Status: Accepted
Date: 2026-07-02
Quality requirements addressed: QR-003
The web admin interface can register users, manage guests, view logs, and affect access-control behavior. These operations must not be exposed without authentication. The system also must not store or compare plain-text passwords.
Use session-based authentication for the admin UI and store password hashes instead of plain-text passwords.
The backend validates the admin session before protected operations such as registration, user/guest management, logs, and dashboard access. The bootstrap admin credentials are supplied through environment configuration, and the stored credential is represented as a password hash.
Positive consequences:
Tradeoffs:
SECRET_KEY management.| View | Rendered diagram | Source artifact |
|---|---|---|
| Static view | component-diagram.png | component-diagram.puml |
| Dynamic view | register-new-person-sequence.png | register-new-person-sequence.puml |
This ADR is visible in the static view through the separated Auth Module. It is visible in the dynamic view because the registration workflow starts with session validation before protected registration logic is executed.