481492543efb185699b03857e478bc8a6bd44b98
[motion2.git] / server / api / cloudProvider / cloudProvider.oauth.js
1 // *************************************************************************
2 // *                                                                       *
3 // * xCALLY Motion -  The Omnichannel Contact Center                       *
4 // * Copyright (c) Xenialab s.r.l. All Rights Reserved                     *
5 // *                                                                       *
6 // *************************************************************************
7 // *                                                                       *
8 // * Email: info@xcally.com                                                *
9 // * Website: https://www.xcally.com                                       *
10 // *                                                                       *
11 // *************************************************************************
12 // *                                                                       *
13 // * The SOFTWARE PRODUCT is protected by copyright laws and international *
14 // * copyright treaties, as well as other intellectual property laws and   *
15 // * treaties. The SOFTWARE PRODUCT is licensed, not sold.                         *
16 // *                                                                       *
17 // *************************************************************************
18 var _0xde47=['util','../../components/encryptor','../../config/environment','../../config/schedule/cloud-provider','../../mysqldb','redis','defaults','openid','profile','email','offline_access','https://outlook.office365.com/IMAP.AccessAsUser.All','https://outlook.office.com/POP.AccessAsUser.All','https://outlook.office.com/SMTP.Send','/authorize','map','type','push','/.default','Outlook365','Dynamics365','data7','replace','{TENANT_ID}','data2','code','id_token','from','stringify','base64','hex','join','redirect_uri','response_mode','scope','state','nonce','login','key','value','oauth2Claims','data1','set','decode','payload','iss','issuer','audience','exp','then','data3','CloudProvider','findOne','refresh_token','data4','decryptString','POST','data5','access_token','data6','update','Failed\x20to\x20refresh\x20access\x20token\x20for\x20cloud\x20provider\x20#%s,\x20-\x20err:%s','intervals','bind','findAll','catch','error','exports','lodash','crypto','ioredis','request-promise'];(function(_0x365ea9,_0x17ec94){var _0xb7a188=function(_0x5028c2){while(--_0x5028c2){_0x365ea9['push'](_0x365ea9['shift']());}};_0xb7a188(++_0x17ec94);}(_0xde47,0x1f4));var _0x7de4=function(_0x8a917c,_0x19c5f6){_0x8a917c=_0x8a917c-0x0;var _0x2c704e=_0xde47[_0x8a917c];return _0x2c704e;};'use strict';var _=require(_0x7de4('0x0'));var crypto=require(_0x7de4('0x1'));var jwt=require('jsonwebtoken');var moment=require('moment');var Redis=require(_0x7de4('0x2'));var rp=require(_0x7de4('0x3'));var util=require(_0x7de4('0x4'));var