API is currently open, details route show logs of every user. We need to restrict API access (secret token is shsd.conf ?) or remove the API and use an internal process to parse logs. We also need to restrict access to the "details" route to admin users.