'options':{'algorithm':_0x5985('0x7f'),'subject':_0x52632d['id'][_0x5985('0x7c')](),'issuer':hardwareConf[_0x5985('0x6a')](),'audience':hardwareConf[_0x5985('0x6a')]()}};return signJwt(_0x5b3d35)[_0x5985('0x43')](function(_0x481f6a){return{'iat':_0x52632d[_0x5985('0x66')],'nonce':_0x52632d[_0x5985('0x51')],'token':_0x481f6a};});}