# Mobile App Deep Analysis — Econolab QS1 APK
# Date: 2026-09-21

## App Overview

| Property | Value |
|----------|-------|
| Package | com.example.monitoring_logs |
| App name | Econolab QS1 App |
| Framework | Flutter (Dart compiled to native libapp.so) |
| Version | Compile SDK 35 (Android 15) |
| Signing | **DEBUG CERT** (CN=Android Debug, O=Android, C=US) |
| SHA1 | 11:31:C9:46:73:CA:4E:45:6A:D9:07:C3:F8:89:37:AE:63:33:F9:5E |
| Validity | Jan 2025 - Jan 2055 |
| Libs | libapp.so (5.5MB), libflutter.so (11MB), libdatastore_shared_counter.so |

## Login Flow (reconstructed from libapp.so strings)

1. User enters username + password in LoginView
2. POST to `https://api-inno.pharmalink.id/manufacture-be/login`
3. Server returns: token (Bearer) + user_id
4. Token stored in FlutterSecureStorage (encrypted on-device)
5. FCM token registered: POST `/manufacture-be/insertusernotificationtoken`
6. Session guard checks token expiry, redirects to login if expired
7. Error messages (Indonesian):
   - "Login gagal. Data user tidak valid." = Login failed, invalid user data
   - "token kosong dari login" = token empty from login
   - "Session expired. Please login again."

## API Endpoints (13 — all under /manufacture-be/)

| # | Endpoint | Purpose |
|---|----------|---------|
| 1 | /manufacture-be/login | Login (returns Bearer token) |
| 2 | /manufacture-be/getversion | Version check |
| 3 | /manufacture-be/getpdfpath | PDF report path |
| 4 | /manufacture-be/getcompanies | List companies |
| 5 | /manufacture-be/getfactories | List factories |
| 6 | /manufacture-be/getuserbyid?user_id={id} | User profile |
| 7 | /manufacture-be/getuseraccesslist?user_id={id} | User ACL |
| 8 | /manufacture-be/getanalysisqueue?factory_id={id} | QC queue |
| 9 | /manufacture-be/getmonitoringqueuebyanalysisid?analysis_id={id} | Monitoring |
| 10 | /manufacture-be/getwarninghistories | Warning history |
| 11 | /manufacture-be/checktermsandconditions?user_id={id} | T&C check |
| 12 | /manufacture-be/insertusernotificationtoken | FCM token register |
| 13 | /manufacture-be/updateusernotificationnonactivate | Disable notif |

## Firebase Config (hardcoded in strings.xml)

| Key | Value |
|-----|-------|
| google_api_key | AIzaSyBPEgWSgKCBAH640Aknbl-vw_YSDGEewio |
| google_app_id | 1:2882385210:android:9f9e437e91d9dc68e64c03 |
| gcm_defaultSenderId | 2882385210 |
| project_id | monitoringlogs-bfc19 |
| google_storage_bucket | monitoringlogs-bfc19.firebasestorage.app |

## Security Findings

### 1. Debug-signed APK (MEDIUM)
- Signed with public Android Debug keystore
- Certificate is publicly reproducible
- Debug builds often have: debug logging enabled, less strict SSL pinning, test endpoints

### 2. No SSL Pinning (MEDIUM)
- No `network_security_config.xml` found
- No certificate pinning in AndroidManifest
- All API calls go to `https://api-inno.pharmalink.id` — MITM possible on rooted device

### 3. Exported Components (LOW-MEDIUM)

| Component | Exported | Permission | Risk |
|-----------|----------|------------|------|
| MainActivity | true | LAUNCHER | Standard |
| FlutterFirebaseMessagingReceiver | true | c2dm.SEND | FCM injection if sender compromised |
| FirebaseInstanceIdReceiver | true | c2dm.SEND | Instance ID spoofing |
| ProfileInstallReceiver | true | DUMP | Requires DUMP perm (system only) |

### 4. Token Storage (GOOD)
- Uses FlutterSecureStorage (encrypted Keychain/Keystore)
- Tokens not stored in plaintext SharedPreferences

### 5. No Hardcoded Credentials (GOOD)
- No API keys, passwords, or secrets in Dart code
- Firebase API key is public (used for client-side Firebase init, not a secret)
- Auth uses Bearer token from server login

### 6. Developer Path Leak (LOW)
- `D:\workspace_kerja\manufacturing-monitoring-apps\monitoring_logs_mobile_app\`
- Developer Windows username: NITRO 5

### 7. Bundled Pharma Data (LOW)
- queue.json contains sample data: Erlotinib dissolution testing
- Factory FA00001, Company CO00001, Product PR00001-TEST1
- Active substance: IN-ERL-001-ERLOTINIB

## App Architecture

```
monitoring_logs/
├── main.dart
├── controllers/
│   ├── home_controller.dart — queue management
│   └── login_controller.dart — auth flow
├── models/
│   ├── analysis_queue_response.dart
│   ├── company_model.dart
│   ├── factory_model.dart
│   ├── notification_model.dart
│   ├── queue_analysis_model.dart
│   ├── queue_model.dart
│   └── user_detail_model.dart
├── services/
│   ├── api_service.dart — HTTP client to api-inno.pharmalink.id
│   ├── app_lifecycle_service.dart — lifecycle management
│   ├── notification_service.dart — push notification handler
│   └── tts_service.dart — text-to-speech (alert announcements)
├── utils/
│   ├── notification_helper.dart
│   ├── session_guard.dart — token expiry check
│   └── storage_helper.dart — FlutterSecureStorage wrapper
└── views/
    ├── home_view.dart
    ├── login_view.dart
    ├── notification_view.dart
    ├── profile_view.dart
    ├── queue_detail_view.dart
    └── queue_view.dart
```

## Flutter Dependencies

- firebase_core, firebase_messaging — FCM push notifications
- flutter_secure_storage — encrypted token storage
- http — API client
- flutter_local_notifications — local notification handling
- flutter_tts — text-to-speech (factory floor announcements)
- google_fonts — UI fonts
- package_info_plus — app version info
- path_provider — file system access

## Vectors from APK Analysis

1. **api-inno.pharmalink.id endpoints** — 13 known endpoints, login returns Bearer token. Need valid creds or encryption bypass.
2. **FCM token injection** — firebase-adminsdk key available, can send push to registered devices
3. **Debug APK** — weaker security, debug logging may leak tokens in logcat
4. **No SSL pinning** — MITM possible on network level
5. **TTS service** — can be used for social engineering if device compromised