encryptor=require(_0x7de4('0x5'));var config=require(_0x7de4('0x6'));var logger=require('../../config/logger')('api');var schedule=require(_0x7de4('0x7'));var db=require(_0x7de4('0x8'))['db'];config[_0x7de4('0x9')]=_[_0x7de4('0xa')](config['redis'],{'host':'localhost','port':0x18eb});var redis=new Redis(config['redis']);var MICROSOFT_AUTH_URL='https://login.microsoftonline.com/{TENANT_ID}/oauth2/v2.0';var AZURE_AUTH_SCOPES={'Outlook365':[_0x7de4('0xb'),_0x7de4('0xc'),_0x7de4('0xd'),_0x7de4('0xe'),_0x7de4('0xf'),_0x7de4('0x10'),_0x7de4('0x11')],'Dynamics365':[_0x7de4('0xb'),'offline_access']};var MICROSOFT_AUTH_ENDPOINT=_0x7de4('0x12');var MICROSOFT_TOKEN_ENDPOINT='/token';var OAUTH_REFRESH_INTERVAL=0xfa;function getAuthorizationScopes(_0x3142db){var _0x272a19=_[_0x7de4('0x13')](AZURE_AUTH_SCOPES[_0x3142db[_0x7de4('0x14')]]);if(_0x3142db[_0x7de4('0x14')]==='Dynamics365')_0x272a19[_0x7de4('0x15')](_0x3142db['data7']+_0x7de4('0x16'));return _0x272a19['join']('\x20');}function getAccessTokenScope(_0x1f362a){if(_0x1f362a[_0x7de4('0x14')]===_0x7de4('0x17'))return _0x7de4('0xf');if(_0x1f362a['type']===_0x7de4('0x18'))return _0x1f362a[_0x7de4('0x19')]+_0x7de4('0x16');}function generateMicrosoftAuthorizationUrl(_0x5a9fb6,_0x3601a9){var _0x4fe245=MICROSOFT_AUTH_URL[_0x7de4('0x1a')](_0x7de4('0x1b'),_0x5a9fb6[_0x7de4('0x1c')]);var _0x51cbd9=[_0x7de4('0x1d'),_0x7de4('0x1e')];var _0x9c4e2b=Buffer[_0x7de4('0x1f')](JSON[_0x7de4('0x20')]({'id':_0x3601a9}))['toString'](_0x7de4('0x21'));var _0x579b76=crypto['randomBytes'](0x10)['toString'](_0x7de4('0x22'));var _0xc4d2a9=getAuthorizationScopes(_0x5a9fb6);var _0x4bb550=[{'key':'client_id','value':_0x5a9fb6['data1']},{'key':'response_type','value':encodeURIComponent(_0x51cbd9[_0x7de4('0x23')]('\x20'))},{'key':_0x7de4('0x24'),'value':_0x5a9fb6['data4']},{'key':_0x7de4('0x25'),'value':'form_post'},{'key':_0x7de4('0x26'),'value':encodeURIComponent(_0xc4d2a9)},{'key':_0x7de4('0x27'),'value':_0x9c4e2b},{'key':_0x7de4('0x28'),'value':_0x579b76},{'key':'prompt','value':_0x7de4('0x29')}];var _0x36c4ba=_0x4fe245+MICROSOFT_AUTH_ENDPOINT+'?'+_[_0x7de4('0x13')](_0x4bb550,function(_0xd5c92c){return _0xd5c92c[_0x7de4('0x2a')]+'='+_0xd5c92c[_0x7de4('0x2b')];})[_0x7de4('0x23')]('&');_0x5a9fb6[_0x7de4('0x2c')]={'issuer':_0x4fe245[_0x7de4('0x1a')]('oauth2/',''),'audience':_0x5a9fb6[_0x7de4('0x2d')],'state':_0x9c4e2b,'nonce':_0x579b76};redis[_0x7de4('0x2e')](_0x9c4e2b,JSON[_0x7de4('0x20')](_0x5a9fb6));return _0x36c4ba;}function isValidIdToken(_0x4ab4d9,_0xb83994){try{var _0x1e2069=jwt[_0x7de4('0x2f')](_0x4ab4d9,{'complete':!![]});var _0x2b9ed8=_0x1e2069[_0x7de4('0x30')];if(_0x2b9ed8[_0x7de4('0x31')]!==_0xb83994[_0x7de4('0x32')])return![];if(_0x2b9ed8['aud']!==_0xb83994[_0x7de4('0x33')])return![];if(_0x2b9ed8[_0x7de4('0x28')]!