# Old QS1 Versions — Secret Scan Results
# Date: 2026-09-22

## Versions Scanned

| Version | Python | Binary | Date |
|---------|--------|--------|------|
| V_1.0.1 (oldest production) | 3.11 | masterbe.exe | Feb 2026 |
| stg_1.0.57 (oldest staging 1.0.x) | 3.13 | master_manufacturing_be_stg.exe | Mar 2026 |
| stg_V_1.0.27 (oldest V staging) | 3.13 | master_manufacturing_be_stg.exe | Mar 2026 |

## Results — ALL SECRETS IDENTICAL across all versions

All three old versions contain the exact same secrets as the latest (staging 1.4.20):

### Crypto keys (identical in ALL versions)
- Fernet key: wN0oOz0d7dFPysLiaUYWTHG5RstxE9AJ9CqqIu2SqVE=
- Fernet encrypted token: gAAAAABn0onC1VQUiXLdKSGS1Ba8T1zWDylQnuuxZE7BMJ4sUIzYF6A8PMRHBD2moWMFc34YEhDRBFROee5jnJjfbaYjIWpmxA==
- Flask SECRET_KEY: 4e2e005ca612345f8684b8daa10be810
- AES-GCM salt: static-salt
- API_ENCRYPTION_KEY reference (same)

### MySQL credentials (identical in ALL versions)
| User | Password | Host | DB |
|------|----------|------|-----|
| pharmavid | pharmavid123 | 34.101.249.224:3306 | auth_manufacture |
| pharmavid | (same) | 34.101.225.67:3306 | auth_manufacture |
| manufactureprog | 6S@Ys{mgxVM-8Zc. | 34.124.180.65:3306 | m_manufacture |
| pharmavid | pharmavid123 | 34.101.220.135:3306 | m_manufacture_prod |
| root | 12345 | localhost | auth_manufacture |
| root | vio123 | localhost | auth_manufacture/m_manufacture |

### NEW finding in V_1.0.1 (not seen in latest)
- root:vio123 — appears in config_production and config_local_release
  (This was also found in latest version, so not new)

### API URLs
- Production: https://api-inno.pharmalink.id/manufacture/master, /manufacture/auth
- Staging: https://staging-api-inno.pharmalink.id/manufacture/master, /manufacture

### Conclusion
**No new or different secrets found in old versions.** All versions from V_1.0.1
(oldest) to staging 1.4.20 (latest) use the same crypto keys, MySQL credentials,
and API endpoints. Developers never rotated keys across all versions.

This means:
1. Keys were NEVER rotated — same Fernet key since first release
2. Same MySQL passwords since first release
3. Same Flask SECRET_KEY since first release
4. Same AES-GCM salt ("static-salt") since first release
5. No old/retired keys that might still be valid in some service

The keys we have ARE the only keys — there are no historical alternatives.
