# API Encryption — CONFIRMED WORKING

## Date: 2026-09-29

## Encryption Key
- _DEFAULT_KEY = GkWdMVpsGDEgfM9+ISF/nUy5NMgCbjUdV0Gv1dxIFUM=
- Derivation: PBKDF2HMAC(SHA256, salt=b"static-salt", iterations=100000, length=32)
- Cipher: AES-GCM (IV=12 bytes, tag=16 bytes)
- Format: urlsafe_b64(iv + ciphertext + tag).rstrip('=')

## Request Format
- URL: https://api-inno.pharmalink.id/manufacture-be/<encrypted_path>
- Header: X-Encrypted-Endpoint: true
- Header: Authorization: Bearer <JWT>
- Header: Content-Type: application/json

## Confirmed Working
- POST /login (encrypted) → 200 + JWT (LOGIN SUCCESS!)
- GET / (encrypted) → 200 "Health Check Manufacture"
- GET /login (encrypted) → 405 (correct - GET not allowed)

## Routes (from routes.pyc)
- auth_users
- products
- qs_qc / qc_qs_master
- m_manufacture
- t_manufacture
- t_fp_manufacture
- m_manufacture_history
- firebase_notifications
- error_notifications
- warning_notifications
- version
- formula_procedures / formula_generate_composition
- arduino_setting_standard
- factory_setting / factory_setting_local
- trial_formulas / auto_generate_formula
- mdissolutionsetting
- m_hplc_setting
- m_autosampler_setting
- mhplcpositionsetting
- m_calibration_dissolution_setting
- m_dissolution_filter_setting
- temperature_log
- master_component_slave_parts
- machine_type_master_slave
- machine_unit_master_slave
- cors_url_download (proxy-pdf)
- replication (replicate_m_manufacture, replicate_t_manufacture, replicate_qs_qc_manufacture)

## Access
- Production: api-inno.pharmalink.id (34.101.32.120)
- Staging: staging-api-inno.pharmalink.id (34.128.78.65)
- Both require Indonesian proxy
- Login: admin:admin123 → JWT (ADMIN role, userid U00001)

## Encrypted Endpoints
- All attempts on /users, /products, etc → 405 "Method not allowed for this route"
- This is Flask middleware error — routes not found under these names
- Need to find exact route names from routes.pyc registration
