fd2f5b020539b15865dcf997d5968cd325147de0
[motion2.git] / server / components / auth / service.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xd2d7=['payload','options','verify','session','randomBytes','hex','floor','toString','../../mysqldb','../../config/license/util','lodash','express-jwt','composable-middleware','basic-auth','crypto','util','moment','secrets','role','fullname','internal','userpic','permissions','md5secret','voicePause','chatPause','openchannelPause','showWebBar','lastLoginAt','crudPermissions','alias','phoneBarAutoAnswer','phoneBarAutoAnswerDelay','phoneBarDnd','phoneBarEnableDtmfTone','phoneBarEnableSettings','phoneBarPrefixRequired','phoneBarRemoteControl','phoneBarRemoteControlPort','userProfileId','privacyEnabled','settingsEnabled','wssPort','downloadVoiceRecordings','downloadOmnichannelInteractions','downloadAttachments','ignorePauseForPreviewCalls','user','ChatInteraction','findOne','closed','disposition','then','status','unmanaged','json','Unmanaged.','Forbidden.','use','authorization','User','find','pass','Wrong\x20credentials.','catch','startsWith','headers','Bearer','Unknown\x20authorization\x20format','query','getUuid','apikey','sub','allowedLoginAttempts','nonce','API\x20access\x20key\x20is\x20not\x20valid\x20anymore','disabled','blocked','blockDuration','blockedAt','add','minutes','Invalid\x20API\x20access\x20key','User\x20not\x20found.','canUpdate','getLicense','update','Forbidden','webrtc','isMiddleware','setTokenCookie','It\x20looks\x20like\x20you\x20aren\x27t\x20logged\x20in,\x20please\x20try\x20again.','motion.token','redirect','retrieveApiKey','isNil','apiKeyIat','apiKeyNonce','regenerateApiKey','Please\x20use\x20the\x20previous\x20API\x20access\x20key\x20to\x20generate\x20a\x20new\x20one','validatePasswordPattern','test','Sequelize','ValidationError','The\x20password\x20must\x20be\x20at\x20least\x208\x20characters\x20long\x20and\x20have\x201\x20lowercase\x20character,\x201\x20uppercase\x20character,\x201\x20number\x20and\x201\x20special\x20character\x20~!@#$%^&-_=+[{]}.','decryptString','toLowerCase','format','The\x20password\x20must\x20be\x20different\x20from\x20the\x20previous\x20%d\x20passwords.\x20Please\x20choose\x20another\x20one.','The\x20password\x20must\x20be\x20different\x20from\x20the\x20last\x20one.\x20Please\x20choose\x20another\x20one.','updatePasswordsHistory','split','length','join','promisify','sign','secret'];(function(_0x4b1d9c,_0x2b95b9){var _0x1a50fd=function(_0x3f29ea){while(--_0x3f29ea){_0x4b1d9c['push'](_0x4b1d9c['shift']());}};_0x1a50fd(++_0x2b95b9);}(_0xd2d7,0x1dc));var _0x7d2d=function(_0x3dd15e,_0x1f0015){_0x3dd15e=_0x3dd15e-0x0;var _0x231fd0=_0xd2d7[_0x3dd15e];return _0x231fd0;};'use strict';var db=require(_0x7d2d('0x0'))['db'];var config=require('../../config/environment');var hardwareConf=require('../../config/license/hardware');var licenseUtil=require(_0x7d2d('0x1'));var encryptor=require('../encryptor');var _=require(_0x7d2d('0x2'));var jwt=require('jsonwebtoken');var expressJwt=require(_0x7d2d('0x3'));var compose=require(_0x7d2d('0x4'));var basicAuth=require(_0x7d2d('0x5'));var crypto=require(_0x7d2d('0x6'));var