Secure authentication and password storage
The PHP backend uses PHP's password hashing and verification functions. Plain-text passwords are never written to the database. Successful login creates a cryptographically random API token, while only its SHA-256 hash is retained server-side. Tokens expire and can be revoked at logout or after a password reset.
Production login endpoints should always run through HTTPS. Administrator passwords should be changed immediately after installation, kept unique and protected with a password manager.