# api-inno.pharmalink.id — Production API Analysis

## LOGIN SUCCESS
- URL: https://api-inno.pharmalink.id/manufacture-be/login
- Creds: admin:admin123
- JWT in response header `Token`
- userid: U00001, userrole: ADMIN
- Access via Indonesian proxy required

## API Structure (from binary analysis)
- Reverse proxy: Caddy (all paths except /login and / return 405)
- Backend: Flask (Python)
- Encryption middleware: AES-GCM with PBKDF2/SHA256
- X-Encrypted-Endpoint header for encrypted routes
- API_ENCRYPTION_KEY from environment variable
- _DEFAULT_KEY fallback in middleware

## Found API Routes (from staging binary)
- /manufacture-be/login (POST) — WORKS
- /manufacture-be/ (GET) — Health Check
- /manufacture/master/proxy-pdf (GET) — SSRF (staging only)
- /api/encrypt (POST) — encrypt text
- /api/decrypt (POST) — decrypt text
- /api/encrypt-endpoint (POST) — encrypt endpoint path

## GCP Infrastructure
- api-inno.pharmalink.id → 34.101.32.120
- staging-api-inno.pharmalink.id → 34.128.78.65
- GCP MySQL 34.87.44.167:3306 (grom:d3v3l0p8015/simpapi) — firewalled
- GCP MySQL 34.101.249.224:3306 (pharmavid:pharmavid123/auth_manufacture) — firewalled

## Config (from config.pyc)
- Databases: m_manufacture, m_manufacture_prod, m_manufacture2, t_manufacture, t_fp_manufacture, qs_qc_manufacture, m_manufacture_history
- Auth DB: auth_manufacture
- SECRET_KEY = 'development key'
- encrypted_password field
- manufacture_master, manufacture_auth, manufacture_auth_staging

## Blocked
- All API endpoints blocked by reverse proxy (405)
- GCP metadata not accessible (SSRF endpoint not on production)
- GCP MySQL ports firewalled