BPromise=require('bluebird');var util=require(_0x7d2d('0x7'));var moment=require(_0x7d2d('0x8'));var validateJwt=expressJwt({'secret':config[_0x7d2d('0x9')]['session']});var userAttributes=['id',_0x7d2d('0xa'),_0x7d2d('0xb'),'name',_0x7d2d('0xc'),'email',_0x7d2d('0xd'),_0x7d2d('0xe'),_0x7d2d('0xf'),_0x7d2d('0x10'),_0x7d2d('0x11'),'mailPause','faxPause','smsPause',_0x7d2d('0x12'),'pauseType',_0x7d2d('0x13'),_0x7d2d('0x14'),'lastPauseAt',_0x7d2d('0x15'),'allowmessenger','passwordResetAt',_0x7d2d('0x16'),_0x7d2d('0x17'),_0x7d2d('0x18'),_0x7d2d('0x19'),'phoneBarEnableRecording',_0x7d2d('0x1a'),_0x7d2d('0x1b'),'phoneBarExpires',_0x7d2d('0x1c'),_0x7d2d('0x1d'),_0x7d2d('0x1e'),'hotdesk','interface',_0x7d2d('0x1f'),_0x7d2d('0x20'),_0x7d2d('0x21'),_0x7d2d('0x22'),_0x7d2d('0x23'),_0x7d2d('0x24'),_0x7d2d('0x25'),_0x7d2d('0x26'),'selectRecallMeCampaign'];exports['isChatInteractionAuthorized']=function(){return this['isAuthenticated'](!![])['use'](function(_0x1b3984,_0x44191e,_0x1f686c){if(_0x1b3984[_0x7d2d('0x27')]){_0x1f686c();}else{return db[_0x7d2d('0x28')][_0x7d2d('0x29')]({'where':{'id':_0x1b3984['params']['id']},'attributes':['id',_0x7d2d('0x2a'),_0x7d2d('0x2b')],'raw':!![]})[_0x7d2d('0x2c')](function(_0x440d18){if(_0x440d18&&_0x440d18[_0x7d2d('0x2a')]){return _0x44191e[_0x7d2d('0x2d')](_0x440d18['disposition']===_0x7d2d('0x2e')?0x195:0x193)[_0x7d2d('0x2f')]({'message':_0x440d18[_0x7d2d('0x2b')]===_0x7d2d('0x2e')?_0x7d2d('0x30'):_0x7d2d('0x31')});}else{_0x1f686c();}})['catch'](function(_0x234bcb){_0x1f686c(_0x234bcb);});}});};exports['isAuthenticated']=function isAuthenticated(_0x51815a){return compose()[_0x7d2d('0x32')](function(_0x52b165,_0x22f65b,_0x26a0b7){var _0x1e34b1;if(_0x52b165['headers'][_0x7d2d('0x33')]){if(_['startsWith'](_0x52b165['headers'][_0x7d2d('0x33')],'Basic')){var _0x307881=basicAuth(_0x52b165);db[_0x7d2d('0x34')][_0x7d2d('0x35')]({'where':{'name':_0x307881['name']}})['then'](function(_0x124824){if(!_0x124824||!_0x124824['authenticate'](_0x307881[_0x7d2d('0x36')])){return _0x22f65b[_0x7d2d('0x2d')](0x191)[_0x7d2d('0x2f')]({'message':_0x7d2d('0x37')});}_0x52b165[_0x7d2d('0x27')]={'id':_0x124824['id']};_0x26a0b7();})[_0x7d2d('0x38')](function(_0x5833b2){_0x26a0b7(_0x5833b2);});}else if(_[_0x7d2d('0x39')](_0x52b165[_0x7d2d('0x3a')]['authorization'],_0x7d2d('0x3b'))){validateJwt(_0x52b165,_0x22f65b,_0x26a0b7);}else{if(_0x51815a){_0x26a0b7();}else{return _0x22f65b[_0x7d2d('0x2d')](0x193)[_0x7d2d('0x2f')]({'message':_0x7d2d('0x3c')});}}}else if(_0x52b165[_0x7d2d('0x3d')]['apikey']){try{var _0x304504={'audience':hardwareConf[_0x7d2d('0x3e')](),'issuer':hardwareConf[_0x7d2d('0x3e')]()};verifyJwt(_0x52b165[_0x7d2d('0x3d')][_0x7d2d('0x3f')],_0x304504)[_0x7d2d('0x2c')](function(_0x282a8f){return db[_0x7d2d('0x34')]['find']({'where':{'id':_0x282a8f[_0x7d2d('0x40')]}})[_0x7d2d('0x2c')](function(_0xc0ef3b){_0x1e34b1=_0xc0ef3b;return db['Setting'][_0x7d2d('0x29')]({'where':{'id':0x1},'attributes':[_0x7d2d('0x41'),'blockDuration'],'raw':!![]});})[_0x7d2d('0x2c')](function(_0xe8d247){if(!_0x1e34b1||!