==_0xb83994[_0x7de4('0x28')])return![];if(moment()['isAfter'](moment['unix'](_0x2b9ed8[_0x7de4('0x34')])))return![];return!![];}catch(_0x36ffbc){throw _0x36ffbc;}}function refreshOauth2MicrosoftAccessToken(_0x566e85){return Promise['resolve']()[_0x7de4('0x35')](function(){if(_0x566e85[_0x7de4('0x36')])return _0x566e85;return db[_0x7de4('0x37')][_0x7de4('0x38')]({'where':{'id':_0x566e85['id']},'raw':!![]});})['then'](function(_0x355d16){var _0x153160={'grant_type':_0x7de4('0x39'),'refresh_token':_0x355d16['data6'],'scope':getAccessTokenScope(_0x355d16),'redirect_uri':_0x355d16[_0x7de4('0x3a')],'client_id':_0x355d16[_0x7de4('0x2d')],'client_secret':encryptor[_0x7de4('0x3b')](_0x355d16[_0x7de4('0x36')])};var _0x1c604e={'method':_0x7de4('0x3c'),'uri':MICROSOFT_AUTH_URL[_0x7de4('0x1a')](_0x7de4('0x1b'),_0x355d16[_0x7de4('0x1c')])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x153160,'json':!![]};return rp(_0x1c604e);})[_0x7de4('0x35')](function(_0x1aa77f){_0x566e85[_0x7de4('0x3d')]=_0x1aa77f[_0x7de4('0x3e')];_0x566e85[_0x7de4('0x3f')]=_0x1aa77f[_0x7de4('0x39')];return db[_0x7de4('0x37')][_0x7de4('0x40')]({'data5':_0x566e85[_0x7de4('0x3d')],'data6':_0x566e85['data6']},{'where':{'id':_0x566e85['id']}});})['then'](function(){return _0x566e85;})['catch'](function(_0x258366){logger['error'](_0x7de4('0x41'),_0x566e85['id'],_0x258366);});}function getOauth2MicrosoftAccessToken(_0x452b2f,_0x506707){var _0x4c3618={'grant_type':'authorization_code','code':_0x452b2f,'scope':getAccessTokenScope(_0x506707),'redirect_uri':_0x506707[_0x7de4('0x3a')],'client_id':_0x506707['data1'],'client_secret':encryptor[_0x7de4('0x3b')](_0x506707[_0x7de4('0x36')])};var _0x4cbca8={'method':_0x7de4('0x3c'),'uri':MICROSOFT_AUTH_URL[_0x7de4('0x1a')](_0x7de4('0x1b'),_0x506707[_0x7de4('0x1c')])+MICROSOFT_TOKEN_ENDPOINT,'form':_0x4c3618,'json':!![]};return rp(_0x4cbca8);}function startRefreshInterval(_0x1e8257){var _0x4078ef=schedule[_0x7de4('0x42')];if(_0x4078ef[_0x1e8257['id']])clearInterval(_0x4078ef[_0x1e8257['id']]);_0x4078ef[_0x1e8257['id']]=setInterval(refreshOauth2MicrosoftAccessToken[_0x7de4('0x43')](this,{'id':_0x1e8257['id']}),OAUTH_REFRESH_INTERVAL*0x3e8);schedule[_0x7de4('0x42')]=_0x4078ef;}function startAllRefreshIntervals(){return db[_0x7de4('0x37')][_0x7de4('0x44')]({'where':{'data6':{'$ne':null}},'raw':!![]})['then'](function(_0x4872bb){var _0x56e8d1=_0x4872bb['map'](function(_0x3d4116){return refreshOauth2MicrosoftAccessToken(_0x3d4116)[_0x7de4('0x35')](function(_0x96c52f){startRefreshInterval(_0x96c52f);});});return Promise['all'](_0x56e8d1);})[_0x7de4('0x45')](function(_0x129214){var _0x2c7579=_0x129214?util['inspect'](_0x129214,{'showHidden':![],'depth':null}):'';logger[_0x7de4('0x46')]('[CLOUD_PROVIDER]\x20Error\x20while\x20refreshing\x20the\x20tokens\x20after\x20service\x20restart\x20error:%s',_0x2c7579);});}module[_0x7de4('0x47')]={'generateMicrosoftAuthorizationUrl':generateMicrosoftAuthorizationUrl,'getOauth2MicrosoftAccessToken':getOauth2MicrosoftAccessToken,'isValidIdToken':isValidIdToken,'startAllRefreshIntervals':startAllRefreshIntervals,'refreshOauth2MicrosoftAccessToken':refreshOauth2MicrosoftAccessToken,'startRefreshInterval':startRefreshInterval};