Access control
Users
Grant the minimum access each operator needs. Administrative and transmit capabilities are enforced server-side.ViewerObserve live activity and logsUser / operatorManage QSOs within safety policyAdministratorConfigure station and access
◌Loading local accountsReading access records from the authenticated station service.
✓
Layered local authentication
Scrypt password hashes, server-side sessions, strict cookies, CSRF validation and role capabilities are enforced. Operator and administrator sessions require a replay-protected authenticator code; sensitive actions require fresh step-up verification.