_['isEqual'](_0x1e34b1['apiKeyNonce'],_0x282a8f[_0x7d2d('0x42')])){return _0x22f65b['status'](0x191)['json']({'message':_0x7d2d('0x43')});}if(_0x1e34b1[_0x7d2d('0x44')]){return _0x22f65b[_0x7d2d('0x2d')](0x191)[_0x7d2d('0x2f')]({'message':'Invalid\x20API\x20access\x20key'});}if(_0x1e34b1[_0x7d2d('0x45')]){if(_0xe8d247[_0x7d2d('0x46')]>0x0){if(moment(_0x1e34b1[_0x7d2d('0x47')])[_0x7d2d('0x48')](_0xe8d247[_0x7d2d('0x46')],_0x7d2d('0x49'))>moment()){return _0x22f65b[_0x7d2d('0x2d')](0x191)[_0x7d2d('0x2f')]({'message':'Invalid\x20API\x20access\x20key'});}}else{return _0x22f65b[_0x7d2d('0x2d')](0x191)[_0x7d2d('0x2f')]({'message':_0x7d2d('0x4a')});}}_0x52b165[_0x7d2d('0x27')]={'id':_0x1e34b1['id']};_0x26a0b7();});})[_0x7d2d('0x38')](function(){return _0x22f65b[_0x7d2d('0x2d')](0x191)[_0x7d2d('0x2f')]({'message':'Invalid\x20API\x20access\x20key'});});}catch(_0x5c0abc){_0x26a0b7(_0x5c0abc);}}else if(_0x51815a){_0x26a0b7();}else{return _0x22f65b[_0x7d2d('0x2d')](0x193)[_0x7d2d('0x2f')]({'message':'Unknown\x20authorization\x20format'});}})[_0x7d2d('0x32')](function(_0x2c98e9,_0x1867d2,_0x9a07eb){if(_0x2c98e9[_0x7d2d('0x27')]){db[_0x7d2d('0x34')][_0x7d2d('0x35')]({'where':{'id':_0x2c98e9['user']['id']},'attributes':userAttributes})['then'](function(_0x5730ab){if(!_0x5730ab){return _0x1867d2[_0x7d2d('0x2d')](0x194)['json']({'message':_0x7d2d('0x4b')});}_0x2c98e9[_0x7d2d('0x27')]=_0x5730ab;_0x9a07eb();})[_0x7d2d('0x38')](function(_0x4969c5){_0x9a07eb(_0x4969c5);});}else if(_0x51815a){_0x9a07eb();}else{return _0x1867d2[_0x7d2d('0x2d')](0x194)[_0x7d2d('0x2f')]({'message':'User\x20object\x20not\x20found.'});}});};exports[_0x7d2d('0x4c')]=function canUpdate(){return compose()[_0x7d2d('0x32')](function(_0x30544d,_0x2c9eed,_0x47700f){return licenseUtil[_0x7d2d('0x4d')]()[_0x7d2d('0x2c')](function(_0x1d64dd){if(_0x1d64dd[_0x7d2d('0x4e')]){_0x47700f();}else{return _0x2c9eed[_0x7d2d('0x2d')](0x193)['json']({'message':_0x7d2d('0x4f')});}})['catch'](function(_0xc31784){_0x47700f(_0xc31784);});});};exports['isWebrtcLicence']=function isWebrtcLicence(){return compose()[_0x7d2d('0x32')](function(_0x34ecd5,_0x184200,_0x49247b){return licenseUtil[_0x7d2d('0x4d')]()[_0x7d2d('0x2c')](function(_0x3780c9){if(_0x3780c9[_0x7d2d('0x50')]){_0x49247b();}else{return _0x184200[_0x7d2d('0x2d')](0x193)[_0x7d2d('0x2f')]({'message':_0x7d2d('0x4f')});}})[_0x7d2d('0x38')](function(_0xd48a28){_0x49247b(_0xd48a28);});});};exports[_0x7d2d('0x51')]=function(_0x1998ed,_0x127bd3,_0x55e720){_0x1998ed[_0x7d2d('0x51')]=!![];return _0x55e720();};exports['signToken']=function signToken(_0x2eb1b1){return signJwt(_0x2eb1b1);};exports[_0x7d2d('0x52')]=function(_0x1daf38,_0x4d28d3){if(!_0x1daf38['user']){return _0x4d28d3[_0x7d2d('0x2d')](0x194)[_0x7d2d('0x2f')]({'message':_0x7d2d('0x53')});}var _0x1d8021={'payload':{'id':_0x1daf38['user']['id'],'role':_0x1daf38[_0x7d2d('0x27')][_0x7d2d('0xa')]},'options':{'expiresIn':0x15180}};return signJwt(_0x1d8021)['then'](function(_0x1de3ed){_0x4d28d3['cookie'](_0x7d2d('0x54'),_0x1de3ed);_0x4d28d3[_0x7d2d('0x55')]('/dashboards/general');})['catch'](function(_0x929b40){return _0x4d28d3[_0x7d2d('0x2d')](0x1f4)['send'](_0x929b40);});};exports[_0x7d2d('0x56')]=function(_0x534f96){if(_[_0x7d2d('0x57')](_0x534f96['apiKeyNonce'])||_[_0x7d2d('0x57')](_0x534f96[_0x7d2d('0x58')])){return