# QS1 Secret Scan — FINAL Consolidated Results
# Date: 2026-09-21
# Source: EconolabQS1 Staging 1.4.20 — all binaries (PyInstaller Python 3.13)
# Subagents: 3 parallel (frontend/binaries, HPLC workers, APK)

## ALL HARDCODED CREDENTIALS

### MySQL Production (NEW — from auto_sampler_hplc.exe, all 6 binaries)

| Parameter | Value |
|-----------|-------|
| Connection string | mysql+mysqlconnector://grom:d3v3l0p8015@34.87.44.167:3306/simpapi |
| Host | 34.87.44.167 (GCP) |
| Port | 3306 |
| User | grom |
| Password | d3v3l0p8015 |
| Database | simpapi |
| Status | FIREWALLED (port 3306 timeout) |

### MySQL Staging (from config_staging.pyc)

| Parameter | Value |
|-----------|-------|
| Host | 34.101.249.224 (GCP) |
| Port | 3306 |
| User | pharmavid |
| Password | pharmavid123 (decrypted from Fernet) |
| Databases | mprocess, m_manufacture, m_manufacture2, tprocess, t_manufacture, qs_qc, hplc + cloud/local variants |
| Status | FIREWALLED |

### MySQL Local (all binaries)

| Parameter | Value |
|-----------|-------|
| Host | localhost |
| User | root |
| Password | 12345 |

### Flask SECRET_KEY (all binaries)

| Parameter | Value |
|-----------|-------|
| SECRET_KEY | 4e2e005ca612345f8684b8daa10be810 |

### API Encryption Key (middleware.pyc, all binaries)

| Parameter | Value |
|-----------|-------|
| API_ENCRYPTION_KEY | GkWdMVpsGDEgfM9+ISF/nUy5NMgCbjUdV0Gv1dxIFUM= |
| Algorithm | AES + PBKDF2HMAC (SHA256, static-salt) |
| Fernet key (DB pass encrypt) | wN0oOz0d7dFPysLiaUYWTHG5RstxE9AJ9CqqIu2SqVE= |

### GCP Service Account Keys (embedded in binaries)

| Key | project_id | private_key_id | Already in gcp_keys/ |
|-----|------------|----------------|----------------------|
| innopharm_main.json | innopharm-main | fc30895bd7c32768dcd163a1a64adff7ea38ff31 | YES (1112__) |
| firebase-adminsdk | monitoringlogs-bfc19 | b135befb55842463629aa750d84d588fcaff76a3 | YES (1203__/1259__) |

### Firebase (from APK strings.xml)

| Parameter | Value |
|-----------|-------|
| google_api_key | AIzaSyBPEgWSgKCBAH640Aknbl-vw_YSDGEewio |
| google_app_id | 1:2882385210:android:9f9e437e91d9dc68e64c03 |
| gcm_defaultSenderId | 2882385210 |
| project_id | monitoringlogs-bfc19 |
| google_storage_bucket | monitoringlogs-bfc19.firebasestorage.app |

### Backend API URLs

| Env | URL | IP | Status |
|-----|-----|----|--------|
| Production | https://api-inno.pharmalink.id/manufacture-be/ | 34.101.32.120 | 403 (X-Encrypted-Endpoint) |
| Staging | https://staging-api-inno.pharmalink.id/manufacture-be/ | 34.128.78.65 | LIVE |
| Internal | http://10.0.55.127:8080 | 10.0.55.127 | N/A (internal) |
| Local backend | http://localhost:8600/manufacture/server/core/main/* | localhost | N/A |
| Tauri dev | http://127.0.0.1:1420 | localhost | N/A |
| PC_HOST | 192.168.0.195 | LAN | N/A |

### GCS Buckets (from innopharm_main.json)

- innopharm-main-development
- storage-innopharm-prod
- video-storage-all

### Hardware Config (from routes.pyc)

- COM13, COM20, COM21 — HPLC detector/pump serial ports
- Arduino control via socket (IP+MAC based)
- pyserial embedded

### Developer Path Leak

D:\workspace_kerja\manufacturing-monitoring-apps\

## DECRYPTION LOG

Fernet key: wN0oOz0d7dFPysLiaUYWTHG5RstxE9AJ9CqqIu2SqVE=
Encrypted: gAAAAABn0onC1VQUiXLdKSGS1Ba8T1zWDylQnuuxZE7BMJ4sUIzYF6A8PMRHBD2moWMFc34YEhDRBFROee5jnJjfbaYjIWpmxA==
Decrypted: pharmavid123

## VALIDATION STATUS

| Cred | Target | Status |
|------|--------|--------|
| grom/d3v3l0p8015 | 34.87.44.167:3306 | FIREWALLED |
| pharmavid/pharmavid123 | 34.101.249.224:3306 | FIREWALLED |
| API_ENCRYPTION_KEY | api-inno.pharmalink.id | 403 (needs encrypted request) |
| Firebase API key | monitoringlogs-bfc19 | Not validated |
| GCP SA keys | innopharm-main, monitoringlogs-bfc19 | Already known, LIVE |
| Flask SECRET_KEY | Session forgery | Not validated |

### Backend Service Architecture (from EconolabQS1.exe + replication.exe + download_report_30m.exe)

| Port | Service | Auth | Endpoints |
|------|---------|------|-----------|
| 8081 | master_manufacturing_be_stg.exe | NONE in client code | /manufacture/master/getlocalfactory, /manufacture/master/bridgereplication, /manufacture/master/getlistcircuitpart* |
| 8600 | core_controller_stg.exe or qc_core.exe | NONE | (readiness check only) |
| 62001 | report/log service | NONE | /manufacture/server/service/logs/reportsummarycircuitparts |

IMPORTANT: replication.exe and download_report_30m.exe make bare HTTP GET/POST requests — no Bearer tokens, API keys, or auth headers. If internal network access is obtained (pivot/VPN), these endpoints can be called directly without authentication.

### Tauri Application Config (EconolabQS1.exe)

| Field | Value |
|-------|-------|
| Bundle ID | com.developmentInnopharm.stgmain |
| Tauri version | 2.11.2 |
| Frontend | Next.js (turbopack) |
| Plugins | dialog, fs (read/write), shell (open arbitrary URLs), window |
| IPC | window.__TAURI_INTERNALS__.invoke() — filesystem, shell, dialog |
| Build machine | NITRO 5 (C:\Users\NITRO 5\.cargo\) |
| Rust toolchain | 4a4ef493e3a1488c6e321570238084b38948f6db |
| PDB refs | EconolabQS1.pdb, app.pdb, backend_launcher.pdb |

### Security Implications

1. Backend services on ports 8081/8600/62001 have NO authentication in client code
2. Tauri shell plugin allows opening arbitrary URLs from frontend JS
3. Tauri fs plugin allows filesystem read/write from frontend JS
4. Arduino flasher integration suggests physical IoT device interaction
5. ~200+ Next.js frontend routes reveal complete app functionality

## NEXT STEPS

1. Try grom/d3v3l0p8015 on other ports/services on 34.87.44.167 (SSH, HTTP)
2. Try pharmavid/pharmavid123 on other services
3. Forge Flask session using SECRET_KEY 4e2e005ca612345f8684b8daa10be810
4. Build encrypted API request to api-inno.pharmalink.id (AES + PBKDF2HMAC + X-Encrypted-Endpoint)
5. Test Firebase API key against Firebase REST API
6. Check video-storage-all bucket (NEW — not in previous inventory)
7. If internal pivot obtained: call localhost:8081/8600/62001 endpoints directly (no auth)
