Secure internal web application
Admin control for projects and money.
Built from the functional specification: CRM, projects, maintenance contracts, finance, POP tracking, reports, integrations, audit, and administration.
Session cookie authMFA deferredAudit logged
Security rail
- Role-based access now enforced for admin and finance write paths.
- HttpOnly session cookie; no browser-visible access token.
- MFA field and trusted-device UI retained while enforcement is deferred.
- Sensitive changes are audited with actor metadata.
Admin login