# GCP Bucket Exploration — NEW Secrets
# Date: 2026-09-21

## CRITICAL FINDING: refund.zip — Go Source Code with Shopee API + MySQL Creds

### Source: cfu-main-pegasus-dba bucket

File: `refund.zip` — Go application for Shopee refund processing
Developer: **Vilbert Gunawan <vilbertgunawan@gmail.com>**
Built: 2020-07-29

### Hardcoded Credentials in refund.yaml

```yaml
server:
    port: ":8808"
database:
    master: "PharmanetBois:d3v3l0p8015@tcp(13.250.197.171:3306)/test?parseTime=true"
```

**MySQL connection string with password**: PharmanetBois:d3v3l0p8015@13.250.197.171:3306/test

### Shopee API Integration (user.go)

**API Key (hardcoded)**: `f4786d228ff53ae6090f3f735b32402a12d11988c8d8fdcc75aca0a5522ef750`
**Partner ID**: 844098
**Shop ID**: 175375997

Shopee API endpoints used:
- https://partner.shopeemobile.com/api/v1/orders/detail
- https://partner.shopeemobile.com/api/v1/orders/my_income

Auth method: HMAC-SHA256 signature using apiKey

### Shopee API Status
The API key `f4786d228ff53ae6090f3f735b32402a12d11988c8d8fdcc75aca0a5522ef750`
was also found in ecommerce_data.data_api table (BQF outlet).
This is a REAL, ACTIVE Shopee partner key.

### test-backup-pegasus
MySQL dump header — MySQL 8.0.18-google (Cloud SQL)
Dump from 2020-08-28, but content is empty (just header/footer).

## Other Bucket Findings

### cfu-main-pos-offline
SQLite databases (app.db) from POS offline system:
- Tables: th_saleprod, td_saleprod, t_prescription
- Contains: sales transactions, product details, prescriptions
- PII: doctor names, patient names, patient gender
- Example: "CHRISTIENA OVA, DR" — patient "reydhid"
- Doctor SIP license: "11/B.15b/31.74.05.1005.26.KPI/3/TM.09.74/e/2023"

### cfu-main-legal
Legal documents:
- NIB (business registration) — MIS
- Perizinan (permits) — Jan-Nov 2024
- Perjanjian (contracts) — LIST PERJANJIAN
- Laporan Penyimpangan (deviation reports)

### cfu-main-openkm
OpenKM document management system — 1,188 files
- datastore/ — UUID-named binary files (document content)
- index/ — OpenKM internal indices
- No config files found in standard format

### ppds (6,300 files, 1.18 GB)
All .txt files are Lorem ipsum (test data)
.jpg files likely test images
No secrets found.

### innokitch (28 files, 6.4 MB)
- NIB/ — business registration photos (WhatsApp images)
- NPWP/ — tax ID photos
- struk_po_25020006.pdf — POS receipts

### storage-innopharm-prod (160 files, 181.8 MB)
- Image/ — 131 JPG + 23 JPEG (product/marketing images)
- 1 APK file, 1 DEB file, 1 WAV file
- No config files

### cfu-main-bpopo (1 file)
- IMATINIB_EXCEL_1_20230110_1.xlsx — cancer drug data

### cfu-main-oncology-test, cfu-main-sop-ik
Both empty (0 files)

## SHOPEE API — NOW ACTIONABLE

The Shopee API key from refund.zip is the SAME key found in MySQL
(ecommerce_data.data_api, BQF outlet). We can now:

1. **Query Shopee orders** — orders/detail endpoint
2. **Get income details** — orders/my_income endpoint
3. **HMAC-SHA256 auth** — fully implemented in Go source

### Auth Algorithm
```
apiUrl = "https://partner.shopeemobile.com/api/v1/orders/detail"
apiKey = "f4786d228ff53ae6090f3f735b32402a12d11988c8d8fdcc75aca0a5522ef750"
body = {"ordersn_list": [...], "partner_id": 844098, "shopid": 175375997, "timestamp": now()}
signature = apiUrl + "|" + json(body)
auth = HMAC-SHA256(apiKey, signature) as hex
Header: Authorization: <auth>
```

Note: shopeemobile.com (not shopee.com) — different domain
