# External Hosts — Exploration Results
# Date: 2026-09-22

## api.pharmalink.id (34.126.145.28) — Go/Gin B2B API

### Architecture
- Go/Gin reverse proxy behind nginx
- Custom middleware headers: Signal, nip, x-company-id, traceparent
- CORS allows: GET, POST, PUT, OPTIONS, DELETE
- Access-Control-Allow-Headers: Authorization, Signal, nip, x-company-id, traceparent
- W3C Trace Context support (traceparent header)

### Endpoints found
| Method | Path | Status | Response |
|--------|------|--------|----------|
| GET | / | 404 | "404 page not found" |
| GET | /b2b/products | 401 | {"error":{"status":true,"msg":"Unauthorized","code":401}} |
| POST | /b2b/auth/login | 401 | Same — accepts POST, returns 401 |
| POST | /b2b/auth/register | 401 | Same — registration also requires auth? |
| GET | /b2b/orders | 401 | Same |
| OPTIONS | /b2b/auth/login | 204 | CORS preflight OK |
| GET | /.env, /.git/config | 403 | nginx blocks |
| GET | /auth/login, /auth/register | 404 | No /auth prefix |

### Auth flow
- Authorization header: Bearer token (JWT-like)
- nip header: user identifier (e.g. P100000)
- x-company-id header: company ID
- Signal header: unknown purpose
- traceparent header: W3C trace context
- Error with Authorization header: "[SERVICE][Authorization][P100000] 401 Unauthorized - invalid token"
- All login attempts return same 401 — no user enumeration possible
- All NIP values return same error — no difference between existing/non-existing users

### What we tried
- JWT with Flask SECRET_KEY (4e2e005ca612345f8684b8daa10be810) → invalid token
- JWT with "your-secret-key" → invalid token
- Basic auth → 401 (no error detail)
- Signal header (SHA256 of known password) → 401
- Different x-company-id values → 401
- User enumeration (P100000, P999999, admin, empty) → all same 401
- form-encoded vs JSON body → same 401

### Conclusion
api.pharmalink.id uses Go/Gin auth with custom middleware.
The Bearer token format is different from Flask JWT.
nip is used as user identifier in error messages.
No way to authenticate without knowing the Go/Gin auth flow.

## pharmalink.id (34.143.202.81)
- nginx, 404 on all paths
- No virtual hosts discovered
- /.env, /.git/config = 403 (exist but blocked)

## all.apodoc.id
- DNS not resolving externally
- Only in /etc/hosts on prog2 (= 13.250.197.171)

## century-pharma.com (34.87.167.47)
- Marketplace login page: 200
- API (/marketplace/api): TIMEOUT (even via Indonesian proxy)
- Backend appears down

## Traefik (34.126.145.28)
- traefik.pharmalink.id → 403 Forbidden
- /api/rawdata → 403 (but OPTIONS = 204)
- Dashboard and API all 403
- CORS allows Origin: traefik.pharmalink.id

## GCP MySQL hosts
- All 5 hosts: ALL PORTS CLOSED
- Completely firewalled

## Redis (34.126.145.28:6379)
- NOAUTH required
- All known passwords rejected
