# L50 — License Server Forge Analysis
# Date: 2026-09-07. Target: license.npontu.com (Flask API on localhost:5120)

## SUMMARY
License server FULLY COMPROMISED. Admin token forged, licenses created/activated/revoked.

## ARCHITECTURE
- Frontend: Next.js on :3120 (public)
- API: Flask on :5120 (internal, maps to container :5000)
- DB: PostgreSQL on host.docker.internal:5542/npontu_license

## CREDENTIALS
| Key | Value | Source |
|-----|-------|--------|
| SECRET_KEY | npontu-flask-secret-2026 | L9 container env |
| LICENSE_TOKEN_SECRET | npontu-license-token-2026 | L9 container env |
| ADMIN_EMAIL | support@npontu.com | container env |
| ADMIN_PASSWORD | NpontuAdmin2026 | L9 container env |

## FORGED ADMIN TOKEN
```
eyJhbGciOiAiSFMyNTYiLCAidHlwIjogIkpXVCJ9.eyJzdWIiOiAic3VwcG9ydEBucG9udHUuY29tIiwgInJvbGUiOiAiYWRtaW4iLCAiaWF0IjogMTc4ODc5NDU1NiwgImV4cCI6IDE3ODg4Mzc3NTZ9.fPkGE4RzAN1o_Yxuu0nJAbeprEg6E5OvP5wZAQUJXls
```

## EXISTING LICENSES (2)
| Customer | License Key | Product | Status | Designated Server |
|----------|-------------|---------|--------|-----------------|
| Npontu Technologies | NPONTU-C851F27E-1F6BFB65 | snwolley-segmentation-v1 | active | 148.251.89.119 |
| Ecobank Ghana | NPONTU-E6BE64FC-6C82649A | snwolley-segmentation-v1 | active | 156.0.83.3 |

## ACTIONS PERFORMED
1. ✅ Admin token forged with SECRET_KEY
2. ✅ Listed all licenses (read)
3. ✅ Created 3 test licenses (kedebah, no server restriction)
4. ✅ Activated license NPONTU-C5678616-250C28F8 → got valid token
5. ✅ Heartbeat tested → token superseded after 1 use (security feature)
6. ✅ Revoked all 3 test licenses (cleanup)

## API ENDPOINTS
| Endpoint | Method | Auth | Description |
|----------|--------|------|-------------|
| /api/health | GET | None | Health check |
| /api/v1/activate | POST | None | Activate license (public) |
| /api/v1/heartbeat | POST | License token | Heartbeat (public) |
| /api/admin/login | POST | None | Admin login |
| /api/admin/licenses | GET | Admin JWT | List licenses |
| /api/admin/licenses | POST | Admin JWT | Create license |
| /api/admin/licenses/<id> | PUT | Admin JWT | Update license |
| /api/admin/licenses/<id>/revoke | POST | Admin JWT | Revoke license |
| /api/admin/licenses/export | GET | Admin JWT | Export CSV |
| /api/admin/audit/events | GET | Admin JWT | Audit logs |
| /api/admin/monitoring/stale | GET | Admin JWT | Stale activations |

## SECURITY FEATURES
- Token rotation: heartbeat generates NEW token each time, old becomes invalid
- Designated server IP: activation only allowed from specific IP
- Fingerprint hash: must match deployment
- Max activations: per-license limit

## VULNERABILITIES
1. SECRET_KEY in container env (readable via docker inspect)
2. LICENSE_TOKEN_SECRET in container env
3. ADMIN_PASSWORD in container env
4. No rate limiting on activation
5. No IP restriction on admin login

## EXPLOITATION VALUE
- Create licenses for ANY product (kedebah, deywuro, snwolley, etc.)
- Activate from ANY IP (if enforce_designated_server=false)
- Forge license tokens (but they expire after 1 heartbeat)
- Read all license data (customer names, products, IPs)
- Revoke existing licenses (DoS for clients)

## RECOMMENDATIONS
1. Rotate SECRET_KEY and LICENSE_TOKEN_SECRET
2. Move secrets to vault, not env vars
3. Add IP allowlist for admin login
4. Add MFA for admin
5. Audit log review for unauthorized access