null;}else{return createJwt(_0x534f96);}};exports['generateApiKey']=function(_0x2a4c66){_0x2a4c66[_0x7d2d('0x59')]=generateNonce();_0x2a4c66['apiKeyIat']=generateIssuedAt();return createJwt(_0x2a4c66);};exports[_0x7d2d('0x5a')]=function(_0x4da077,_0x1f56dd){var _0x25a773=_0x4da077[_0x7d2d('0x3d')][_0x7d2d('0x3f')];if(_0x25a773){var _0x412e57={'nonce':_0x1f56dd[_0x7d2d('0x59')],'iat':_0x1f56dd[_0x7d2d('0x58')],'audience':hardwareConf['getUuid'](),'issuer':hardwareConf[_0x7d2d('0x3e')]()};return verifyJwt(_0x25a773,_0x412e57)['then'](function(){return generateApiKey(_0x1f56dd);});}else{throw{'message':_0x7d2d('0x5b')};}};exports[_0x7d2d('0x5c')]=function(_0x14ad47){var _0x3a2f5d=new RegExp(/(?=.*[a-z])(?=.*[A-Z])(?=.*[0-9])(?=.*[?!@#\$%\^&\*~\-_=+[{\]\}])(?=.{8,})/);if(!_0x3a2f5d[_0x7d2d('0x5d')](_0x14ad47))throw new db[(_0x7d2d('0x5e'))][(_0x7d2d('0x5f'))](_0x7d2d('0x60'));return;};exports['validatePasswordHistory']=function(_0x1d0f7f,_0x3fa100,_0x5c101f){var _0x1a050b=encryptor[_0x7d2d('0x61')](_0x3fa100)['split'](',');for(var _0x4c58f2=0x0;_0x4c58f2<_0x5c101f;_0x4c58f2++){if(!_0x1a050b[_0x4c58f2])break;if(_0x1d0f7f[_0x7d2d('0x62')]()===_0x1a050b[_0x4c58f2]['toLowerCase']()){var _0x4ca1ac=util[_0x7d2d('0x63')](_0x7d2d('0x64'),_0x5c101f);if(_0x5c101f===0x1){_0x4ca1ac=_0x7d2d('0x65');}throw new db[(_0x7d2d('0x5e'))][(_0x7d2d('0x5f'))](_0x4ca1ac);}}return;};exports[_0x7d2d('0x66')]=function(_0x12810a,_0x220cf4){var _0x2b7b0f=_0x220cf4?encryptor[_0x7d2d('0x61')](_0x220cf4)[_0x7d2d('0x67')](','):[];if(_0x2b7b0f[_0x7d2d('0x68')]===0x5){_0x2b7b0f['splice'](-0x1,0x1);}_0x2b7b0f['unshift'](_0x12810a);return encryptor['encryptString'](_0x2b7b0f[_0x7d2d('0x69')](','));};function signJwt(_0x780f78){var _0x296b53=BPromise[_0x7d2d('0x6a')](jwt[_0x7d2d('0x6b')],{'context':jwt});var _0x56de=_0x780f78[_0x7d2d('0x6c')]||config[_0x7d2d('0x9')]['session'];return new BPromise(function(_0x465fd3,_0x48bca1){_0x296b53(_0x780f78[_0x7d2d('0x6d')],_0x56de,_0x780f78[_0x7d2d('0x6e')])[_0x7d2d('0x2c')](function(_0x23e563){_0x465fd3(_0x23e563);})['catch'](function(_0x128c1f){_0x48bca1(_0x128c1f);});});}function verifyJwt(_0x1294a6,_0x4e4b99,_0x149e34){var _0x49cea1=BPromise['promisify'](jwt[_0x7d2d('0x6f')],{'context':jwt});var _0xbb9423=_0x149e34||config[_0x7d2d('0x9')][_0x7d2d('0x70')];return new BPromise(function(_0x1a4a8b,_0x9b29b0){_0x49cea1(_0x1294a6,_0xbb9423,_0x4e4b99)['then'](function(_0x2bc952){_0x1a4a8b(_0x2bc952);})[_0x7d2d('0x38')](function(_0x23a394){_0x9b29b0(_0x23a394);});});}function generateNonce(){return crypto[_0x7d2d('0x71')](0x10)['toString'](_0x7d2d('0x72'));}function generateIssuedAt(){return Math[_0x7d2d('0x73')](Date['now']()/0x3e8)[_0x7d2d('0x74')]();}function createJwt(_0x6907b2){var _0x475a15={'payload':{'iat':_0x6907b2['apiKeyIat'],'nonce':_0x6907b2[_0x7d2d('0x59')]},'options':{'algorithm':'HS512','subject':_0x6907b2['id']['toString'](),'issuer':hardwareConf[_0x7d2d('0x3e')](),'audience':hardwareConf[_0x7d2d('0x3e')]()}};return signJwt(_0x475a15)[_0x7d2d('0x2c')](function(_0x108621){return{'iat':_0x6907b2[_0x7d2d('0x58')],'nonce':_0x6907b2['apiKeyNonce'],'token':_0x108621};});}