# QS1 Binary Secret Scan — Hardcoded Secrets Report
# Date: 2026-09-21
# Source: EconolabQS1 Staging 1.4.20 + master_manufacturing_be_stg.exe

## CRITICAL FINDINGS

### 1. MySQL Database Credentials (config_staging.pyc)

| Parameter | Value |
|-----------|-------|
| MySQL host | 34.101.249.224 |
| MySQL port | 3306 |
| MySQL user | pharmavid |
| MySQL password | (encrypted with Fernet) |
| Fernet key | wN0oOz0d7dFPysLiaUYWTHG5RstxE9AJ9CqqIu2SqVE= |
| Encrypted password | gAAAAABn0onC1VQUiXLdKSGS1Ba8T1zWDylQnuuxZE7BMJ4sUIzYF6A8PMRHBD2moWMFc34YEhDRBFROee5jnJjfbaYjIWpmxA== |
| Charset | utf8mb4 |

Databases on 34.101.249.224:3306:
- mprocess, m_manufacture, m_manufacture2
- tprocess, t_manufacture, t_fp_process, t_fp_manufacture
- qs_qc_manufacture, qs_qc
- hplc, HPLC
- cloud_mprocess, cloud_tprocess, cloud_qs_qc, cloud_HPLC
- local_mprocess, local_tprocess, local_qs_qc, local_HPLC
- m_manufacture_history, cloud_mprocess_history

Also: localhost root/12345 (local DB)

### 2. API Encryption Key (middleware.pyc)

| Parameter | Value |
|-----------|-------|
| API_ENCRYPTION_KEY | GkWdMVpsGDEgfM9+ISF/nUy5NMgCbjUdV0Gv1dxIFUM= |
| Algorithm | AES + PBKDF2HMAC (SHA256) |
| Salt | static-salt |
| Used for | Endpoint encryption/decryption |

Same key also in runapp.pyc:
| Parameter | Value |
|-----------|-------|
| Cloud registration key | GkWdMVpsGDEgfM9+ISF/nUy5NMgCbjUdV0Gv1dxIFUM= |

### 3. Backend API URLs

| Environment | URL |
|-------------|-----|
| Production | https://api-inno.pharmalink.id/manufacture-be/ |
| Staging | https://staging-api-inno.pharmalink.id/manufacture-be/ |
| Production master | https://api-inno.pharmalink.id/manufacture/master |
| Staging master | https://staging-api-inno.pharmalink.id/manufacture |

### 4. Firebase API Key (from APK)

| Parameter | Value |
|-----------|-------|
| google_api_key | AIzaSyBPEgWSgKCBAH640Aknbl-vw_YSDGEewio |
| google_app_id | 1:2882385210:android:9f9e437e91d9dc68e64c03 |
| gcm_defaultSenderId | 2882385210 |
| project_id | monitoringlogs-bfc19 |
| google_storage_bucket | monitoringlogs-bfc19.firebasestorage.app |

### 5. App Architecture (from pyc analysis)

- Framework: Flask (Python)
- Entry point: runapp.py
- Config: appname/config_staging.py, config_production.py, config_local_release.py
- Crypto: cryptography.fernet (Fernet symmetric encryption)
- DB: MySQL (mysql.connector)
- Cloud: Firebase Admin (FCM push notifications)
- API: encrypted endpoints (AES + PBKDF2)
- Frontend: Tauri (Rust + WebView2)
- Mobile: Flutter

### 6. Developer Path Leak

D:\workspace_kerja\manufacturing-monitoring-apps\monitoring_logs_mobile_app\

## DECRYPTION NEEDED

The MySQL password is Fernet-encrypted. To decrypt:
- Key: wN0oOz0d7dFPysLiaUYWTHG5RstxE9AJ9CqqIu2SqVE=
- Ciphertext: gAAAAABn0onC1VQUiXLdKSGS1Ba8T1zWDylQnuuxZE7BMJ4sUIzYF6A8PMRHBD2moWMFc34YEhDRBFROee5jnJjfbaYjIWpmxA==

## NEXT STEPS

1. Decrypt Fernet password -> get MySQL creds for 34.101.249.224
2. Try MySQL creds on 34.101.249.224:3306
3. Test API endpoints at api-inno.pharmalink.id
4. Check if Firebase key allows unauthorized access
