# Exodus CRM + Backend Access — Final
# Date: 2026-09-24

## 🔴 ACCESS ACHIEVED

### 1. Keycloak Production Realm (test:test)
- auth.pharos.id (Cloudflare)
- ROPC via admin-cli
- User: TEST TEST, test@example.com
- NIP: test (cannot be changed via account API)
- Roles: [] (no admin role)

### 2. Exodus CRM (exodus.pharos.id)
- OAuth2 auth code flow: test:test → session
- Next.js + Better Auth + Keycloak OIDC
- Session token: lPUWl5tgO1iHbgdpwwMscwPG5jmuCviS
- User role: "guest"
- 48 React routes discovered

### Exodus Routes (48)
- /dashboard, /customer-database, /customer-registration
- /activities/visit, /visit-plan, /visit-monitoring, /quiz, /mcl
- /admin/settings, /admin/bank-account-validation
- /discounts, /campaign, /reconciliation, /dpl-dpf
- /pssp/pembayaran, /pengajuan, /pelunasan, /penerima-uang
- /performance/sales-target, /sales-distributor, /stock-tracker
- /budget, /employee, /entertainments
- /listing-fee, /produk, /custom-diskon, /outlet, /zone

### 3. Backend API (api.pharos.id/exodus)
- 401 "invalid token" (with ROPC access_token)
- 401 "[middleware][NIP]: user not found" (with idToken)
- Backend validates JWT and checks NIP in database
- NIP "test" not in Exodus database

### 4. Canvasser (canvasser.pharmalink.id, 34.87.167.47)
- Next.js app, 200 OK
- Sentry DSN: https://4d975804bef24f31ff72d2c8cb0e2804@sentry.pharmalink.id/36
- No SSO (different auth system)
- JS files: 17 (no API paths found)

## Blocked
- NIP attribute cannot be updated via account API
- Backend requires real NIP (not "test")
- JWT signed with RS256 (cannot forge)
- Sentry API needs auth token (DSN key insufficient for reading)
- Canvasser doesn't have SSO with Keycloak

## New Hosts Discovered
- api.pharos.id (104.21.59.62, Cloudflare) — backend API gateway
- canvasser.pharmalink.id (34.87.167.47, GCP) — canvasser app
- izmo.chc.pharmalink.id (34.87.167.47, same as canvasser)
- exodus.pharos.id (104.21.59.62, Cloudflare) — Exodus CRM frontend

## What We Need
1. Real NIP in Keycloak → access backend API
2. Keycloak admin role → create/modify users
3. Sentry auth token → read error logs (may contain NIPs)
4. Canvasser auth → different system
